How Attackers Use It
Attack Summary
Using built-in OS tools (PowerShell, WMI, certutil, curl, cron) to carry out malicious actions, blending in with normal system behaviour to evade signature-based detection.
- Adversary identifies built-in binaries that can execute, download, or persist.
- Commands are chained to avoid custom malware deployment.
- Activity blends with administrative operations to evade signatures.
- Persistence and lateral movement continue through trusted tools.