This talk explored ML classification of living-off-the-land (LOL) scripts and commands to identify those that were suspicious. By building a training set of both representative baseline commands run in an environment, as well as known-malicious samples, a ML classifier can then detect suspicious commands being run in an environment. The researchers explored how different types of ML models were susceptible to backdoor poisoning.