A common mistake is to assume that a cyberattack necessarily involves a malicious file.

This is not always the case.

An attacker can use legitimate tools already present in the environment.

Specifically, we are talking about:

Living off the Land.

An attacker can exploit:

  • PowerShell;
  • WMI;
  • cmd;
  • scripts;
  • administration tools;
  • cloud services;
  • system tools.

The SIEM can then search for unusual behavior rather than simply identifying a file as malicious. The detection techniques and strategies of the MITRE ATT&CK framework can serve as a basis for building detection rules.

Categories: