惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Security Latest
Security Latest
博客园_首页
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
爱范儿
爱范儿
小众软件
小众软件
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
博客园 - Franky
S
SegmentFault 最新的问题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
NISL@THU
NISL@THU
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
V
Visual Studio Blog
雷峰网
雷峰网
C
Cybersecurity and Infrastructure Security Agency CISA
美团技术团队
The Cloudflare Blog
P
Privacy & Cybersecurity Law Blog
Latest news
Latest news
S
Securelist
C
CERT Recently Published Vulnerability Notes
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Palo Alto Networks Blog
Last Week in AI
Last Week in AI
V
V2EX
Know Your Adversary
Know Your Adversary
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Threat Research - Cisco Blogs
T
Tailwind CSS Blog
J
Java Code Geeks
I
Intezer
Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园 - 【当耐特】
Schneier on Security
Schneier on Security

SECURITY.COM

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor The Detection Gap: MITRE ATT&CK T1140 and T1105 Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For AV-TEST Gives Symantec® Endpoint Security Complete a Perfect Score The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Your DLP Incident Backlog Owes You Closure Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Another Year, Another Win: SE Labs® Recognizes Symantec® Endpoint Security Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden Locking Down the Server 🎙️SECURITY.COM The Podcast: The Death of SIEM Threats Rise on a Tide of Global Unrest When Nation-States Stop Caring About Size Espionage Campaign Targeted Stock Exchange Executive for Five Months Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 🎙️SECURITY.COM The Podcast: The Evolution of Cybersecurity PR with W2 Communications The Maximalism Trap: When More Becomes Too Much Symantec DLP Cloud and DPSM are the Power Couple Security Strategists Need Symantec DLP Cloud and DSPM are the Power Couple Security Strategists Need The Future of the Partnership: AI, Automation, and Ecosystems Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations 🎙️SECURITY.COM The Podcast: Iran’s Cyber Warfare Playbook: What Defenders Need to Know Right Now 5 Ways To Keep AI in Check Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign Doing More with Less: How Government Agencies are Rethinking Cybersecurity Navigating Compliance and Insurance as a Competitive Edge Is SIEM Trying to Do Too Much? Every Defender Deserves Frontier AI The New Partner-Vendor Relationship DLP Made Easier on the Teams Running It The EU Digital Wallet: Why Waiting is Not an Option Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft Stopping Data Leaks at the Speed of AI Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor How AI Increases the Load on Security Teams Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? Technical Enablement vs. Marketing Noise Enterprise-Grade Security for All in 2026 Architecting for Margin Beyond the Initial Sale 🎙️SECURITY.COM The Podcast: A Brief History of Data Loss Prevention Symantec CBX Through the Paparazzi Lens The U.S. Navy’s Playbook for Cost-Controlled, Reliable Cybersecurity The Modern Threat Landscape and The Partner’s New Burden Symantec CBX Rocked RSAC 2026 Conference For Financial Services, a Wake-Up Call for Reclaiming IAM Control The Next Identity Shift Cyber Legends: Behind the Scenes of CBX Built for This Moment (and All Those to Come)
3 Ways to Defend Against LOTL Attacks Now
About the Author · 2026-07-20 · via SECURITY.COM
  • Trusted tools have become one of attackers’ favorite hiding places.
  • Stopping living off the land (LOTL) attacks requires more than detection. It requires limiting opportunities for abuse, anticipating attacker behavior, and being the first one to connect the dots.
  • Three groundbreaking, AI-driven protections each defend a different stage of the same problem.

Attackers are practical. If they can borrow your tools, why bring their own?

A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues to drive the appeal. After all, the best disguise has always been looking like you belong.

Recent research shows nearly all threat actors are deploying living off the land (LOTL) techniques, using legitimate software to host and launch attacks. 

For a long time, malicious activity announced itself by breaking everyday operations or looking out of place. LOTL changed that. Though the tool may belong and the command may be routine, there’s a persistent challenge in recognizing when normal activity starts looking out of place.

The best LOTL defenses aren’t comprised of a single defense mechanism. They come from doing three things well: making trusted tools harder to misuse, anticipating where attackers will pivot next, and connecting evidence before small events become much bigger problems.

