Skip to main content

Investigating LOLBin and Fileless

Learn about LOLBins and fileless techniques from execution to detection.

Back to all walkthroughs
Room Icon

Investigating LOLBin and Fileless

Max room.

Learn about LOLBins and fileless techniques from execution to detection.

medium

60 min

21

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In the world of cyber security defense, there is a heavy reliance on scanning files on disk to detect malicious programs and payloads. To bypass this, modern attackers adapt by living off the land, abusing trusted, signed operating system tools (LOLBins), and executing malicious code directly inside memory. In this room, you will explore these techniques, get hands-on practice executing them, and learn what detections you can count on to catch them when they occur.

Learning Objectives

  • Understand what LOLBins are, why attackers use them, and which trusted binaries are commonly abused
  • Explore how attackers abuse Living Off the Land Binaries (LOLBins) from an adversary's perspective
  • Identify and investigate usage through Windows event logs and forensic artifacts
  • Understand fileless techniques and how attackers use them to minimize their footprint
  • Practice executing common fileless techniques, including registry-based and in-memory execution
  • Detect and analyze fileless attacks using relevant log sources and artifacts

Prerequisites

Familiarity with , Windows Event Logs, and is recommended for this walkthrough. A solid understanding of Windows forensic artifacts and detection techniques will also be beneficial.

Machine Access

Click the Start Machine button below. The machine will start in Split-Screen mode. Once you gain access, all necessary tools and files will be available on the machine's desktop.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off

If you prefer to connect using your own -connected machine, please use the credentials below to in: 

Credentials

Only needed if you are using your own machine.

Username
 
DFIRUser
 
Password
 
TryHackMe!
 
IP address
 
MACHINE_IP
 
Connection via
 
RDP
 
Answer the questions below

I understand the learning objectives and am ready to learn about LOLBins and fileless techniques!