Godlike Productions - Discussion Forum
Users Online Now: 1,661 (Who's On?)Visitors Today: 919,900
Pageviews Today: 1,620,848Threads Today: 529Posts Today: 11,327
06:41 PM


Rate this Thread

Absolute BS Crap Reasonable Nice Amazing
 

The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”

 
LoneStarRisingModerator
Forum Moderator

User ID: 86828684
United States
02/12/2024 08:51 AM

Report Abusive Post
Report Copyright Violation
The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”

LoneStarRising
Trained NoticerModerator
Forum Moderator

User ID: 82601536
United States
02/12/2024 08:58 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
fifestars
For those who believe, no proof is necessary. For those who don't believe, no proof is possible. (Stuart Chase)

It's easier to fool people than to convince them that they have been fooled. (Mark Twain)
Anonymous Coward
User ID: 65602020
United States
02/12/2024 09:09 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Your title is misleading, but the subject of s still a threat.
[link to www.cisa.gov (secure)]

LOTL-living off the land is code for a type of cyber abuse activity. The govt did not put a book out to teach people how to live off the land.
Digital mix guy Spock

User ID: 83526970
United States
02/12/2024 09:10 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”


bump
Have no fear, Spock is here!!! LLAP
curry nosher

User ID: 86843310
United Kingdom
02/12/2024 09:16 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Interesting... they know somethings coming, is it local, global, war... something external??

I would guess its some way off yet, but one day we'll wake up and nothing, no power etc... that's if we're lucky and not preceeded by a big boom chuckle
TradeWindsDrifter

User ID: 85410352
United States
02/12/2024 09:28 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
This is not "living off the land" this is a specific group of hacking techniques referred to as living off the land or LOTL.

[link to www.cisa.gov (secure)]
More revolutions are won with ballot boxes than ammo boxes.
Anonymous Coward
User ID: 47628110
United States
02/12/2024 09:29 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
LoL is using OS-native tools to avoid detection.

Has nothing to do with self sufficiency outside of computers
Anonymous Coward
User ID: 15969040
United States
02/12/2024 09:30 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
bumpyoda
TradeWindsDrifter

User ID: 85410352
United States
02/12/2024 09:30 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Your title is misleading, but the subject of s still a threat.
[link to www.cisa.gov (secure)]

LOTL-living off the land is code for a type of cyber abuse activity. The govt did not put a book out to teach people how to live off the land.
 Quoting: Anonymous Coward 65602020


hesright
More revolutions are won with ballot boxes than ammo boxes.
AxX

User ID: 75450217
United States
02/12/2024 09:31 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
This is not referring to plant and dirt gardening.

It's a rebranded IT Term.
Energy flows where focus goes.

[25/77/21]

Rev 3:9 <-- Wonder who these guys are?

“The future’s uncertain and The End is always near!” - Jim Morrison, 1970
ChefElvis

User ID: 85408449
United States
02/12/2024 09:33 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
billgates
A legend in my own mind
CharlieFoxtrot

User ID: 85848653
United States
02/12/2024 09:37 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
In a hacker context, "living off the land" refers to a strategy employed by cyber attackers to carry out malicious activities using tools and resources that are already present on a targeted system or network, rather than relying on installing additional malware or tools. This approach aims to evade detection by security measures that often focus on identifying and blocking known malicious software.

Living off the land tactics involve leveraging legitimate system administration tools, built-in operating system functionalities, or third-party utilities that are commonly used for legitimate purposes. By using these existing tools, attackers can blend their activities with normal network and system operations, making their actions harder to detect and attribute.

Examples of living off the land techniques include abusing PowerShell scripts, utilizing Windows Management Instrumentation (WMI), exploiting native command-line utilities (such as PowerShell, cmd, or Bash), and employing legitimate remote administration tools like PsExec or Remote Desktop Protocol (RDP).

This approach is favored by attackers because it reduces their reliance on traditional malware, making it more difficult for security defenses to detect and block their activities. Additionally, living off the land techniques can help attackers maintain persistence within a compromised system or network for extended periods without raising suspicion.
Fema Camp Hobo

User ID: 86832343
United States
02/12/2024 09:40 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Basically they are telling us how the government exploits our PC's.

hiding
DYOR - "Do your own research" and you will be amazed with what you will learn.
TradeWindsDrifter

User ID: 85410352
United States
02/12/2024 09:41 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
In a hacker context, "living off the land" refers to a strategy employed by cyber attackers to carry out malicious activities using tools and resources that are already present on a targeted system or network, rather than relying on installing additional malware or tools. This approach aims to evade detection by security measures that often focus on identifying and blocking known malicious software.

