
"When malware uses your own tools against you: detecting living-off-the-land attacks in Australia"
When malware uses your own tools against you: detecting living-off-the-land attacks in Australia
The most effective malware often carries no payload at all. Instead of shipping custom binaries that antivirus software can fingerprint, attackers borrow what is already installed on the target machine — PowerShell, certutil, bitsadmin, Windows Management Instrumentation, even msbuild — and abuse those signed, trusted tools to move through a network and copy data out. The technique is called living off the land (LOTL), and a well-researched Hackers Arise article on creative C2 and data exfiltration walks through how attackers hide command-and-control and exfiltration inside ordinary-looking traffic. This post looks at the problem from the other side: how an Australian organisation or home user can detect it.
Why LOTL is hard to catch
Signed Windows binaries running from trusted directories, launched by a user who is logged in anyway — nothing about that trips a signature scanner. The Australian Signals Directorate's Australian Cyber Security Centre, together with CISA, the FBI and the NSA, published joint guidance on identifying and mitigating living off the land techniques precisely because these attacks defeat conventional detection. The operators who use them — from opportunistic criminals to state-sponsored groups — are ordinary in their tools and extraordinary in their patience.
The signals that give it away
The ACSC guidance groups detection into practical, mostly free measures, and three of them matter most for Australian organisations:
Baselining. You cannot spot abnormal use of certutil.exe if you never recorded what normal looks like. Enable Windows command-line process auditing (or Sysmon on Windows, auditd on Linux) and record which binaries run, from where, with which arguments. After two to four weeks you will have a baseline; deviations become your lead list.
Scrutinising native tools. The joint guidance recommends placing additional scrutiny on LOLBin activity: PowerShell launched with -EncodedCommand or -nop -w hidden, certutil used with -urlcache (a download function nobody in accounting needs), bitsadmin transfers that no backup job owns. These pairings are rare in legitimate use and loud in malicious use.
Watching egress. Data has to leave somehow. The Hackers Arise piece shows exfiltration hidden in cloud storage uploads, DNS queries and even social-media payloads. A cheap countermeasure is DNS logging plus egress allow-listing: workstations talk to your mail provider and your cloud apps, not to arbitrary new domains. Sudden DNS volume to an uncategorised domain is one of the most reliable LOTL telltales.
Free detection layers for Australian teams
Essential Eight strategies make a real difference here because they shrink the attack surface the LOLBins rely on: application allow-listing blocks certutil outright on standard users, and macro/application-hardening controls stop the initial foothold. The ACSC's Essential Eight maturity model is the reference framework most Australian organisations are assessed against.
For small teams, Windows event forwarding plus a single SIEM instance — even an Elastic or Wazuh box on a spare machine — gets you correlation of process, network and DNS events. For home users and sole traders: turn on PowerShell script block logging, keep your OS patched, and treat any tool asking to "run a script" as hostile by default.
The Australian reporting duty is part of detection
If you operate a business covered by the Privacy Act and suffer an eligible data breach, you may be required to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme — which means your detection capability directly affects your legal exposure. Late detection has already produced enforceable outcomes for Australian entities.
This article is general information, not legal advice, and not a certification guide. For incident response, contact the ACSC's ReportCyber service.
Further reading: our beginner's guide to what an RTL-SDR can actually receive covers the radio side of signal awareness, and our device-security threat model covers buying decisions for privacy hardware (our own stock — disclosed).
Sources: Hackers Arise — Living Off The Land: Creative C2 and Data Exfiltration Options · ACSC/CISA/FBI/NSA joint guidance, Identifying and Mitigating Living Off the Land Techniques · ACSC Essential Eight · OAIC Notifiable Data Breaches scheme
Header image: US Department of Energy (via EFTA), public domain.