SOC Operations7 min read•Sep 15, 2026

Blue Teaming 101: Investigating Living-off-the-Land (LotL) Attacks

An investigation field guide for junior and intermediate SOC analysts on identifying adversary misuse of legitimate system binaries like PowerShell, WMI, and MSBuild.

C
Citadock Academy
SOC Training Faculty

Key Defensive Takeaways

  • Understand parent-child process relationships (e.g., word.exe spawning powershell.exe is a critical red flag).
  • Enable PowerShell Script Block Logging (Event ID 4104) to capture obfuscated payload execution in plain text.
  • Cross-reference command-line flags with the LOLBAS project documentation during alert triage.

Attackers no longer bring custom malware into corporate networks when they can simply misuse what is already installed. The LOLBAS (Living Off The Land Binaries and Scripts) project catalogs hundreds of legitimate Microsoft binaries that can execute code, download payloads, or bypass AppLocker.

1. Anomalous Parent-Child Relationships

Office applications (Word, Excel) or web servers (w3wp.exe, nginx) have no legitimate operational reason to spawn cmd.exe or powershell.exe. Establishing parent-process baseline rules in your SIEM immediately surfaces initial compromise attempts.

2. PowerShell Script Block Logging Telemetry

PowerShell execution policies do not prevent attacks. By enabling Event ID 4104, Windows decodes Base64 obfuscated scripts and logs the executed abstract syntax tree, allowing SOC analysts to see the true attacker intent.

Defensive Summary

Effective blue teaming is about understanding how normal systems operate so that anomalies jump out immediately. Practice analyzing benign logs to build instinct for the malicious.

#SOC Analyst#Blue Team#PowerShell#LOLBAS#Incident Triage