LOLBins Guide & Resources by Huntress
Threat actors have caught on to something simple: the fewer new files they bring into your environment, the less likely anyone is to notice them. LOLBins let them move through your systems using tools your team already trusts, which means traditional antivirus often has nothing obvious to flag. Understanding how this works is just as important as any tool you put in place to stop it.
We built this hub because LOLBins are quietly becoming one of the most common ways threat actors move through a network undetected. Learn all the basics and then some: get a solid grasp on what LOLBins are, why they work so well against traditional defenses, and how to spot the signs that a trusted tool is being used against you.
Who it's for: Whether you're an IT pro, a SOC analyst, or a business owner who wants to understand what's really running on your network, you'll find resources here to help you recognize LOLBin activity and build a plan to catch it.
How it helps your business: Our guide shows you exactly how threat actors turn everyday tools into a way in, and what to watch for so you can catch it early. You'll walk away knowing which binaries to keep an eye on and how to build detection that goes beyond just scanning for malware.
There are plenty of reasons we put this LOLBins guide together. Our SOC analysts see this pattern play out constantly—an attacker skips the obvious malware and goes straight for PowerShell or a scheduled task instead, because they know it's less likely to be flagged the same way. But we also see how much harder that gets for them once a team knows what normal looks like and has eyes on the behavior, not just the file. With the right knowledge and the right monitoring, you can catch attackers even when they're hiding in plain sight.