Living Off The Land (lotl) - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 6, 2026
Last Seen
January 6, 2026

Living Off The Land (LOTL) is a MITRE ATT&CK technique in which attackers abuse legitimate system tools and processes (such as PowerShell, WMI, certutil, and other built-in utilities) to carry out malicious actions.

Overview

Living Off The Land (LOTL) is a MITRE ATT&CK technique in which attackers abuse legitimate system tools and processes (such as PowerShell, WMI, certutil, and other built-in utilities) to carry out malicious actions. This approach helps adversaries evade detection, perform lateral movement, and persist without introducing new binaries. In MSP and enterprise environments, LOTL is significant because it leverages trusted tools, making it harder for defenders to distinguish malicious activity from normal operations.

Related Threat Clusters

  • Increase in Cyber Attacks on SMBs in 2026

    Managed Service Providers (MSPs) report a rise in cyber attacks targeting small and medium businesses that lack adequate security measures. The shift from traditional reactive defense strategies to a more proactive,…

    2 articles · Updated January 6, 2026

Recent Intelligence Reports

  • How MSPs Can Shift to Human, Prevention-Driven Defense in 2026 — Bitdefender · January 6, 2026

Related Entities

CVSS v3.1 Breakdown