LOLBins Guide

Living off the Land binaries, or LOLBins, are one of the most effective tools in a threat actor's kit—because they're not added tools at all. They're the software already sitting on your systems: PowerShell, PsExec, certutil, and dozens of other trusted, signed programs that ship with Windows. Attackers don't need to sneak in new malware when they can just use what's already there.

That's what makes LOLBins so hard to catch—and so important to understand. They give attackers a way into your network that often avoids triggering a traditional malware alert, because there's no obvious payload to scan for and the activity can blend in with everyday admin work.

Let our LOLBins guide show you what to look for.

Want to see Huntress Managed Platform in action?

Get your organization up to speed with the Huntress Agentic Security Platform and give your team 24/7 eyes on the behaviors that traditional antivirus often misses. LOLBins aren't going away, but with the right visibility, they're a lot harder to hide behind.

Learn More