惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
P
Privacy International News Feed
C
Cybersecurity and Infrastructure Security Agency CISA
MyScale Blog
MyScale Blog
D
DataBreaches.Net
I
Intezer
GbyAI
GbyAI
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
S
Security @ Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
NISL@THU
NISL@THU
Project Zero
Project Zero
博客园_首页
Martin Fowler
Martin Fowler
A
About on SuperTechFans
J
Java Code Geeks
AI
AI
WordPress大学
WordPress大学
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
L
LINUX DO - 热门话题
云风的 BLOG
云风的 BLOG
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cisco Blogs
L
LangChain Blog
Google Online Security Blog
Google Online Security Blog
AWS News Blog
AWS News Blog
Help Net Security
Help Net Security
Application and Cybersecurity Blog
Application and Cybersecurity Blog
D
Docker
N
Netflix TechBlog - Medium
Know Your Adversary
Know Your Adversary
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Secure Thoughts
H
Heimdal Security Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
O
OpenAI News
S
Security Affairs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
雷峰网
雷峰网
V
Visual Studio Blog
T
Threat Research - Cisco Blogs

SECURITY.COM

Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For Your DLP Incident Backlog Owes You Closure 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Locking Down the Server Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 5 Ways To Keep AI in Check DLP Made Easier on the Teams Running It Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? For Financial Services, a Wake-Up Call for Reclaiming IAM Control How Cloud-Managed DLP Lowers the Barrier to Entry As Identity Takes Control, Telecom Needs Repatriated IAM Capable of Keeping Up Post-Quantum Security Starts at the Edge The Public Sector Case for Repatriating IAM in the Age of AI The Data Sovereignty Paradox The Unseen Wall: How Billions of Attacks Were Blocked in 2025 The “Zero-Blindness” Roadmap: Achieving Maturity in the DLP Endpoint Workspace IAM Has a Fix for the Modern Identity Crisis Identity is the Control Plane, and AI Just Changed the Game
3 Ways to Defend Against LOTL Attacks Now
About the Author · 2026-07-20 · via SECURITY.COM
  • Trusted tools have become one of attackers’ favorite hiding places.
  • Stopping living off the land (LOTL) attacks requires more than detection. It requires limiting opportunities for abuse, anticipating attacker behavior, and being the first one to connect the dots.
  • Three groundbreaking, AI-driven protections each defend a different stage of the same problem.

Attackers are practical. If they can borrow your tools, why bring their own?

A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues to drive the appeal. After all, the best disguise has always been looking like you belong.

Recent research shows nearly all threat actors are deploying living off the land (LOTL) techniques, using legitimate software to host and launch attacks. 

For a long time, malicious activity announced itself by breaking everyday operations or looking out of place. LOTL changed that. Though the tool may belong and the command may be routine, there’s a persistent challenge in recognizing when normal activity starts looking out of place.

The best LOTL defenses aren’t comprised of a single defense mechanism. They come from doing three things well: making trusted tools harder to misuse, anticipating where attackers will pivot next, and connecting evidence before small events become much bigger problems.

1. Make trusted tools harder to misuse with Adaptive Protection

LOTL attacks put defenders in an uncomfortable position. The tools being abused are often the very ones your organization relies on every day. Blocking them outright isn’t an option. Teams need to administer systems, deploy software, troubleshoot endpoints, and keep work moving.

Adaptive Protection addresses that challenge with behavior-based controls designed to limit misuse of legitimate tools before suspicious activity escalates. Adaptive Protection monitors an organization’s typical use of software and uses those normal behaviors as a baseline for usage policy. From that point on, it automatically blocks behaviors that fall outside the parameters set by the normal usage policy. Rather than chasing every new technique, it narrows an attacker’s ability to operate within tools everyone already trusts.

It’s an approach backed by years of independent validation, reinforcing the value of behavior-based prevention as attackers continue to feed off legitimate business activity.

2. Anticipate the next move with Incident Prediction

Most alerts arrive late to the party. By the time a questionable remote session reaches an analyst, an attacker may have already tested an account, mapped a few systems, and learned which controls react—and which don’t. The attacker gets feedback in seconds. The analyst gets a ticket.

Incident Prediction

uses attack-trained AI and native telemetry correlation to help teams look beyond the alert in front of them and identify where an attacker is likely to go next. This gives analysts a clearer picture of where suspicious activity is headed, creating an opportunity to disrupt the attack before it gains momentum.

In LOTL attacks, individual events rarely tell the whole story. Looking at how activity unfolds over time helps teams prioritize what matters most 

while there’s still time to respond

. And predicting what will happen next? That’s next level defense against all threats, including LOTL attacks.

3. Connect the dots with Threat Tracer

SOCs rarely struggle with a lack of data. They struggle because they lack context. Endpoint activity, network connections, identity events, and data access live in different places, forcing analysts to piece together an attack while it’s still unfolding.

Threat Tracer helps connect those signals within a single console. Correlating activity across users, devices, processes, network behavior, and file metadata gives analysts a clearer view of the attack—and where to focus first. This is a huge benefit for all analysts, from beginners to experts.

Built on Carbon Black’s pioneering’ EDR capabilities, Threat Tracer helps analysts visualize the full blast radius of an attack instead of manually chasing and connecting disconnected alerts. The result is faster, more focused investigations—and greater confidence you’re responding to the right thing. 

Unified defenses with Symantec CBX

Attackers don’t care where one security product ends and another begins. They care whether the next move works.

That’s where Symantec CBX comes in. CBX brings together Adaptive Protection, Incident Prediction, and Threat Tracer into a single, unified platform—giving security teams the full picture they need to investigate faster and respond with confidence. In addition, CBX correlates signals from across endpoints, networks, SaaS applications, and data to give analysts a comprehensive view of what’s happening at any moment. Analysts can stop guessing and take defensive action sooner.

Catch CBX Fest live or on-demand for a deeper look at how these capabilities come together.

Feeling lost? Here are a couple FAQs. 

What are living-off-the-land attacks?

Living-off-the-land (LOTL) attacks use legitimate tools, applications, and system processes that are already present in an environment to carry out malicious activity. Because attackers rely on trusted resources instead of custom malware, LOTL techniques are often harder to detect using traditional, signature-based security controls.

Why are LOTL attacks difficult to detect?

LOTL attacks blend into normal operations by using legitimate tools, valid credentials, and routine administrative activity. Individual events may appear harmless on their own, making it difficult to distinguish malicious behavior without understanding the broader sequence of events and the context surrounding them.

How can organizations defend against LOTL attacks?

Effective LOTL defense combines behavior-based prevention, visibility into likely attacker behavior, and connected investigation capabilities. Rather than focusing only on malware, organizations should look for suspicious use of legitimate tools, anticipate how attacks may progress, and correlate activity across endpoint, network, identity, and data to detect and stop attacks sooner.

You might also enjoy

3 Ways to Defend Against LOTL Attacks Now

Shanleigh Reardon

Shanleigh Reardon

Product Marketing Manager