Modern cyberattacks don’t always look like cyberattacks. Increasingly, adversaries are using “living off the land” (LOTL) techniques, abusing legitimate tools, credentials, and protocols to operate in ways that closely resemble normal business activity.

According to the 2025 Comcast Business Cybersecurity Threat Report, these stealth tactics make up a significant portion of post-compromise behavior. Attackers attempt to blend into daily operations, sometimes using applications such as but not limited to PowerShell, Remote Desktop Protocol (RDP), and Windows Management Instrumentation (WMI), move laterally with valid account credentials, and hide command-and-control traffic inside trusted services. The goal isn’t to smash-and-grab—it’s to persist quietly, collect intelligence, and strike when the payoff can be maximized.


Addressing these threats requires advanced detection strategies centered on Managed Detection and Response (MDR) and proactive threat hunting.


Stealth tactics and why they slip past traditional tools


LOTL techniques are often the foundation for highly damaging attacks. They can enable credential harvesting that grants domain-wide access, privilege escalation that disables defenses, data exfiltration in unremarkable trickles, or ransomware deployment timed for maximum disruption.


In one example detailed in the threat report, a threat actor spent three months inside a company’s environment, simply watching email to learn payroll patterns. At the right moment, they diverted payroll to a fraudulent account—a heist enabled by months of undetected reconnaissance.

The problem: By the time LOTL activity begins, the attacker has already bypassed the perimeter. They may have entered through a phishing click, compromised credentials, or an unpatched service. Once inside, attackers can be harder to detect because:

  • No malware signature: Repurposed system tools like PsExec or WMI don’t trigger antivirus.
  • Legitimate looking credentials: Logins look valid unless correlated with unusual patterns.
  • Low-and-slow movement: Lateral movement and privilege escalation unfold gradually, generating minimal alerts.

Perimeter defenses and endpoint detection alone can’t piece together these cross-system behaviors. Rule-based detection often misclassifies them as routine IT operations, extending dwell time and giving adversaries room to maneuver.


Closing the gaps with MDR and threat hunting


Defending against stealthy threats requires AI-powered managed detection and response backed by skilled threat hunters, not just isolated point solutions.


MDR combines:

  • Behavioral analytics to baseline “normal” activity and flag subtle anomalies.
  • Cross-layer correlation to connect signals from endpoints, network activity, and identity systems.
  • Human-led investigation to validate suspicious activity that automation alone might dismiss.

Some living-off-the-land behaviors may later be classified as benign, which underscores the challenge for defenders: distinguishing harmless anomalies from the opening moves of an intrusion. Experienced analysts can help decipher behavioral context, reducing false positives and prioritizing threats. This expertise can mean catching a PowerShell command that’s actually staging ransomware or linking short-burst DDoS traffic to concurrent credential misuse.

By combining automation with active human threat hunting, MDR shortens detection-to-response time, which is the most important factor in containing an attack.


The bottom line for IT leaders


LOTL tactics can turn your own environment into an attacker’s toolkit. They thrive in the gray area between normal and suspicious, slipping past perimeter defenses and evading rule-based detection.


To help reduce risk and business impact:

  • Assume breaches will occur: Plan for the fact that some threats will get inside.
  • Invest in advanced detection: Combine behavioral analytics with human-led hunting.
  • Correlate across layers: Look for patterns that span identities, endpoints, and network traffic.
  • Act quickly: Reduce dwell time to cut off attackers before credential theft, exfiltration, or ransomware deployment.

When attackers blend in, visibility alone can’t protect you—it’s the ability to detect the faint signals that something is wrong, investigate them with context, and respond decisively. MDR delivers that capability, by spotting stealth moves and helping organizations deter them.


Read the full 2025 Comcast Business Cybersecurity Threat Report to explore the latest adversary tactics and learn how advanced detection strategies can help you stay ahead.





Let’s talk more about your business needs

Together, we’ll figure out a solution to suit your size and budget.

Request a consultation

Complete the form, and a sales representative will contact you to discuss your needs and recommend solutions.

Don’t want to wait? You can reach out to our sales team at (877) 337-9303.

  1. Step 1
  2. Step 2

* REQUIRED

By entering your email address and selecting "continue," you agree to receive marketing and sales emails from Comcast Business.Privacy policy

Looking for customer support?

If you’re an existing customer and have questions about your account or services, our customer support team is available to help 24/7.