T1220: Technique T1220
Adversaries may leverage living-off-the-land techniques (T1220) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 2
•
Windows: 2
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1220
Across 2 verified binariesWindows3 payloads
winrm.vbs
Script used for manage Windows RM settings
Sample Attack Vector:
winrm invoke Create wmicimv2/Win32_Process @{CommandLine="{CMD}"} -r:http://target:5985Windows6 payloads
msxsl.exe
Command line utility used to perform XSL transformations.
Sample Attack Vector:
msxsl.exe {PATH:.xml} {PATH:.xsl}Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point