Question 5 of 10Pro Only

Living-off-the-land techniques are notoriously difficult to detect because they use legitimate system tools. How would you hunt for malicious use of PowerShell, WMI, or other built-in Windows tools?

Sample answer preview

Living-off-the-land techniques, sometimes referred to as LOLBins attacks, are particularly challenging because the tools being used are legitimate and present on every Windows system. You cannot simply block PowerShell or WMI because administrators rely on them daily.

living-off-the-landLOLBinsPowerShell huntingWMI abuseencoded commandsdownload cradle

Unlock the full answer

Get the complete model answer, key points, common pitfalls, and access to 9+ more SOC Analyst interview questions.

Upgrade to Pro

Starting at $19/month • Cancel anytime