Living off the land tactics involve leveraging legitimate system administration tools, built-in operating system functionalities, or third-party utilities that are commonly used for legitimate purposes. By using these existing tools, attackers can blend their activities with normal network and system operations, making their actions harder to detect and attribute.

Examples of living off the land techniques include abusing PowerShell scripts, utilizing Windows Management Instrumentation (WMI), exploiting native command-line utilities (such as PowerShell, cmd, or Bash), and employing legitimate remote administration tools like PsExec or Remote Desktop Protocol (RDP).

This approach is favored by attackers because it reduces their reliance on traditional malware, making it more difficult for security defenses to detect and block their activities. Additionally, living off the land techniques can help attackers maintain persistence within a compromised system or network for extended periods without raising suspicion.
 Quoting: CharlieFoxtrot


Succinct and accurate. This is what I do for a living, by the way. Obviously, the video creator just saw the title and reacted without reading the advisory. Not everything DHS and CISA do are sinister.

https://imgur.com/a/f57VxTT

My office shelf.
More revolutions are won with ballot boxes than ammo boxes.
Anonymous Coward
User ID: 75690622
Netherlands
02/12/2024 09:50 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”


wut? lotl isn't what you think it means
TradeWindsDrifter

User ID: 85410352
United States
02/12/2024 10:03 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
https://imgur.com/a/0zBI2Ag


All jokes aside, if you didn't look at the bulletin and just jumped to the conclusion that the infrastructure could collapse at any moment, because it could, I could see the mistake.

It doesn't make the guy in the video dumb, just poorly informed.
More revolutions are won with ballot boxes than ammo boxes.
Anonymous Coward
User ID: 75690622
Netherlands
02/12/2024 10:12 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
[imgur] [link to imgur.com (secure)]

All jokes aside, if you didn't look at the bulletin and just jumped to the conclusion that the infrastructure could collapse at any moment, because it could, I could see the mistake.

It doesn't make the guy in the video dumb, just poorly informed.
 Quoting: TradeWindsDrifter


poorly informed = dumb
Anonymous Coward
User ID: 85913975
United States
02/12/2024 10:27 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”


Yeah, I saw this yesterday when they first came out with it.

Very, very weird.
The Walking Dude

User ID: 86584802
United States
02/12/2024 10:56 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
+1 if I can.
Nuke Marx's grave in London, please.
What am I thinking?
How do I feel?
What am I doing?
ElleMira

User ID: 86541972
United States
02/12/2024 10:57 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
fivestars
ElleMira

User ID: 86541972
United States
02/12/2024 11:04 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Your title is misleading, but the subject of s still a threat.
[link to www.cisa.gov (secure)]

LOTL-living off the land is code for a type of cyber abuse activity. The govt did not put a book out to teach people how to live off the land.
 Quoting: Anonymous Coward 65602020


this

"What Is a Living-Off-the-Land (LOTL) Attack? An LOTL attack is a type of cyberattack where a hacker uses legitimate tools and features already present in the target system to avoid detection and carry on a cyberattack."
Anonymous Coward
User ID: 86822679
United States
02/12/2024 11:06 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Strictly on the QT!

dragnet-facts45
5essence

User ID: 86354454
United States
02/12/2024 11:12 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
[link to www.cisa.gov (secure)]

page 3:

"Implement authentication and authorization controls for all human-to-software and
software-to-software interactions regardless of network location."

That's what they want!
ElleMira

User ID: 86541972
United States
02/12/2024 11:15 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Tech is out of my scope of knowledge/interest.

Some possibly interesting bits I found regarding this LOTL/Volt Typhoon stuff - China started these attacks in 2021, after Biden took office:

"Microsoft has claimed that a Chinese cyberespionage group has been targeting critical infrastructure organizations across the United States…including Guam, an island hosting multiple military bases, since at least mid-2021"



Thread: The Missing Link: SolarWinds ORION Software interfaces with SENTINEL, the FBI system developed and created by Ghislaine Maxwell’s sister

Thread: BREAKING: FBI, Texas Rangers and US Marshals Raid Solarwinds HQ in Austin. Dominion link down.
Anonymous Coward
User ID: 86565862
United States
02/12/2024 11:43 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
That post is written in broken English. The Chinese are really really bad at trying to sound American when they speak. Whoever wrote that post doesn’t speak English as their first language.

