Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that attackers are using…
Threats, Abuse & Incident Response

What are the signs that attackers are using living off the land techniques to move toward a domain controller?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Threats, Abuse & Incident Response

Common signs include a burst of built-in commands such as whoami, net users, ipconfig, netstat, and net use from a user workstation, followed by attempts to enumerate groups, shares, routes, and remote sessions. Suspicious PowerShell remoting, WinRM activity, or RPC-based connections from an unusual host can also indicate that discovery is underway.

How living off the land activity reaches the domain controller

living off the land becomes dangerous when attacker reconnaissance stops being local and starts mapping the wider Windows environment. On a workstation, that usually looks like built-in admin and network commands being used in a short burst to answer basic questions: who is logged in, what subnets exist, which hosts are reachable, and which remote management paths are open. The pattern matters more than any single command.

At that stage, the operator is usually trying to identify the easiest path to higher-value systems, especially the domain controller. Commands such as net use, net users, netstat, and ipconfig are not proof of compromise on their own, but when they appear together, especially from an ordinary user endpoint, they can show that discovery and access planning are underway.

Remote administration activity is the next clue. Suspicious PowerShell remoting, WinRM sessions, or RPC-based connections from a host that does not normally manage servers often indicate the attacker is testing lateral movement options. A domain controller target is especially significant because once an adversary can enumerate it, authenticate to it, or interact with services exposed on or through it, the blast radius expands quickly.

What the command sequence usually reveals

Attackers rarely move straight from first access to a domain controller. They typically use native tools to answer one question at a time, then chain those answers into the next step. That is why an analyst should read the sequence, not the individual process names, because a short run of benign-looking commands can still form a coherent attack path.

  • Local discovery: whoami, ipconfig, and netstat help the operator understand the current identity context, network reachability, and active sessions.
  • Directory and share discovery: net users and share enumeration help identify groups, administrative patterns, file locations, and likely pivot points.
  • Remote execution testing: PowerShell remoting, WinRM, and RPC traffic help confirm whether the host can reach management services on adjacent systems.
  • Target refinement: once a likely path is found, the attacker often narrows attention to systems that can expose credentials, sessions, or privileged relationships.

In practice, the strongest signal is not “built-in tools exist”, it is “built-in tools are being used in a progression that matches lateral movement”.

For broader attack-path context, MITRE ATT&CK Enterprise Matrix is the clearest external reference for mapping discovery, lateral movement, remote services, and credential-access behaviour into a structured detection model. For breach examples that show how native tooling and stolen access frequently combine during real intrusions, see The 52 NHI Breaches Report.

Why the domain controller becomes the focal point

The domain controller is not just another server. It concentrates authentication, directory state, and trust relationships, so an attacker who can reach it has a much better chance of expanding access, finding reusable credentials, or learning which accounts and systems matter most. That is why discovery activity on a workstation can be an early warning of a much more consequential campaign.

Several conditions make this pattern more credible. First, the commands appear outside the user’s normal role. Second, the same host begins touching remote management services or unusual ports. Third, the activity is followed by attempts to enumerate users, groups, shares, routes, or sessions across the environment. Fourth, the source host is not a known admin jump point, but it is behaving like one.

When those conditions line up, the likely interpretation is not simple troubleshooting. It is environment mapping for pivoting, with the domain controller often serving as the highest-value destination or the central source of further compromise.

Risk and Threat Considerations

Living off the land is attractive because it blends into normal administration and reduces the need for malware-heavy tooling. That makes detection harder, especially when the attacker is using valid local utilities and remote management protocols that defenders already expect to see in some form.

Failure mechanism: An adversary abuses trusted Windows tooling to enumerate the network, validate remote paths, and test management channels from a benign-looking endpoint, then uses that reconnaissance to reach privileged systems such as domain controllers.

Impact: If the pattern is missed, the attacker can move from initial access to lateral movement, privilege discovery, and eventually domain-wide compromise without triggering obvious payload-based alarms.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1021 — Remote ServicesLiving-off-the-land movement to a DC often uses WinRM, PowerShell remoting, or RPC paths.
T1087 — Account DiscoveryBursts of net users and related enumeration show directory and account discovery.
T1046 — Network Service Discoveryipconfig, netstat, and host probing support discovery of reachable systems and services.
Recommendation — Map remote-service activity to T1021 and alert on unusual source-to-server management connections. Correlate account-discovery commands with endpoint baselines and escalate when they precede lateral movement. Detect network-discovery sequences from workstations and investigate when they lead toward privileged hosts.

Practitioner Guidance

What to verify: Confirm whether the workstation producing the command burst normally performs administrative discovery. The key test is whether the sequence matches the user’s baseline and role, not whether each command is individually allowed.

Decision rule: If native commands are followed by remote service use from an unusual source, treat it as a lateral-movement investigation first and as benign administration only after you can prove the account, host, and time window fit the expected change process.

What good looks like: Your telemetry should let you connect process creation, authentication, remote service use, and destination host together so that a workstation-to-domain-controller path is visible as a chain, not as isolated events.

Practitioner takeaway: The most reliable indicator is not a single suspicious command, but a short sequence that shows environment discovery, remote path testing, and movement toward higher privilege from a host that should not normally behave like an admin console.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org