Attack MEDIUM relevance

Living Off the LLM: How LLMs Will Change Adversary Tactics

Sean Oesch Jack Hutchins Luke Koch Kevin Kurian
Published
October 13, 2025
Updated
October 13, 2025

Abstract

In living off the land attacks, malicious actors use legitimate tools and processes already present on a system to avoid detection. In this paper, we explore how the on-device LLMs of the future will become a security concern as threat actors integrate LLMs into their living off the land attack pipeline and ways the security community may mitigate this threat.

Metadata

Comment
6 pages, 0 figures

Pro Analysis

Full threat analysis, ATLAS technique mapping, compliance impact assessment (ISO 42001, EU AI Act), and actionable recommendations are available with a Pro subscription.

Threat Deep-Dive
ATLAS Mapping
Compliance Reports
Actionable Recommendations
Start 14-Day Free Trial