Living Off the Land (LOTL) Resources

Living Off the Land (LOTL) Resources

Views: 5

🌿 Living Off the Land (LOTL) Resources πŸ—ΊοΈ

🎯 Attackers don’t always bring their own tools. Sometimes the best weapon is already sitting on the machine. This guide walks through a well-organized collection of Living Off the Land (LOTL) catalogs, grouped by category, so defenders, red teamers, and researchers know where to look.


πŸ€” What Is “Living Off the Land”?

LOTL means abusing legitimate, trusted tools and processes that already exist in an environment, instead of dropping custom malware. Because the activity comes from software that is supposed to be there, it blends into normal operations and is much harder to spot.

The resources below catalog these techniques so you can understand them, hunt for them, and defend against them. πŸ›‘οΈ


πŸ–₯️ 1. Operating System Binaries and Scripts

Built-in OS tools that can be bent to do things they were never meant to do.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
GTFOArgsUnix binaries that can be exploited through argument injectiongtfoargs.github.io
GTFOBinsUnix binaries that help bypass local security restrictionsgtfobins.github.io
LOLBASWindows binaries, scripts, and librarieslolbas-project.github.io
LOOBins“Living Off the Orchard” – abusable macOS binariesloobins.io
LOLESXiBinaries and scripts in VMware ESXi that adversaries uselolesxi-project.github.io
WTFBinsSuspicious Windows binaries and how they behavewtfbins.wtf

βš™οΈ 2. Drivers and Low-Level Components

Going deeper than the OS layer, down to boot and kernel territory.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
BootloadersKnown malicious bootloaders across operating systemsbootloaders.io
LOLDriversVulnerable and malicious Windows driversloldrivers.io

πŸ“¦ 3. Applications and Tools

Software that’s installed on purpose, and sometimes abused anyway.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
LOLAPPSBuilt-in and third-party apps misused for malicious endslolapps-project.github.io
LOLRMMRemote Monitoring and Management tools that attackers can repurposelolrmm.io

πŸ”Œ 4. Hardware and Firmware

The physical side of LOTL.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
LOTHIdentifying and using malicious hardware and deviceslothardware.com.tr

πŸ₯· 5. Evasion and Exploitation Techniques

How attackers slip past defenses and turn trusted components against their owners.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
Argument Injection VectorsExploitable options behind argument injection bugssonarsource.github.io
EvasionsUnderstanding and applying a wide range of evasion techniquesevasions.checkpoint.com
HijackLibsDLL hijacking techniques and the libraries that are vulnerablehijacklibs.net
LOFLCmdlets and binaries for remote activity and unusual persistencelofl-project.github.io
LOTDDev tools in CI/CD pipelines that offer remote code executionboostsecurityio.github.io/lotp
LOTS Project“Living Off Trusted Sites” – legitimate domains attackers can abuselots-project.com
LOTTunnelsDigital tunnels used for exfiltration, persistence, and morelottunnels.github.io
LOTWebhooksWebhooks exploited for data theft and C2 trafficlotwebhooks.github.io
SploitifyDatabase of exploits and vulnerabilities for systems and appssploitify.haxx.it

πŸ” 6. Persistence Mechanisms

Staying put after the initial foothold.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
Persistence InfoWindows persistence techniques, with detection and mitigation in mindpersistence-info.github.io

πŸ” 7. Certificates and Trust

When a valid signature becomes a disguise.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
LOLCertsCode signing certificates abused by threat actorsgithub.com/WithSecureLabs/lolcerts

πŸ“‘ 8. Command and Control

Hiding C2 traffic inside legitimate services.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
LOLC2C2 frameworks that ride on legitimate services to avoid detectionlolc2.github.io

🏒 9. Active Directory and Windows-Specific

Everything for the heart of the enterprise.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
LOLADA broad set of Active Directory techniques for offensive operationslolad-project.github.io
WADComsOne-liners and commands for Windows AD environmentswadcoms.github.io

🧬 10. APIs and Malware Analysis

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
MalAPIWindows API reference for malware analysis and red teamingmalapi.io

🎲 11. Miscellaneous

A few extras that don’t fit neatly elsewhere.

πŸ”§ ProjectπŸ“ What It Covers🌐 Link
FileSecFile extensions and the security risks tied to eachfilesec.io
LOLBins CTI DrivenGraphical view of how threat actors use LOLBinslolbins-ctidriven.vercel.app
Project LostLesser-known techniques and tools for red teaming and pentesting0xanalyst.github.io/Project-Lost

πŸš€ Final Thoughts

LOTL attacks work because they exploit trust: trusted binaries, trusted drivers, trusted domains, trusted certificates. Knowing what’s abusable in your environment is the first step toward detecting it.

πŸ’‘ Bookmark this list, and use it to sharpen your threat hunting, detection logic, and hardening priorities.

#LOTL #LivingOffTheLand #CyberSecurity #ThreatHunting #BlueTeam #RedTeam