Incident Response: Living off the land, investigating attacks that leave no malware behind
Abstract Proposal: Modern attackers often hide in plain sight by abusing trusted tools already on compromised systems, including PowerShell, WMI, scheduled tasks, RDP, and other built-in utilities. This episode breaks down the LOLBin problem through detection baselines and scoped alerts, separation of legitimate from malicious activity using parent process, arguments, and behavior, and forensic reconstruction from surviving host artifacts, including ScriptBlock logs, WMI subscriptions, task XML, Shimcache, Amcache, prefetch, and RDP/SMB lateral movement.
