Living Off The Land (LOTL) is a MITRE ATT&CK technique in which attackers abuse legitimate system tools and processes (such as PowerShell, WMI, certutil, and other built-in utilities) to carry out malicious actions.
Overview
Living Off The Land (LOTL) is a MITRE ATT&CK technique in which attackers abuse legitimate system tools and processes (such as PowerShell, WMI, certutil, and other built-in utilities) to carry out malicious actions. This approach helps adversaries evade detection, perform lateral movement, and persist without introducing new binaries. In MSP and enterprise environments, LOTL is significant because it leverages trusted tools, making it harder for defenders to distinguish malicious activity from normal operations.
Related Threat Clusters
-
Increase in Cyber Attacks on SMBs in 2026
Managed Service Providers (MSPs) report a rise in cyber attacks targeting small and medium businesses that lack adequate security measures. The shift from traditional reactive defense strategies to a more proactive,…
2 articles · Updated January 6, 2026
Recent Intelligence Reports
- How MSPs Can Shift to Human, Prevention-Driven Defense in 2026 — Bitdefender · January 6, 2026