SEC.co Podcast

Attackers don't need custom malware when your own trusted, pre-installed tools can do the job. This episode unpacks LOLBAS — how threat actors weaponize legitimate system utilities and what defenders must do to stop them.

Show Notes

Your operating system ships with powerful, digitally signed utilities that administrators rely on every day — and so do attackers. This episode of Cybersecurity explores LOLBAS (Living Off the Land Binaries and Scripts), a post-compromise technique in which threat actors turn an organization's own trusted tools against it. Drawing on this in-depth look at LOLBAS tradecraft and defenses, the episode walks through why the technique is so effective, why it frustrates traditional defenses, and what a realistic hardening and detection strategy actually looks like.
Here's what this episode covers:
  • Why LOLBAS works: Vendor-signed binaries inherit implicit trust from endpoint security tools, meaning fewer alerts fire — the attacker is wearing a uniform that already belongs inside the building.
  • The defender's core challenge: Because the files themselves are legitimate, the question shifts from "is this binary bad?" to "is this behavior intentional?" — moving the entire game from signature matching to intent detection.
  • What malicious use actually looks like: The episode maps attacker actions to observable verbs — collection, staging, lateral movement, persistence, and cleanup — and explains how to spot those patterns in telemetry without drowning in noise.
  • Building the right visibility: Effective detection requires process ancestry data, identity context, network signals, and cloud telemetry stitched together into coherent timelines — not just a flat list of process events.
  • Hardening without breaking the business: Thoughtful application control, script guardrails with signing enforcement and block logging, and just-in-time prompting for sensitive actions can narrow the attack surface without crippling operations.
  • Testing your assumptions: Tabletop and lab exercises using only native tools help teams measure detection speed, analyst pivot time, and false-positive rates — treating every surprise as a gap that needs closing before it matters for real.
The central takeaway: tools are neutral, and context is everything. Defenders who chase file reputation will keep losing ground; defenders who watch behavior, identity, and timing can hear the threat early enough to act. For more from the show on protecting high-value targets from sophisticated adversaries, check out the episode iOS Lockdown Mode for Executives: Protecting High-Risk iPhones from Targeted Attacks.
SEC

What is SEC.co Podcast ?

A podcast about latest trends, techniques and learnings in cybersecurity and cyberdefense.