detecting-living-off-the-land-attacks

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The agent optionally fetches binary metadata from the official LOLBAS project API at lolbas-project.github.io. This is a well-known and trusted community resource used to provide up-to-date detection signatures for common Windows binary abuses.
  • [SAFE]: The skill performs static analysis of log data using pre-defined regular expression signatures and does not invoke any system commands or execute external code. No evidence of data exfiltration, credential theft, or persistence mechanisms was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 03:02 AM