A recent analysis of 700,000 security incidents reveals widespread exploitation of Microsoft tools by cybercriminals for breaching systems undetected.
Netsh.exe, a command-line utility for managing network configurations, emerged as the top tool abused by cybercriminals, being found in a third of major attacks.
PowerShell was running on 73% of endpoints, well beyond administrative use alone, and its dual-use nature makes detection challenging.
Despite being deprecated, wmic.exe is still widely present in environments and used by attackers to blend in due to its legitimate appearance.