

























Attackers are practical. If they can borrow your tools, why bring their own?
A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues to drive the appeal. After all, the best disguise has always been looking like you belong.
Recent research shows nearly all threat actors are deploying living off the land (LOTL) techniques, using legitimate software to host and launch attacks.
For a long time, malicious activity announced itself by breaking everyday operations or looking out of place. LOTL changed that. Though the tool may belong and the command may be routine, there’s a persistent challenge in recognizing when normal activity starts looking out of place.
The best LOTL defenses aren’t comprised of a single defense mechanism. They come from doing three things well: making trusted tools harder to misuse, anticipating where attackers will pivot next, and connecting evidence before small events become much bigger problems.
LOTL attacks put defenders in an uncomfortable position. The tools being abused are often the very ones your organization relies on every day. Blocking them outright isn’t an option. Teams need to administer systems, deploy software, troubleshoot endpoints, and keep work moving.
Adaptive Protection addresses that challenge with behavior-based controls designed to limit misuse of legitimate tools before suspicious activity escalates. Adaptive Protection monitors an organization’s typical use of software and uses those normal behaviors as a baseline for usage policy. From that point on, it automatically blocks behaviors that fall outside the parameters set by the normal usage policy. Rather than chasing every new technique, it narrows an attacker’s ability to operate within tools everyone already trusts.
It’s an approach backed by years of independent validation, reinforcing the value of behavior-based prevention as attackers continue to feed off legitimate business activity.
Most alerts arrive late to the party. By the time a questionable remote session reaches an analyst, an attacker may have already tested an account, mapped a few systems, and learned which controls react—and which don’t. The attacker gets feedback in seconds. The analyst gets a ticket.
uses attack-trained AI and native telemetry correlation to help teams look beyond the alert in front of them and identify where an attacker is likely to go next. This gives analysts a clearer picture of where suspicious activity is headed, creating an opportunity to disrupt the attack before it gains momentum.
In LOTL attacks, individual events rarely tell the whole story. Looking at how activity unfolds over time helps teams prioritize what matters most
while there’s still time to respond. And predicting what will happen next? That’s next level defense against all threats, including LOTL attacks.
SOCs rarely struggle with a lack of data. They struggle because they lack context. Endpoint activity, network connections, identity events, and data access live in different places, forcing analysts to piece together an attack while it’s still unfolding.
Threat Tracer helps connect those signals within a single console. Correlating activity across users, devices, processes, network behavior, and file metadata gives analysts a clearer view of the attack—and where to focus first. This is a huge benefit for all analysts, from beginners to experts.
Built on Carbon Black’s pioneering’ EDR capabilities, Threat Tracer helps analysts visualize the full blast radius of an attack instead of manually chasing and connecting disconnected alerts. The result is faster, more focused investigations—and greater confidence you’re responding to the right thing.
Attackers don’t care where one security product ends and another begins. They care whether the next move works.
That’s where Symantec CBX comes in. CBX brings together Adaptive Protection, Incident Prediction, and Threat Tracer into a single, unified platform—giving security teams the full picture they need to investigate faster and respond with confidence. In addition, CBX correlates signals from across endpoints, networks, SaaS applications, and data to give analysts a comprehensive view of what’s happening at any moment. Analysts can stop guessing and take defensive action sooner.
Catch CBX Fest live or on-demand for a deeper look at how these capabilities come together.
Feeling lost? Here are a couple FAQs.
Living-off-the-land (LOTL) attacks use legitimate tools, applications, and system processes that are already present in an environment to carry out malicious activity. Because attackers rely on trusted resources instead of custom malware, LOTL techniques are often harder to detect using traditional, signature-based security controls.
LOTL attacks blend into normal operations by using legitimate tools, valid credentials, and routine administrative activity. Individual events may appear harmless on their own, making it difficult to distinguish malicious behavior without understanding the broader sequence of events and the context surrounding them.
Effective LOTL defense combines behavior-based prevention, visibility into likely attacker behavior, and connected investigation capabilities. Rather than focusing only on malware, organizations should look for suspicious use of legitimate tools, anticipate how attacks may progress, and correlate activity across endpoint, network, identity, and data to detect and stop attacks sooner.


Shanleigh Reardon
Product Marketing Manager
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。