I’m going to go out on a limb here and say nothing is going to happen the way we all think. It’s not going to be boots on your throat and locked in a van while you’re sent to a reeducation camp. Something may break in the markets and they may have to roll out a CBDC. Perhaps after that a bit or a lot of unrest occurs in certain pockets, so they enact a marshal law order and track you based off of your digital id or something to that effect. It’s a slow boil, it’s incremental changes. There may be an attack, there certainly has been in the past. But if there is an attack we’re all waiting for it, we all expect it, and we all think it’ll be used to take our freedoms and wealth away. That means it’s not a black swan and that we see it coming.

No I think it’s something else we’re going to be dealing with.
Riff-Raff
DEFCON 5

User ID: 80740666
United States
02/12/2024 11:47 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Nice find, OP! 5 stars & green!
"Collapse is a process, not an event." - Unknown

"It's in your nature to destroy yourselves." - Terminator 2

"Risking my life for people I hate for reasons I don't understand." - Riff-Raff

Deputy Director - DEFCON Warning System
Anonymous Coward
User ID: 82255720
United States
02/12/2024 11:52 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
This is not "living off the land" this is a specific group of hacking techniques referred to as living off the land or LOTL.

[link to www.cisa.gov (secure)]
 Quoting: TradeWindsDrifter


This

Fucking morons
Anonymous Coward
User ID: 70707278
United States
02/12/2024 11:54 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Your title is misleading, but the subject of s still a threat.
[link to www.cisa.gov (secure)]

LOTL-living off the land is code for a type of cyber abuse activity. The govt did not put a book out to teach people how to live off the land.
 Quoting: Anonymous Coward 65602020





Anything with an X/ Tweeter video link is misleading, esp. when it’s all about someone wanting attention (their mug takes up half the screen).
VampPatriot

User ID: 82423301
United States
02/12/2024 11:56 AM

Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
Anyone that is in denial about what’s coming deserves their future hardships.

The writing is not just on the wall, it’s all over the wall. It’s full of fucking graffiti.

You’ll be at the mercy of people like me, and I’m the more magnanimous and practical.

More people are likely to shoot anyone who even gets within their line of sight

Last Edited by VampPatriot on 02/12/2024 11:58 AM
Sic Semper Tyrannis.

"FREEDOM IS SLAVERY.
IGNORANCE IS STRENGTH.
WAR IS PEACE.
STAYING APART BRINGS US TOGETHER." NWO Mantra
Anonymous Coward
User ID: 82508839
United States
02/12/2024 11:57 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
In a hacker context, "living off the land" refers to a strategy employed by cyber attackers to carry out malicious activities using tools and resources that are already present on a targeted system or network, rather than relying on installing additional malware or tools. This approach aims to evade detection by security measures that often focus on identifying and blocking known malicious software.

Living off the land tactics involve leveraging legitimate system administration tools, built-in operating system functionalities, or third-party utilities that are commonly used for legitimate purposes. By using these existing tools, attackers can blend their activities with normal network and system operations, making their actions harder to detect and attribute.

Examples of living off the land techniques include abusing PowerShell scripts, utilizing Windows Management Instrumentation (WMI), exploiting native command-line utilities (such as PowerShell, cmd, or Bash), and employing legitimate remote administration tools like PsExec or Remote Desktop Protocol (RDP).

This approach is favored by attackers because it reduces their reliance on traditional malware, making it more difficult for security defenses to detect and block their activities. Additionally, living off the land techniques can help attackers maintain persistence within a compromised system or network for extended periods without raising suspicion.
 Quoting: CharlieFoxtrot


Succinct and accurate. This is what I do for a living, by the way. Obviously, the video creator just saw the title and reacted without reading the advisory. Not everything DHS and CISA do are sinister.

[imgur] [link to imgur.com (secure)]
My office shelf.
 Quoting: TradeWindsDrifter


True hacks don’t need books about it.
Anonymous Coward
User ID: 86565862
United States
02/12/2024 11:57 AM
Report Abusive Post
Report Copyright Violation
Re: The Cybersecurity & Infrastructure Security Agency Quietly Published “Joint Guidance On How To Live Off The Land”
I believe that a major disclosure event will happen that rocks the foundation of our reality. I dunno what that could be (something controversial though that will pit us against each other) but that’s what it looks to be shaping up as. All this talk about Chinese and other groups infiltrating our border is most likely for whatever happens AFTER.





GLP