Cybercriminals love this ancient Windows tool, but a little-known CLI utility is their new secret weapon

Cybercriminals love this ancient Windows tool, but a little-known CLI utility is their new secret weapon

Cybercriminals love this ancient Windows tool, but a little-known CLI utility is their new secret weapon


  • Netsh.exe is the most abused Windows tool, and it still hides in plain sight
  • PowerShell shows up on 73% of endpoints, not just in admin hands
  • WMIC’s surprising comeback shows attackers favor tools no one’s watching anymore

A new analysis of 700,000 security incidents has revealed just how extensively cybercriminals exploit trusted Microsoft tools to breach systems undetected.

While the trend of attackers using native utilities, known as Living off the Land (LOTL) tactics, is not new, the latest data from Bitdefender’s GravityZone platform suggests it’s even more widespread than previously believed.

Leave a Comment

Your email address will not be published. Required fields are marked *