To access material, start machines and answer questions login.
In the world of cyber security defense, there is a heavy reliance on scanning files on disk to detect malicious programs and payloads. To bypass this, modern attackers adapt by living off the land, abusing trusted, signed operating system tools (LOLBins), and executing malicious code directly inside memory. In this room, you will explore these techniques, get hands-on practice executing them, and learn what detections you can count on to catch them when they occur.
Learning Objectives
- Understand what LOLBins are, why attackers use them, and which trusted binaries are commonly abused
- Explore how attackers abuse Living Off the Land Binaries (LOLBins) from an adversary's perspective
- Identify and investigate usage through Windows event logs and forensic artifacts
- Understand fileless techniques and how attackers use them to minimize their footprint
- Practice executing common fileless techniques, including registry-based and in-memory execution
- Detect and analyze fileless attacks using relevant log sources and artifacts
Prerequisites
Familiarity with , Windows Event Logs, and is recommended for this walkthrough. A solid understanding of Windows forensic artifacts and detection techniques will also be beneficial.
- Cover Living Off the Land Attacks for an overview of trusted binary abuse
- Go through Windows Event Logs to learn about important event types
- Check out Sysmon to explore event and important logging fields
- Complete Investigating Executables Evidence to learn about tracking file execution
Machine Access
Click the Start Machine button below. The machine will start in Split-Screen mode. Once you gain access, all necessary tools and files will be available on the machine's desktop.
Set up your virtual environment
If you prefer to connect using your own -connected machine, please use the credentials below to in:
Credentials
Only needed if you are using your own machine.
I understand the learning objectives and am ready to learn about LOLBins and fileless techniques!
Ready to learn Cyber Security?
The Investigating LOLBin and Fileless room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
