惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
罗磊的独立博客
U
Unit 42
I
InfoQ
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
Microsoft Security Blog
Microsoft Security Blog
月光博客
月光博客
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
博客园_首页
腾讯CDC
F
Fortinet All Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
MongoDB | Blog
MongoDB | Blog
阮一峰的网络日志
阮一峰的网络日志
D
Docker
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Azure Blog
Microsoft Azure Blog
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
V
V2EX
Last Week in AI
Last Week in AI
博客园 - 司徒正美
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
L
LangChain Blog
WordPress大学
WordPress大学
Y
Y Combinator Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
M
MIT News - Artificial intelligence
The Cloudflare Blog
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享

SECURITY.COM

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor The Detection Gap: MITRE ATT&CK T1140 and T1105 Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For AV-TEST Gives Symantec® Endpoint Security Complete a Perfect Score The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Your DLP Incident Backlog Owes You Closure Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Another Year, Another Win: SE Labs® Recognizes Symantec® Endpoint Security Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden Locking Down the Server 🎙️SECURITY.COM The Podcast: The Death of SIEM Threats Rise on a Tide of Global Unrest When Nation-States Stop Caring About Size Espionage Campaign Targeted Stock Exchange Executive for Five Months Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 🎙️SECURITY.COM The Podcast: The Evolution of Cybersecurity PR with W2 Communications The Maximalism Trap: When More Becomes Too Much Symantec DLP Cloud and DPSM are the Power Couple Security Strategists Need Symantec DLP Cloud and DSPM are the Power Couple Security Strategists Need The Future of the Partnership: AI, Automation, and Ecosystems Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations 🎙️SECURITY.COM The Podcast: Iran’s Cyber Warfare Playbook: What Defenders Need to Know Right Now 5 Ways To Keep AI in Check Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign Doing More with Less: How Government Agencies are Rethinking Cybersecurity Navigating Compliance and Insurance as a Competitive Edge Is SIEM Trying to Do Too Much? Every Defender Deserves Frontier AI The New Partner-Vendor Relationship DLP Made Easier on the Teams Running It The EU Digital Wallet: Why Waiting is Not an Option Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft Stopping Data Leaks at the Speed of AI Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor How AI Increases the Load on Security Teams Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? Technical Enablement vs. Marketing Noise Enterprise-Grade Security for All in 2026 Architecting for Margin Beyond the Initial Sale 🎙️SECURITY.COM The Podcast: A Brief History of Data Loss Prevention Symantec CBX Through the Paparazzi Lens The U.S. Navy’s Playbook for Cost-Controlled, Reliable Cybersecurity The Modern Threat Landscape and The Partner’s New Burden Symantec CBX Rocked RSAC 2026 Conference For Financial Services, a Wake-Up Call for Reclaiming IAM Control The Next Identity Shift Cyber Legends: Behind the Scenes of CBX Built for This Moment (and All Those to Come)
3 Ways to Defend Against LOTL Attacks Now
About the Author · 2026-07-20 · via SECURITY.COM
  • Trusted tools have become one of attackers’ favorite hiding places.
  • Stopping living off the land (LOTL) attacks requires more than detection. It requires limiting opportunities for abuse, anticipating attacker behavior, and being the first one to connect the dots.
  • Three groundbreaking, AI-driven protections each defend a different stage of the same problem.

Attackers are practical. If they can borrow your tools, why bring their own?

A signed binary, A remote management utility. A script interpreter doing exactly what it was installed to do. None of it looks inherently hostile. That’s what continues to drive the appeal. After all, the best disguise has always been looking like you belong.

Recent research shows nearly all threat actors are deploying living off the land (LOTL) techniques, using legitimate software to host and launch attacks. 

For a long time, malicious activity announced itself by breaking everyday operations or looking out of place. LOTL changed that. Though the tool may belong and the command may be routine, there’s a persistent challenge in recognizing when normal activity starts looking out of place.

The best LOTL defenses aren’t comprised of a single defense mechanism. They come from doing three things well: making trusted tools harder to misuse, anticipating where attackers will pivot next, and connecting evidence before small events become much bigger problems.

