| name | hunting-for-lolbins-execution-in-endpoint-logs |
| description | Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing endpoint process creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when hunting for adversary abuse of living off the land binaries. |
| domain | cybersecurity |
| tags | ["threat-hunting","lolbins","living-off-the-land","endpoint-detection","process-monitoring","mitre-t1218","defense-evasion"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Executable Denylisting","Execution Isolation","File Metadata Consistency Validation","Application Protocol Command Analysis","Content Format Conversion"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Lolbins Execution In Endpoint Logs
Overview
Cybersecurity skill for hunting for lolbins execution in endpoint logs. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for lolbins execution in endpoint logs"
-
"Hunt for adversary abuse of Living Off the Land Binaries (LOLBins) by analyzing "
-
When hunting for fileless attack techniques that abuse built-in Windows binaries
-
After threat intelligence indicates LOLBin-based campaigns targeting your industry
-
When investigating alerts for suspicious use of certutil, mshta, rundll32, or regsvr32
-
During purple team exercises testing detection of defense evasion techniques
-
When assessing endpoint detection coverage for MITRE ATT&CK T1218 sub-techniques
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Sysmon Event ID 1 (Process Creation) with full command-line logging
- Windows Security Event ID 4688 with command-line auditing enabled
- EDR telemetry with parent-child process relationships
- SIEM platform for query and correlation (Splunk, Elastic, Microsoft Sentinel)
- LOLBAS project reference (lolbas-project.github.io) for known abuse patterns
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}