惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Stack Overflow Blog
Stack Overflow Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
The Exploit Database - CXSecurity.com
美团技术团队
P
Proofpoint News Feed
S
Schneier on Security
P
Privacy International News Feed
Last Week in AI
Last Week in AI
Scott Helme
Scott Helme
V
Vulnerabilities – Threatpost
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tor Project blog
S
SegmentFault 最新的问题
Security Latest
Security Latest
月光博客
月光博客
A
About on SuperTechFans
Martin Fowler
Martin Fowler
A
Arctic Wolf
C
Cyber Attacks, Cyber Crime and Cyber Security
腾讯CDC
Schneier on Security
Schneier on Security
H
Hacker News: Front Page
TaoSecurity Blog
TaoSecurity Blog
NISL@THU
NISL@THU
B
Blog RSS Feed
C
Cybersecurity and Infrastructure Security Agency CISA
Cyberwarzone
Cyberwarzone
V2EX - 技术
V2EX - 技术
Hacker News - Newest:
Hacker News - Newest: "LLM"
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
W
WeLiveSecurity
Cisco Talos Blog
Cisco Talos Blog
MyScale Blog
MyScale Blog
M
MIT News - Artificial intelligence
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
P
Proofpoint News Feed
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
N
News and Events Feed by Topic
The Last Watchdog
The Last Watchdog
Engineering at Meta
Engineering at Meta
博客园 - 叶小钗
T
Tenable Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
LINUX DO - 热门话题
Help Net Security
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog

SECURITY.COM

4 Application Control Updates That Help Teams Move Faster Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For Your DLP Incident Backlog Owes You Closure 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Locking Down the Server Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 5 Ways To Keep AI in Check DLP Made Easier on the Teams Running It Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? For Financial Services, a Wake-Up Call for Reclaiming IAM Control How Cloud-Managed DLP Lowers the Barrier to Entry As Identity Takes Control, Telecom Needs Repatriated IAM Capable of Keeping Up Post-Quantum Security Starts at the Edge The Public Sector Case for Repatriating IAM in the Age of AI The Data Sovereignty Paradox The Unseen Wall: How Billions of Attacks Were Blocked in 2025 The “Zero-Blindness” Roadmap: Achieving Maturity in the DLP Endpoint Workspace IAM Has a Fix for the Modern Identity Crisis Identity is the Control Plane, and AI Just Changed the Game
3 Ways to Defend Against LOTL Attacks Now
About the Author · 2026-07-20 · via SECURITY.COM
  • Trusted tools have become one of attackers’ favorite hiding places.
  • Stopping living off the land (LOTL) attacks requires more than detection. It requires limiting opportunities for abuse, anticipating attacker behavior, and being the first one to connect the dots.
  • Three groundbreaking, AI-driven protections each defend a different stage of the same problem.

Attackers are practical. If they can borrow your tools, why bring their own?

A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues to drive the appeal. After all, the best disguise has always been looking like you belong.

Recent research shows nearly all threat actors are deploying living off the land (LOTL) techniques, using legitimate software to host and launch attacks. 

For a long time, malicious activity announced itself by breaking everyday operations or looking out of place. LOTL changed that. Though the tool may belong and the command may be routine, there’s a persistent challenge in recognizing when normal activity starts looking out of place.

The best LOTL defenses aren’t comprised of a single defense mechanism. They come from doing three things well: making trusted tools harder to misuse, anticipating where attackers will pivot next, and connecting evidence before small events become much bigger problems.

1. Make trusted tools harder to misuse with Adaptive Protection

LOTL attacks put defenders in an uncomfortable position. The tools being abused are often the very ones your organization relies on every day. Blocking them outright isn’t an option. Teams need to administer systems, deploy software, troubleshoot endpoints, and keep work moving.

Adaptive Protection addresses that challenge with behavior-based controls designed to limit misuse of legitimate tools before suspicious activity escalates. Adaptive Protection monitors an organization’s typical use of software and uses those normal behaviors as a baseline for usage policy. From that point on, it automatically blocks behaviors that fall outside the parameters set by the normal usage policy. Rather than chasing every new technique, it narrows an attacker’s ability to operate within tools everyone already trusts.

It’s an approach backed by years of independent validation, reinforcing the value of behavior-based prevention as attackers continue to feed off legitimate business activity.

2. Anticipate the next move with Incident Prediction

Most alerts arrive late to the party. By the time a questionable remote session reaches an analyst, an attacker may have already tested an account, mapped a few systems, and learned which controls react—and which don’t. The attacker gets feedback in seconds. The analyst gets a ticket.

Incident Prediction

uses attack-trained AI and native telemetry correlation to help teams look beyond the alert in front of them and identify where an attacker is likely to go next. This gives analysts a clearer picture of where suspicious activity is headed, creating an opportunity to disrupt the attack before it gains momentum.

In LOTL attacks, individual events rarely tell the whole story. Looking at how activity unfolds over time helps teams prioritize what matters most 

while there’s still time to respond

. And predicting what will happen next? That’s next level defense against all threats, including LOTL attacks.

3. Connect the dots with Threat Tracer

SOCs rarely struggle with a lack of data. They struggle because they lack context. Endpoint activity, network connections, identity events, and data access live in different places, forcing analysts to piece together an attack while it’s still unfolding.

Threat Tracer helps connect those signals within a single console. Correlating activity across users, devices, processes, network behavior, and file metadata gives analysts a clearer view of the attack—and where to focus first. This is a huge benefit for all analysts, from beginners to experts.

Built on Carbon Black’s pioneering’ EDR capabilities, Threat Tracer helps analysts visualize the full blast radius of an attack instead of manually chasing and connecting disconnected alerts. The result is faster, more focused investigations—and greater confidence you’re responding to the right thing. 

Unified defenses with Symantec CBX

Attackers don’t care where one security product ends and another begins. They care whether the next move works.

That’s where Symantec CBX comes in. CBX brings together Adaptive Protection, Incident Prediction, and Threat Tracer into a single, unified platform—giving security teams the full picture they need to investigate faster and respond with confidence. In addition, CBX correlates signals from across endpoints, networks, SaaS applications, and data to give analysts a comprehensive view of what’s happening at any moment. Analysts can stop guessing and take defensive action sooner.

Catch CBX Fest live or on-demand for a deeper look at how these capabilities come together.

Feeling lost? Here are a couple FAQs. 

What are living-off-the-land attacks?

Living-off-the-land (LOTL) attacks use legitimate tools, applications, and system processes that are already present in an environment to carry out malicious activity. Because attackers rely on trusted resources instead of custom malware, LOTL techniques are often harder to detect using traditional, signature-based security controls.

Why are LOTL attacks difficult to detect?

LOTL attacks blend into normal operations by using legitimate tools, valid credentials, and routine administrative activity. Individual events may appear harmless on their own, making it difficult to distinguish malicious behavior without understanding the broader sequence of events and the context surrounding them.

How can organizations defend against LOTL attacks?

Effective LOTL defense combines behavior-based prevention, visibility into likely attacker behavior, and connected investigation capabilities. Rather than focusing only on malware, organizations should look for suspicious use of legitimate tools, anticipate how attacks may progress, and correlate activity across endpoint, network, identity, and data to detect and stop attacks sooner.

You might also enjoy

3 Ways to Defend Against LOTL Attacks Now

Shanleigh Reardon

Shanleigh Reardon

Product Marketing Manager