T1220Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1220: Technique T1220

Adversaries may leverage living-off-the-land techniques (T1220) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 2
Windows: 2
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1220

Across 2 verified binaries
Windows3 payloads

winrm.vbs

Script used for manage Windows RM settings

Sample Attack Vector:
winrm invoke Create wmicimv2/Win32_Process @{CommandLine="{CMD}"} -r:http://target:5985
Windows6 payloads

msxsl.exe

Command line utility used to perform XSL transformations.

Sample Attack Vector:
msxsl.exe {PATH:.xml} {PATH:.xsl}
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point