T1562.001: Technique T1562.001
Adversaries may leverage living-off-the-land techniques (T1562.001) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 3
•
Windows: 1
•
Linux: 0
•
macOS: 2
Living-off-the-Land Matrix for T1562.001
Across 3 verified binariesWindows1 payloads
fltMC.exe
Filter Manager Control Program used by Windows
Sample Attack Vector:
fltMC.exe unload SysmonDrvmacOS1 payloads
tccutil
Tccutil manages the Transparency, Consent, and Control (TCC) privacy database. Attackers reset permissions for applications to force prompt re-evaluation or test TCC bypasses.
Sample Attack Vector:
tccutil reset All com.apple.TerminalmacOS1 payloads
networksetup
Networksetup configures macOS network preferences. Attackers abuse it to configure rogue HTTP web proxies or reassign DNS servers to malicious resolvers.
Sample Attack Vector:
networksetup -setwebproxy "Wi-Fi" 127.0.0.1 8080Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point