1. Make trusted tools harder to misuse with Adaptive Protection

LOTL attacks put defenders in an uncomfortable position. The tools being abused are often the very ones your organization relies on every day. Blocking them outright isn’t an option. Teams need to administer systems, deploy software, troubleshoot endpoints, and keep work moving.

Adaptive Protection addresses that challenge with behavior-based controls designed to limit misuse of legitimate tools before suspicious activity escalates. Adaptive Protection monitors an organization’s typical use of software and uses those normal behaviors as a baseline for usage policy. From that point on, it automatically blocks behaviors that fall outside the parameters set by the normal usage policy. Rather than chasing every new technique, it narrows an attacker’s ability to operate within tools everyone already trusts.

It’s an approach backed by years of independent validation, reinforcing the value of behavior-based prevention as attackers continue to feed off legitimate business activity.

2. Anticipate the next move with Incident Prediction

Most alerts arrive late to the party. By the time a questionable remote session reaches an analyst, an attacker may have already tested an account, mapped a few systems, and learned which controls react—and which don’t. The attacker gets feedback in seconds. The analyst gets a ticket.

Incident Prediction

uses attack-trained AI and native telemetry correlation to help teams look beyond the alert in front of them and identify where an attacker is likely to go next. This gives analysts a clearer picture of where suspicious activity is headed, creating an opportunity to disrupt the attack before it gains momentum.

In LOTL attacks, individual events rarely tell the whole story. Looking at how activity unfolds over time helps teams prioritize what matters most 

while there’s still time to respond

. And predicting what will happen next? That’s next level defense against all threats, including LOTL attacks.

3. Connect the dots with Threat Tracer

SOCs rarely struggle with a lack of data. They struggle because they lack context. Endpoint activity, network connections, identity events, and data access live in different places, forcing analysts to piece together an attack while it’s still unfolding.

Threat Tracer helps connect those signals within a single console. Correlating activity across users, devices, processes, network behavior, and file metadata gives analysts a clearer view of the attack—and where to focus first. This is a huge benefit for all analysts, from beginners to experts.

Built on Carbon Black’s pioneering’ EDR capabilities, Threat Tracer helps analysts visualize the full blast radius of an attack instead of manually chasing and connecting disconnected alerts. The result is faster, more focused investigations—and greater confidence you’re responding to the right thing. 

Unified defenses with Symantec CBX

Attackers don’t care where one security product ends and another begins. They care whether the next move works.

That’s where Symantec CBX comes in. CBX brings together Adaptive Protection, Incident Prediction, and Threat Tracer into a single, unified platform—giving security teams the full picture they need to investigate faster and respond with confidence. In addition, CBX correlates signals from across endpoints, networks, SaaS applications, and data to give analysts a comprehensive view of what’s happening at any moment. Analysts can stop guessing and take defensive action sooner.

Catch CBX Fest live or on-demand for a deeper look at how these capabilities come together.

Feeling lost? Here are a couple FAQs. 

What are living-off-the-land attacks?

Living-off-the-land (LOTL) attacks use legitimate tools, applications, and system processes that are already present in an environment to carry out malicious activity. Because attackers rely on trusted resources instead of custom malware, LOTL techniques are often harder to detect using traditional, signature-based security controls.

Why are LOTL attacks difficult to detect?

LOTL attacks blend into normal operations by using legitimate tools, valid credentials, and routine administrative activity. Individual events may appear harmless on their own, making it difficult to distinguish malicious behavior without understanding the broader sequence of events and the context surrounding them.

How can organizations defend against LOTL attacks?

Effective LOTL defense combines behavior-based prevention, visibility into likely attacker behavior, and connected investigation capabilities. Rather than focusing only on malware, organizations should look for suspicious use of legitimate tools, anticipate how attacks may progress, and correlate activity across endpoint, network, identity, and data to detect and stop attacks sooner.

You might also enjoy

3 Ways to Defend Against LOTL Attacks Now

Shanleigh Reardon

Shanleigh Reardon

Product Marketing Manager