While the industry is busy buying its fifteenth monitoring tool to appease an auditor, adversaries are quietly logging in using valid credentials and native binaries. They are Living off the Land (LotL) — using our own infrastructure against us because it is the smartest way to blend into the noise of a modern enterprise.
Last year, for Cyber Deception Day, Maretta Morovitz (Technical SME, MITRE) explored a counter-maneuver using MITRE Engage: Living Off the Land Engagement (LOTLE). The premise is straightforward. If attackers are going to use our environment against us, we should weaponize that exact environment against them. This approach leverages existing assets, data, and forensic artifacts as breadcrumbs and tripwires without relying on heavy, new tooling.
It is a compelling concept. But like any interesting research area, it raises an uncomfortable question for operational defenders: how do you actually do this in a consistent, repeatable, and scalable way?
The Problem: Deception as an Art Project
LOTLE is powerful precisely because it repurposes what already exists. A fake AWS credential left in a developer's bash history or a decoy RDP session blends perfectly because it belongs there. It creates an environment where an adversary's reconnaissance becomes a massive liability.
But flexibility is a double-edged sword. Without structure, deploying deception becomes highly dependent on individual creativity. It becomes hard to scale, impossible to measure, and difficult to standardize across a massive, complex network.
When deception is treated as an artisanal craft, it is just an expensive hobby. If it stays an art, it will never see widespread operational adoption. We need to turn it into a science.
The Blueprint: From Environment to Execution
To explore what it takes to make this repeatable, Morovitz and her team built a proof-of-concept in an environment that perfectly represents a target-rich, resource-poor organization: a K-12 school district.
The goal was not to deploy another blinky box. It was to show how open-source tools, combined methodically, can form a framework for scaling engagement. The workflow follows a rigorous path from planning to deployment:
- Start with the reality of the environment: model the existing infrastructure. No hypotheticals.
- Map the adversary: identify relevant attacker behaviors using the MITRE ATT&CK framework. We have to respect the attacker's methodology to build a trap they will actually fall for.
- Translate to engagement: map those behaviors to specific opportunities for deception.
- Deploy with context: combine open-source tools (like Canary tokens) with living-off-the-land assets, using LLMs and RAG to generate believable, environment-aware artifacts that blend naturally.
The true novelty here is not the technology; it is the chain of execution: Environment to Behavior to Intent to Execution.
Signal over Noise
This structured mapping is what moves deception from abstract theory to actionable capability. The result is a coordinated set of deception elements that produce high-confidence signals tied to real attacker behavior.
Most SOC analysts are treated like professional haystack searchers. We give them more hay and call it visibility. Deception flips the script. A strategically placed decoy does not suffer from false positives because nobody has a legitimate business reason to interact with it. It is the silent alarm of the digital age.
Where This Goes Next
This proof-of-concept is intentionally simplified. In a production network, the deployment of these artifacts would not happen via a standalone script; it would be integrated seamlessly through existing EDR, configuration management, or automation pipelines.
The objective is not to present a finished, silver-bullet solution — those do not exist. The goal is to prove that LOTLE can be moved from a creative exercise toward a repeatable, operational capability without requiring a PhD in adversary psychology from every defender on your team.
We do not need to build higher walls. The intruders are already excellent climbers. We need to make the inside of the perimeter a confusing, hostile labyrinth where every lateral move they make is a gamble.
How much of your team's time is wasted on maybe instead of definitely?
#CyberSecurity #CyberDeception #MITREEngage #LivingOffTheLand #ThreatDetection #DeceptionTechnology #SOC #InfoSec