Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“LOTS” means “Living Off Trusted Sites”: attackers use familiar online services and routine-looking web traffic to make malicious activity harder to distinguish from normal work. The phrase appears in a Zscaler-sponsored webinar promotion published by The Hacker News on 19 June 2025. Its advertised session, “Threat Hunting Insights from the World’s Largest Security Cloud,” was a past event—not an upcoming session with registration established here.

What the webinar meant by LOTS

The promotion used LOTS to describe adversaries abusing platforms that people and organizations already recognize and trust. Examples named in the article included Google, Microsoft, Dropbox, Slack, Teams, Zoom, GitHub, and shortened or vanity URLs. The point is that activity involving a familiar service can resemble ordinary cloud or collaboration use.

Those names are examples from the 2025 promotional copy, not a ranking of services currently being abused or a measure of how common the tactic is. The promotion also does not establish that LOTS is a newly dominant strategy. It is best read as a description of a threat-hunting topic, not an incident report or prevalence study.

How to think about detection

MITRE ATT&CK’s T1071.001, “Web Protocols,” describes adversaries using web protocols to blend command-and-control activity into existing traffic; commands and results may be embedded in protocol traffic. This is a useful related detection lens, but LOTS is not the name of that MITRE technique, and not every example of trusted-service abuse necessarily maps to it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MITRE’s detection guidance points analysts toward communication behavior and context, rather than relying on a service’s reputation alone. A legitimate destination does not make every connection to it benign, just as a connection to a familiar service is not, by itself, proof of compromise.

Observation approach What it can miss More useful question
Destination reputation or a trusted-service allowlist Suspicious activity can use a familiar service or domain, so a trusted name alone may not reveal the process or purpose behind the connection. Is this process, account, timing, volume, and pattern of use expected for this service?
Static malware signatures alone A signature may not explain unusual communications that do not match a known file indicator. Do the communication pattern, initiating process, user agent, and destination fit normal application use?

Signals worth investigating

MITRE’s guidance offers examples, not a complete LOTS playbook. In a security operations workflow, the following patterns can help prioritize investigation:

  • Unexpected or high-volume HTTP, HTTPS, or WebSocket traffic: compare the connection’s frequency and volume with the organization’s normal baseline and the application’s expected behavior.
  • Suspicious process-to-network activity: identify which process initiated the connection and whether that process normally communicates with the destination.
  • Uncommon user agents: examine whether a connection uses a user agent that is rare in the environment or inconsistent with the apparent application.
  • Unusual destinations: investigate destinations that are unexpected for the user, process, or service, even when the surrounding traffic uses a familiar web protocol.
  • Traffic inconsistent with normal use: look for timing, volume, or communication patterns that do not fit how the service is ordinarily used in your environment.

These signals are more informative in combination. For example, a high-volume connection from an unusual process to an unexpected destination merits closer review than the service name alone can provide. Context helps analysts separate routine use from behavior that needs investigation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the session advertised

The Hacker News promotion named security leaders, threat hunters, IT teams, and SOC staff at organizations using SaaS apps, cloud platforms, and collaboration tools as its intended audience. It advertised coverage of attack techniques, threat-hunting examples, misuse of trusted tools, detection improvements, and emerging trends. Those are the promotion’s stated learning outcomes; the available event information does not establish an independently verified expert quotation or measured outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The session was described as free and digital, but the promotion was published on 19 June 2025. The available information does not confirm that the webinar remains available to watch or that registration is open.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.