T1040Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1040: Technique T1040

Adversaries may leverage living-off-the-land techniques (T1040) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 2
Windows: 2
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1040

Across 2 verified binaries
Windows2 payloads

Pktmon.exe

Capture Network Packets on the windows 10 with October 2018 Update or later.

Sample Attack Vector:
pktmon.exe start --etw
Windows1 payloads

Nmcap.exe

Command-line packet capture utility from Microsoft Network Monitor 3.x.

Sample Attack Vector:
nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point