According to CrowdStrike’s 2025 Threat Hunting Report, 81% of interactive intrusions observed were malware-free.

That highlights an important shift in cybersecurity:

Attackers don't always need to introduce a traditional malicious executable.

Instead, they can abuse legitimate tools, trusted credentials, and capabilities already available inside the environment.

This technique is commonly associated with Living off the Land (LOTL).

💻 The tools are legitimate. The behavior isn't.

Windows environments already contain powerful administrative capabilities that IT teams use every day, including:

🔹 PowerShell
🔹 Windows Management Instrumentation (WMI)
🔹 Certutil
🔹 Rundll32
🔹 MSHTA
🔹 Command-line and remote administration utilities

Attackers can abuse legitimate capabilities to perform activities such as discovery, command execution, persistence, lateral movement, and communications while blending into normal administrative activity.

CISA specifically warns that living-off-the-land techniques can make malicious activity harder to distinguish from legitimate system and network administration.

🚨 This changes the security question

Traditional security often focused heavily on:

“Is this file malicious?”

That's still important—but it isn't enough.

Modern detection also needs to ask:

Who executed this?
What process launched it?
Where did the activity originate?
What happened immediately before and after it?
Is this normal behavior for this user or device?
Did the activity lead to credential access or lateral movement?

The focus shifts from simply detecting malicious files to detecting malicious behavior and intent.

🌐 Volt Typhoon is a powerful example

U.S. cybersecurity agencies have documented how the PRC state-sponsored group known as Volt Typhoon used living-off-the-land techniques and valid accounts to blend into normal network activity while targeting U.S. critical infrastructure.

Authorities found indications that the group maintained access to some victim environments for at least five years.

That demonstrates why legitimate activity can sometimes be more difficult to detect than obvious malware.

💡 Bottom line

The absence of malware does not mean the absence of an attack.

Modern endpoint security increasingly needs:

Behavioral Detection + Identity Signals + EDR/XDR + Centralized Logging + Threat Hunting + Context

Because when attackers use the same tools administrators use every day, the challenge isn't simply identifying what ran.

It's understanding why it ran, who ran it, and what happened next.

4c2554ca-2f01-47f1-bd9e-67543d79b241