Living Off The Land: Suspicious System32

Amoranio 🚀
InfoSec Write-ups
Published in
7 min readJan 21, 2022

--

The services below are some of the most commonly abused services for malicious parties to “live of the land”. Each are built into Windows and inherit trust by default. Because of this, security controls won’t ever be able to fully isolate them without affecting the operating system. For example, your endpoint protection can’t block command prompt and Powershell because engineers use them for automation tasks, nor can…

--

--