LOLBAS stands for Living Off the Land Binaries And Scripts, a type of activity that misuses tools and executables that are already there because they are part of the operating system. To cite the LOLBAS’ project’s criteria, a LOLBin/lib/script must:
Be a Microsoft-signed file, either native to the OS or downloaded from Microsoft.
Have extra “unexpected” functionality. It is not interesting to document intended use cases.
Have functionality that would be useful to an APT or red team.
The ESA Activity Monitoring rules for monitoring LOLBAS activity are vast limits vendor rules. They are stored in the configuration file uberAgent-ESA-am-vastlimits.conf.
LOLBAS Rules
The rules in this section detect suspicious behavior related to operating system binaries.
LOLBAS Monitoring
In this article
LOLBAS stands for Living Off the Land Binaries And Scripts, a type of activity that misuses tools and executables that are already there because they are part of the operating system. To cite the LOLBAS’ project’s criteria, a LOLBin/lib/script must:
The ESA Activity Monitoring rules for monitoring LOLBAS activity are vast limits vendor rules. They are stored in the configuration file
uberAgent-ESA-am-vastlimits.conf
.LOLBAS Rules
The rules in this section detect suspicious behavior related to operating system binaries.