T1562.001Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1562.001: Technique T1562.001

Adversaries may leverage living-off-the-land techniques (T1562.001) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 3
Windows: 1
Linux: 0
macOS: 2

Living-off-the-Land Matrix for T1562.001

Across 3 verified binaries
Windows1 payloads

fltMC.exe

Filter Manager Control Program used by Windows

Sample Attack Vector:
fltMC.exe unload SysmonDrv
macOS1 payloads

tccutil

Tccutil manages the Transparency, Consent, and Control (TCC) privacy database. Attackers reset permissions for applications to force prompt re-evaluation or test TCC bypasses.

Sample Attack Vector:
tccutil reset All com.apple.Terminal
macOS1 payloads

networksetup

Networksetup configures macOS network preferences. Attackers abuse it to configure rogue HTTP web proxies or reassign DNS servers to malicious resolvers.

Sample Attack Vector:
networksetup -setwebproxy "Wi-Fi" 127.0.0.1 8080
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point