# Detecting Living Off The Land Attacks

> Detect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns.

- Skill: `autohandai-community-skills/detecting-living-off-the-land-attacks` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add autohandai-community-skills/detecting-living-off-the-land-attacks`
- Raw SKILL.md: https://api.skillmd.com/api/skills/autohandai-community-skills/detecting-living-off-the-land-attacks/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- License: Apache-2.0
- Author: autohandai (https://skillmd.com/u/autohandai-community-skills)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/autohandai-community-skills/detecting-living-off-the-land-attacks

---


# Detecting Living Off the Land Attacks

Monitor for suspicious use of legitimate Windows binaries (LOLBins)
including certutil, mshta, rundll32, regsvr32, and others used in
fileless and living-off-the-land attack techniques.