1. Make trusted tools harder to misuse with Adaptive Protection

LOTL attacks put defenders in an uncomfortable position. The tools being abused are often the very ones your organization relies on every day. Blocking them outright isn’t an option. Teams need to administer systems, deploy software, troubleshoot endpoints, and keep work moving.

Adaptive Protection addresses that challenge with behavior-based controls designed to limit misuse of legitimate tools before suspicious activity escalates. Adaptive Protection monitors an organization’s typical use of software and uses those normal behaviors as a baseline for usage policy. From that point on, it automatically blocks behaviors that fall outside the parameters set by the normal usage policy. Rather than chasing every new technique, it narrows an attacker’s ability to operate within tools everyone already trusts.

It’s an approach backed by years of independent validation, reinforcing the value of behavior-based prevention as attackers continue to feed off legitimate business activity.

2. Anticipate the next move with Incident Prediction

Most alerts arrive late to the party. By the time a questionable remote session reaches an analyst, an attacker may have already tested an account, mapped a few systems, and learned which controls react—and which don’t. The attacker gets feedback in seconds. The analyst gets a ticket.

Incident Prediction

uses attack-trained AI and native telemetry correlation to help teams look beyond the alert in front of them and identify where an attacker is likely to go next. This gives analysts a clearer picture of where suspicious activity is headed, creating an opportunity to disrupt the attack before it gains momentum.

In LOTL attacks, individual events rarely tell the whole story. Looking at how activity unfolds over time helps teams prioritize what matters most 

while there’s still time to respond

. And predicting what will happen next? That’s next level defense against all threats, including LOTL attacks.

3. Connect the dots with Threat Tracer

SOCs rarely struggle with a lack of data. They struggle because they lack context. Endpoint activity, network connections, identity events, and data access live in different places, forcing analysts to piece together an attack while it’s still unfolding.

Threat Tracer helps connect those signals within a single console. Correlating activity across users, devices, processes, network behavior, and file metadata gives analysts a clearer view of the attack—and where to focus first. This is a huge benefit for all analysts, from beginners to experts.

Built on Carbon Black’s pioneering’ EDR capabilities, Threat Tracer helps analysts visualize the full blast radius of an attack instead of manually chasing and connecting disconnected alerts. The result is faster, more focused investigations—and greater confidence you’re responding to the right thing. 

Unified defenses with Symantec CBX

Attackers don’t care where one security product ends and another begins. They care whether the next move works.

That’s where Symantec CBX comes in. CBX brings together Adaptive Protection, Incident Prediction, and Threat Tracer into a single, unified platform—giving security teams the full picture they need to investigate faster and respond with confidence. In addition, CBX correlates signals from across endpoints, networks, SaaS applications, and data to give analysts a comprehensive view of what’s happening at any moment. Analysts can stop guessing and take defensive action sooner.

Catch CBX Fest live or on-demand for a deeper look at how these capabilities come together.

Feeling lost? Here are a couple FAQs. 

What are living-off-the-land attacks?

Living-off-the-land (LOTL) attacks use legitimate tools, applications, and system processes that are already present in an environment to carry out malicious activity. Because attackers rely on trusted resources instead of custom malware, LOTL techniques are often harder to detect using traditional, signature-based security controls.

Why are LOTL attacks difficult to detect?

LOTL attacks blend into normal operations by using legitimate tools, valid credentials, and routine administrative activity. Individual events may appear harmless on their own, making it difficult to distinguish malicious behavior without understanding the broader sequence of events and the context surrounding them.

How can organizations defend against LOTL attacks?

Effective LOTL defense combines behavior-based prevention, visibility into likely attacker behavior, and connected investigation capabilities. Rather than focusing only on malware, organizations should look for suspicious use of legitimate tools, anticipate how attacks may progress, and correlate activity across endpoint, network, identity, and data to detect and stop attacks sooner.

You might also enjoy

3 Ways to Defend Against LOTL Attacks Now

Shanleigh Reardon

Shanleigh Reardon

Product Marketing Manager