An attack technique that uses only tools already built into the OS.
By abusing legitimate administrative tools such as PowerShell and WMI, the attacker leaves behind no new malware-specific files, making the activity hard to distinguish from normal administration. Often abbreviated LOLBins, it's favored by attackers trying to evade detection.
© 2026 ITBGM