Gourav Nagar at Upwind explains why you can’t stop the new breed of Living off the Land attacks with static security models

Living-off-the-land (LOTL) is not a new concept. Security teams have been tracking Living-off-the-Land Binary (LOLBin) attacks for over a decade, watching adversaries reach for PowerShell, WMI, and Certutil rather than dropping custom malware that might trigger an alert. But the way those tools are being weaponised today is a fundamentally different proposition.
Attackers are no longer abusing individual native binaries in isolation but are increasingly chaining legitimate processes together in sequences. With each step being largely indistinguishable from routine operations, they can build towards a malicious result with a very high chance of remaining undetected.
Many security teams are trying to answer this new threat with a visibility model built for a slower, more friction-laden attacker. Defences need the ability to detect and stop these extremely stealthy intruders before it’s too late.
Most security programmes still depend on periodic scans, posture checks, and point-in-time asset inventories. These are all valuable capabilities against other threats, but they’re effectively blind to a threat actor operating entirely within your existing tooling.
The biggest issue with this periodic approach is that a snapshot captures a configuration that has already moved on. This gap has become increasingly dangerous as attackers have sped up. Research has found that attackers achieved lateral movement in an average of just 29 minutes last year, with the fastest moving in mere seconds.
Further, as many as 84% of high-severity attacks now involve LOTL techniques, meaning the threat that snapshot security is least equipped to catch is also the most prevalent driver of serious incidents.
Running agentless scans on a 24-hour cycle might feel like enough of a handle on incoming threats, but it’s no match for adversaries that can achieve lateral movement in the space of a coffee break.
Add in the subtle nature of a well-executed LOTL attack, and defenders have no chance of catching up. Closing that gap requires watching execution in real time - not reviewing a snapshot of where things stood at last scan.
Legitimate binaries become weapons not because of what they are, but because of how they are being used. Countering this means making two connected shifts: from asset inventory to execution-layer observability, and from evaluating events in isolation to correlating them across layers and over time.
The first shift addresses a fundamental blind spot. Knowing what exists in your environment is not the same as knowing what it is doing. Against a LOLBin attack, configuration data is largely insufficient because the attack is in the behaviour, not the configuration.
Consider a threat that appears, is resolved, and reappears two days later via the same process on a slightly different path. Without context connecting those events, defenders will likely treat each occurrence as a new incident, missing the wider pattern.
Runtime observability is essential here, providing visibility into suspicious activity while workloads are actively running. This closes that gap by maintaining a continuous, correlated record of what is actually executing across the API layer, the network layer, and the process execution layer simultaneously.
The second shift is equally critical. Each step in a LOLBin attack looks entirely legitimate in isolation: a PowerShell process launches, a credential store is queried, a network connection is opened. None of those events, reviewed individually, would trouble most detection systems.
Instead, it’s the sequence that reveals the presence of an attacker. The order of execution and combination of actions can reveal malicious intent, even if the individual actions are seemingly benign. These signs might be spread across different tools, environments, and targets, so detection needs to see across the whole chain to notice the attack.
The third shift is perhaps most fundamental. Signature-based detection was built to answer one question, “does this file or process match a known malicious pattern?” Against LOTL attacks, that question is no longer the right question. The tools and signatures are clean, so the only thing left is the intent behind their use.
The practical failure of signature-based approaches lies not just in their inability to detect novel threats, but also in the noise they produce at an industrial scale. Every legitimate invocation of a native binary becomes a potential alert, so security teams end up sifting through vast volumes of activity that looks suspicious by signature but is entirely benign in context, while the genuinely malicious execution chain passes through undetected.
Attackers have already adapted to this, using AI to generate multiple simultaneous payload variations and constantly cycling signatures to stay ahead of pattern-matching defences. Syntax-matching has a ceiling, and adversaries have found it.
The threat of LOTL attacks is growing rapidly, with 79% of last year’s detections involving malware-free attacks. Simply being able to identify malicious tools is no longer enough; we must also be able to identify malicious use of legitimate ones. And with attackers striking faster and harder than ever, this must happen in real time, before the chain completes.
Gourav Nagar is Head of Information Security at Upwind
Main image courtesy of iStockPhoto.com and TU IS
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543