Microsoft starts removing WMIC tool used by cybercriminals
Microsoft's removal of WMIC from Windows 11 eliminates a heavily abused living-off-the-land binary, but defenders should prepare for adversary migration to alternative WMI interfaces.
Summary written by editorial AI · Source link below
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
Editorial Analysis
While removing a key attacker utility reduces the LOLBin attack surface, sophisticated adversaries will pivot to PowerShell-based WMI access, requiring updated detection strategies.
Audit internal tooling for WMIC dependencies and update SOC detection playbooks to cover alternative WMI access methods before the change rolls out.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Security Desk
- Named Pipes Under Attack: Securing Windows Interprocess Communication22 Aug
- Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near21 Aug
- [tl;dr sec] #342 - Figma's Agentic Detection, Agent Identity, Uber's Agent-(E)DR20 Aug
- Latvian officials resign after cyberattack exposes data on 1.2 million people19 Aug
- Describing attacks with crime script analysis19 Aug