Views: 5
πΏ Living Off the Land (LOTL) Resources πΊοΈ
π― Attackers don’t always bring their own tools. Sometimes the best weapon is already sitting on the machine. This guide walks through a well-organized collection of Living Off the Land (LOTL) catalogs, grouped by category, so defenders, red teamers, and researchers know where to look.
π€ What Is “Living Off the Land”?
LOTL means abusing legitimate, trusted tools and processes that already exist in an environment, instead of dropping custom malware. Because the activity comes from software that is supposed to be there, it blends into normal operations and is much harder to spot.
The resources below catalog these techniques so you can understand them, hunt for them, and defend against them. π‘οΈ
π₯οΈ 1. Operating System Binaries and Scripts
Built-in OS tools that can be bent to do things they were never meant to do.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| GTFOArgs | Unix binaries that can be exploited through argument injection | gtfoargs.github.io |
| GTFOBins | Unix binaries that help bypass local security restrictions | gtfobins.github.io |
| LOLBAS | Windows binaries, scripts, and libraries | lolbas-project.github.io |
| LOOBins | “Living Off the Orchard” β abusable macOS binaries | loobins.io |
| LOLESXi | Binaries and scripts in VMware ESXi that adversaries use | lolesxi-project.github.io |
| WTFBins | Suspicious Windows binaries and how they behave | wtfbins.wtf |
βοΈ 2. Drivers and Low-Level Components
Going deeper than the OS layer, down to boot and kernel territory.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| Bootloaders | Known malicious bootloaders across operating systems | bootloaders.io |
| LOLDrivers | Vulnerable and malicious Windows drivers | loldrivers.io |
π¦ 3. Applications and Tools
Software that’s installed on purpose, and sometimes abused anyway.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| LOLAPPS | Built-in and third-party apps misused for malicious ends | lolapps-project.github.io |
| LOLRMM | Remote Monitoring and Management tools that attackers can repurpose | lolrmm.io |
π 4. Hardware and Firmware
The physical side of LOTL.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| LOTH | Identifying and using malicious hardware and devices | lothardware.com.tr |
π₯· 5. Evasion and Exploitation Techniques
How attackers slip past defenses and turn trusted components against their owners.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| Argument Injection Vectors | Exploitable options behind argument injection bugs | sonarsource.github.io |
| Evasions | Understanding and applying a wide range of evasion techniques | evasions.checkpoint.com |
| HijackLibs | DLL hijacking techniques and the libraries that are vulnerable | hijacklibs.net |
| LOFL | Cmdlets and binaries for remote activity and unusual persistence | lofl-project.github.io |
| LOTD | Dev tools in CI/CD pipelines that offer remote code execution | boostsecurityio.github.io/lotp |
| LOTS Project | “Living Off Trusted Sites” β legitimate domains attackers can abuse | lots-project.com |
| LOTTunnels | Digital tunnels used for exfiltration, persistence, and more | lottunnels.github.io |
| LOTWebhooks | Webhooks exploited for data theft and C2 traffic | lotwebhooks.github.io |
| Sploitify | Database of exploits and vulnerabilities for systems and apps | sploitify.haxx.it |
π 6. Persistence Mechanisms
Staying put after the initial foothold.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| Persistence Info | Windows persistence techniques, with detection and mitigation in mind | persistence-info.github.io |
π 7. Certificates and Trust
When a valid signature becomes a disguise.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| LOLCerts | Code signing certificates abused by threat actors | github.com/WithSecureLabs/lolcerts |
π‘ 8. Command and Control
Hiding C2 traffic inside legitimate services.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| LOLC2 | C2 frameworks that ride on legitimate services to avoid detection | lolc2.github.io |
π’ 9. Active Directory and Windows-Specific
Everything for the heart of the enterprise.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| LOLAD | A broad set of Active Directory techniques for offensive operations | lolad-project.github.io |
| WADComs | One-liners and commands for Windows AD environments | wadcoms.github.io |
𧬠10. APIs and Malware Analysis
| π§ Project | π What It Covers | π Link |
|---|---|---|
| MalAPI | Windows API reference for malware analysis and red teaming | malapi.io |
π² 11. Miscellaneous
A few extras that don’t fit neatly elsewhere.
| π§ Project | π What It Covers | π Link |
|---|---|---|
| FileSec | File extensions and the security risks tied to each | filesec.io |
| LOLBins CTI Driven | Graphical view of how threat actors use LOLBins | lolbins-ctidriven.vercel.app |
| Project Lost | Lesser-known techniques and tools for red teaming and pentesting | 0xanalyst.github.io/Project-Lost |
π Final Thoughts
LOTL attacks work because they exploit trust: trusted binaries, trusted drivers, trusted domains, trusted certificates. Knowing what’s abusable in your environment is the first step toward detecting it.
π‘ Bookmark this list, and use it to sharpen your threat hunting, detection logic, and hardening priorities.
#LOTL #LivingOffTheLand #CyberSecurity #ThreatHunting #BlueTeam #RedTeam

