#LOTL

Popular Medusa Ransomware utilizes many LOTL (Living of the Land) techniques - CISA cisa.gov/news-events/cybersecu #cybersecurity #ransomware #Medusa #LOTL #Windows #CISA

2025-03-25

for Route53 fanbois out there such as myself, I wrote a dynamic dns client under living off the land constraints.

#ddns #aws #lotl

new23d.com/living-off-the-land

2025-03-03

"Living off the Land (LOTL) attacks: How North Korea’s Lazarus Group Hackers Exploited Windows" published by SystemWeakness. #LOTL, #Lazarus, #DPRK, #CTI systemweakness.com/living-off-

2025-02-18

More food for thought... Human operated attacks can be hard to detect.

Especially if they are of the #LOTL variety.

Or perhaps not hard to detect, but tricky to adjudicate. This is why an MDR service is valuable.
1/3

tio 💜🏳️‍⚧️Aegeah@mastodon.art
2025-02-10
Dan :dumpster_fire:4n68r@infosec.exchange
2025-01-28

Was looking for a good Awesome list on Living Off the Land ( #LOL #LOtL ) tools/techniques. Found some helpful sites / repos but either nothing I could contribute to or it was limited.

So... I made one: github.com/danzek/awesome-lol-

Contributions welcome, whether by replying to this post or sending a PR on GitHub.

#lolbins #lolbas

2025-01-22

🔍 "If you can’t see what’s happening on your network, you can’t defend it." – Brian Dye, CEO of Corelight.

What if the biggest threat isn’t something from outside, but something that’s already inside your network?

In the latest episode of Exploring Information Security, Brian Dye discusses with Timothy De Block the challenge of detecting Living off the Land (#LotL) attacks, why gaining complete network visibility is crucial for defending against these evolving threats, and much more... 👀

🎧 Catch the full episode here: exploresec.com/eis/2024/1/2/sh

#Cybersecurity #NetworkSecurity #NDR #podcast

Carsten O. 💚🌻📯carsten_O@troet.cafe
2024-12-14
2024-12-07

Mift, wir werden es vermutlich aus gesundheitlichen Gründen nicht zum #Lordfest in #Hamburg am 14. Dez schaffen.

Mag jemand unsere beiden Tickets für 50 EUR + Versand übernehmen?

Bitte teilen 🙏

Edit: Schade, verfallen nun 😶

Versand per Einwurf-Einschreiben oder Abholung #Freudenstadt

#lotl #LordOfTheLost

2024-11-26

Living off the Land: разбор задания от экспертов F.A.C.C.T. на CyberCamp2024

Привет Хабр! На связи Владислав Азерский , заместитель руководителя Лаборатории цифровой криминалистики компании F.A.C.C.T. и Иван Грузд , ведущий специалист по реагированию на инциденты и цифровой криминалистике компании F.A.C.C.T. В начале октября мы приняли участие в практической конференции по кибербезопасности CyberCamp 2024 в качестве спикеров. Ссылки на доклады вот и вот. Имея опыт в области реагирования на инциденты ИБ, было принято решение сфокусировать темы докладов на одном из наиболее популярных подходов к реализации современных атак среди злоумышленников – Living off the Land (LotL). Он подразумевает собой использование легитимных программ и инструментов для реализации задач на разных этапах атаки, будь то распространение по сети или выполнение команд на скомпрометированном устройстве.

habr.com/ru/companies/f_a_c_c_

#cybercamp_2024 #форензика #LotL #living_off_the_land #компьютерная_криминалистика #киберучения

2024-04-27

Reminder an mich: Wenn ich nächstes Mal mit meinen Earbuds beim Straßenkehren versehentlich zu dem #LOTL Song mitsinge, sollte ich ne Antwort parat haben, wenn mich mein Nachbar fragt „Wem denn?“…🙈

Wobei „PolitTalks“ als Antwort naheliegend gewesen wäre.😜

Schönes WE!
youtube.com/watch?v=_x-87xd_91

chmod777 :donor:​:d20:​👺​chmod777@infosec.exchange
2024-04-26

I recently read this CISA + Joint Guidance on Living Off The Land Techniques (LOTL). The guidance put out talks about identifying and mitigating LOTL techniques, but if we're going to be honest - it wasn't anything ground breaking. However I think it goes to show that the basic hardening techniques may go a long way.

I agree and acknowledge that identifying may be difficult, but some of the mitigation techniques are pretty basic/elementary:

- change default admin settings & passwords
- remove unnecessary protocols
- Least privilege
- MFA
- UEBA

cisa.gov/resources-tools/resou

#LOTL
#Hardening
#CISA

2024-04-20

Visited the #lotl concert in #Stuttgart today and had a blast. Been years that I went to LKA Longhorn. Like.. dunno.. 20 or so? And nothing changed 😄

Show was great, felt familiar, what I really like. My personal highlight was “Unstoppable” (originally by Sia).

We did hear the struggle in the voice though. Band just recovered from Covid apparently. Hope they don’t overdo it 😅

Anyway, for the curious: The set list “15 Years Of #LordOfTheLost” is available on Spotify at https://open.spotify.com/playlist/2yZvahybiLwDjDJUjldqef (yes yes Spotify evil).

https://beko.famkos.net/2024/04/21/15-years-of-lord-of-the-lost/

#LordOfTheLost #lotl #Stuttgart

Beko Pharm (deprecated)bekopharm@social.tchncs.de
2024-04-20

Visited the #lotl concert in #Stuttgart today. Been years that I went to LKA Longhorn. Like.. dunno.. 20? And nothing changed 🥲

Show was great. We did hear the struggle in the voice tho. Band just recovered from Covid apparently. Hope they don't overdo it 🤔

#LordOfTheLost

Andy Warburton ❌❌❌andy_warb
2024-04-06

Just had the best night in recent memory. Lord of the Lost are epic on stage!

Lord of the Lost on Stage bathed in pink light. The crowd have their hands in the air
2024-03-22

Die Ohren klingen, die Stimme ist rau und mir tut alles weh. Es war so grandios gut. 🥰 #lotl

Die Musiker von Lord of the Lost, vor Konzertbeginn.
2024-03-19

Как собрать контейнер и не вооружить хакера

Известно, что с контейнерами бывает огромное количество разнообразных проблем, в том числе, связанных с информационной безопасностью. Как их избежать и не дать взломщику лазеек в ваш сервис — разбираемся в этой статье. Привет, Хабр! Это Алексей Федулаев и Антон Жаболенко из Wildberries. Мы работаем в сфере информационной безопасности (ИБ) уже больше 10 лет.

habr.com/ru/companies/oleg-bun

#контейнеры #уязвимости #docker #cve #living_off_the_land #LotL #тестирование #харденинг #capabilities #apparmor

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst