During an investigation, you observe an attacker using 'living-off-the-land' (LotL) techniques. Why is it difficult to detect this activity using traditional signature-based antivirus?
LotL techniques leverage legitimate tools that are signed and trusted by the OS. Antivirus signatures are designed to identify known malicious code; because the binaries themselves are benign, the AV ignores them. Detection must focus on the suspicious flags and command-line arguments, which AV does not typically inspect.
Why this answer
Living-off-the-land attacks use legitimate, signed system binaries (like PowerShell, wmic, or certutil) to perform malicious actions. Since the tools themselves are trusted components of the operating system, antivirus software rarely flags them as malicious. Detecting LotL requires behavioral analysis, command-line logging, and monitoring for anomalous execution patterns rather than relying on file signatures, which are ineffective against tools that are inherently part of the system's baseline.
Exam trap
Candidates often assume that because the binary is 'trusted' or 'signed,' it cannot be used for malicious purposes, leading them to overlook the malicious intent hidden within the command-line arguments.