Cybercriminals are constantly looking for ways to blend into legitimate activity. As security solutions have improved at detecting traditional malware, attackers increasingly rely on living off the land (LOTL) techniques that abuse trusted tools already present in the environment.
This presents a challenge for traditional security tools because legitimate Windows utility launches aren’t inherently suspicious. The danger comes from how those tools are used.
Fortunately, you don't have to choose between enabling administrative functionality and accepting unnecessary risk. By applying Zero Trust principles and limiting what trusted tools are allowed to do, you can significantly reduce the opportunities for living off the land attacks to succeed.
What is living off the land?
Computers have powerful built-in tools that are essential for everyday operating system functions and system administration. In a living off the land (LOTL) attack, a threat actor abuses these native tools or other legitimate software to perform malicious actions.
Rather than introducing traditional malware, attackers manipulate trusted applications already present on the system to execute commands, establish persistence, move laterally, or steal sensitive data.
In a recent example of high-profile LOTL attack, researchers reported that threat actors believed to be linked to the Russian Sandworm group compromised Ukrainian organizations by abusing legitimate Windows tools and other dual-use software. The attackers stole sensitive data, established persistence, and evaded detection while deploying very little malware. They even maintained access to one victim's network for nearly two months before their activity was discovered.
Clearly, LOTL attacks are much more than a theoretical risk. Understanding the most common tools being exploited by such cybercriminals can help you safeguard your organization from being exploited.
What tools do cybercriminals use in LOTL attacks?
PowerShell is one of the most commonly abused tools in living off the land attacks. Built into Windows, it provides IT administrators with a powerful command-line interface and scripting language for managing systems and automating administrative tasks.
Attackers often exploit PowerShell to execute malicious scripts, establish persistence, download additional payloads, exfiltrate data, and even deploy ransomware. Once a cybercriminal gains access to PowerShell on a compromised device, they may be able to execute commands, move laterally, and expand their access across the environment.
Although PowerShell may be the most popular tool to abuse, every operating system contains multiple other powerful built-in tools that hackers can exploit.
Windows Management Instrumentation (WMI) can be used for remote system management, reconnaissance, and executing commands on other systems. Rundll32 is commonly abused to execute malicious code through legitimate DLLs, while the Windows Registry is often modified to establish persistence, steal credentials, or weaken security controls.
As defenders improve their ability to detect one technique, attackers continue finding new ways to misuse trusted tools already present in the operating system. This ongoing evolution is one of the reasons living off the land attacks remain such an effective tactic.
Learn more by joining ThreatLocker CEO Danny Jenkins and Chief Product Officer Rob Allen for an exclusive webinar: Preventing trusted software exploitation with application containment
Why are LOTL attacks so difficult to defend against?
LOTL attacks rely on legitimate, digitally signed tools that are included with the operating system by default. Because these utilities are essential for everyday system administration and other legitimate functions, they are readily available for attackers to abuse.
- Malicious use of trusted tools can be difficult to identify
Native Windows tools are designed to perform legitimate administrative tasks, making it difficult to distinguish normal activity from malicious use. Because living off the land attacks rely on trusted tools rather than traditional malware, attackers can blend their activity into everyday system operations. - Attackers can establish persistence
By abusing legitimate Windows tools, attackers can establish persistence and maintain access to an environment over time. This allows them to continue exploring the network, gathering information, escalating privileges, and moving laterally while attempting to avoid detection. - You can’t simply disable these tools
The native tools abused in LOTL attacks are pre-installed on all Windows computers and are necessary for normal administrative functions. Disabling or removing PowerShell, WMI, and other built-in utilities can disrupt your normal business operations, making this approach impractical. Instead, you need controls that let these tools perform their intended functions while preventing attackers from using them for malicious purposes.
How you can prevent LOTL attacks with ThreatLocker
To effectively combat LOTL attacks, you need to control both what is allowed to run and what trusted applications are permitted to do. ThreatLocker helps you achieve this through a Zero Trust approach.
Block unauthorized applications, scripts, and DLLs
ThreatLocker Allowlisting automatically inventories the applications and dependencies running in your environment and recognizes more than 15,000 pre-built applications, helping streamline policy creation. Once you've approved which applications should run, everything else is blocked by default, including unauthorized applications, scripts, and DLLs.
By preventing unauthorized code from running, you reduce opportunities for attackers to execute the scripts and payloads commonly used during living off the land attacks.
Contain trusted applications
Blocking unauthorized applications is only part of the solution. Living off the land attacks frequently abuse applications and native Windows tools that are already trusted and required for legitimate business operations.
ThreatLocker Ringfencing™ helps you apply application containment by controlling what approved applications can access, launch, modify, and connect to. Instead of simply deciding what can run, you can also define how trusted applications are allowed to behave.
For example, you can prevent:
- Microsoft Office applications from launching PowerShell or other command-line tools
- PowerShell from making outbound internet connections
- Applications from modifying the Windows Registry unless explicitly authorized
- Unnecessary child process creation commonly used by attackers
- Applications from accessing sensitive files or other resources they don't need
- Trusted applications from interacting with other applications in ways that could facilitate lateral movement or privilege escalation
By placing guardrails around trusted applications, Ringfencing helps prevent attackers from turning legitimate business tools into attack tools.
Restrict access to sensitive data and resources
Once attackers gain access to a system, their next objective is often to locate and access valuable data. Limiting unnecessary access reduces the impact of a compromised account, endpoint, or application.
ThreatLocker enables organizations to enforce least-privilege access controls giving users, applications, and systems access to only the resources they genuinely need. This helps reduce opportunities for attackers to move laterally, access sensitive information, or leverage trusted tools to reach additional systems.
Reduce attack paths with Zero Trust controls
LOTL attacks succeed when trusted applications have broader permissions than they need. A Zero Trust approach helps eliminate unnecessary privileges and access paths.
By combining Allowlisting and Ringfencing with least-privilege controls, ThreatLocker enables organizations to reduce their attack surface, limit attacker freedom of movement, and prevent common LOTL techniques from succeeding—even when attackers attempt to abuse legitimate tools that already exist within the environment.
The result is a layered defense that helps stop unauthorized code, contain trusted applications, and restrict the actions attackers can take after gaining access.
Prevent attackers from abusing trusted applications
You can't eliminate PowerShell, WMI, or other native Windows tools without disrupting legitimate business operations, but you don't have to leave them uncontrolled either.
By applying Zero Trust controls that prevent unauthorized code from running and limit how trusted applications interact with your environment, you can stop many living off the land techniques before they lead to lateral movement, persistence, or data theft.
Book a demo with ThreatLocker today to see how the ThreatLocker Zero Trust Platform helps you stay in control of trusted applications without sacrificing productivity.


