A common mistake is to assume that a cyberattack necessarily involves a malicious file.
This is not always the case.
An attacker can use legitimate tools already present in the environment.
Specifically, we are talking about:
Living off the Land.
An attacker can exploit:
- PowerShell;
- WMI;
- cmd;
- scripts;
- administration tools;
- cloud services;
- system tools.
The SIEM can then search for unusual behavior rather than simply identifying a file as malicious. The detection techniques and strategies of the MITRE ATT&CK framework can serve as a basis for building detection rules.