Federal News Network pushes agencies on LOTL detection
The useful part is not the warning; CISA gave that in 2024. It is the reminder that native tools still beat shallow monitoring.
TL;DR
A Federal News Network commentary urges federal organizations to strengthen detection and monitoring for living off the land, or LOTL, activity that uses legitimate system tools and administrative processes. The operational audience is federal security teams managing hybrid, legacy and cloud environments where normal administrator behavior can mask an intrusion. CISA, NSA, FBI and partner agencies issued LOTL mitigation guidance in February 2024, so this is less a new mandate than an old visibility problem refusing to die.
Federal News Network’s commentary does not announce a new federal requirement. It restates a practical problem federal defenders already know too well: living off the land activity is hard to catch because the attacker is using the same native tools and administrative paths the agency needs to keep running.
That distinction matters. Disabling the tools is usually not an option. The work is in baseline behavior, central logging, identity monitoring and threat hunting that can separate legitimate administration from command execution that only looks legitimate. CISA and its partners made the same point in February 2024 guidance, saying many organizations lack the security capabilities needed to detect LOTL activity and that the technique remains effective with little investment by attackers: https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques.
The practitioner takeaway is modest but real. Treat this as a monitoring and response story, not a product category. Federal teams should be asking whether application, access and security logs are actually on, centrally stored and usable for hunting. CISA’s Volt Typhoon advisory put those logging steps alongside patching internet-facing systems, phishing-resistant multifactor authentication and end-of-life planning for unsupported technology: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a. The unpleasant diagnosis is that LOTL is not exotic. It works because ordinary administration is still too noisy, too underlogged or too poorly baselined to defend cleanly.
Published ·Deep Fathom