Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Bitdefender Finds 84% of Attacks Use Built In Windows Tools, Here’s How

Criminal groups have increasingly adopted the tactic of utilizing pre-installed software on Windows computers for malicious activities, a method known as "Living off the Land." Bitdefender Labs conducted an analysis of 700,000 incidents through its…

Criminal groups have increasingly adopted the tactic of utilizing pre-installed software on Windows computers for malicious activities, a method known as "Living off the Land." Bitdefender Labs conducted an analysis of 700,000 incidents through its GravityZone platform, revealing that 84% of high-severity breaches employed this strategy. A similar review showed an 85% occurrence in their managed detection operations.

These tools, signed by Microsoft, perform legitimate tasks such as scripting and firewall updates, making them initially undetectable by security scanners. As a result, attackers can navigate systems undetected, appearing as routine maintenance while collecting data.

Netsh.exe , used to modify network configurations, was identified in one-third of the serious breaches. While essential for firewall management, its misuse poses security risks. PowerShell is also frequently exploited, with 96% of organizations using it for legitimate purposes and 73% of endpoints activating it occasionally. Third-party applications often utilize hidden PowerShell windows, providing additional cover for intruders.

A similar review showed an 85% occurrence in their managed detection operations.
Sarah Dawson · Thehackingpost

Other tools such as reg.exe , rundll32.exe , and the C# compiler csc.exe are also exploited. Additionally, msbuild.exe and ngen.exe , typically used by software developers, are targeted in attack sequences, indicating the comprehensive search by attackers for exploitable programs.

Regional Variations in PowerShell Usage

Bitdefender observed regional differences in PowerShell usage. In the Asia-Pacific region, 53.3% of organizations recorded PowerShell activity, significantly lower than the 97.3% observed in Europe, the Middle East, and Africa. In regions with less PowerShell activity, attackers exploit reg.exe more frequently. Legacy tools like WMIC remain in use due to legacy software dependencies, enabling attackers to blend malicious activities with routine system checks.

Advertisement

Bitdefender developed GravityZone Proactive Hardening and Attack Surface Reduction (PHASR) to monitor and mitigate malicious activities without disrupting legitimate operations. By analyzing typical behavior, PHASR identifies and halts suspicious actions, such as PowerShell scripts using encrypted text or attempting to disable protections, while allowing harmless scripts to proceed. This proactive approach also includes monitoring tools like WMIC and netsh.

Based on reporting by techround.co.uk.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories