T1040: Technique T1040
Adversaries may leverage living-off-the-land techniques (T1040) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 2
•
Windows: 2
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1040
Across 2 verified binariesWindows2 payloads
Pktmon.exe
Capture Network Packets on the windows 10 with October 2018 Update or later.
Sample Attack Vector:
pktmon.exe start --etwWindows1 payloads
Nmcap.exe
Command-line packet capture utility from Microsoft Network Monitor 3.x.
Sample Attack Vector:
nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point