logo
Study finds 84% of severe cyber incidents use LOTL methods

Study finds 84% of severe cyber incidents use LOTL methods

Techday NZ4 days ago

Bitdefender has released new research analysing 700,000 cybersecurity incidents to better understand the use of so-called 'living off the land' techniques (LOTL) by cybercriminals.
LOTL techniques involve attackers exploiting commonly used applications and utilities already present in target environments, making them particularly difficult to identify and prevent using conventional security measures.
According to the data collected by Bitdefender Labs, 84 per cent of major security incidents – defined as those with high severity – involved the use of LOTL binaries. This figure was corroborated by managed detection and response (MDR) data, which indicated that 85 per cent of incidents employed LOTL methods.
The research specifically highlights how attackers leverage widely used backend tools like PowerShell, a Microsoft Windows command-line shell and scripting language, and Netsh, a network configuration utility. The most frequently abused tool was found to be netsh.exe, appearing in one-third of major attacks.
Bitdefender's team of several hundred security researchers conducted this foundational study as part of the development of GravityZone Proactive Hardening and Attack Surface Reduction (PHASR) technology. The company is sharing these initial findings in advance of a more comprehensive report.
"Attackers are demonstrably successful in evading traditional defences by expertly manipulating the very system utilities we trust and rely on daily – and threat actors operate with a confident assertion of undetectability. This stark reality demands a fundamental shift towards security solutions like Bitdefender's PHASR, which moves beyond blunt blocking to discern and neutralise malicious intent within these tools," the report stated.
The use of well-known tools such as powershell.exe, wscript.exe, and cscript.exe was common among both administrators and attackers. Notably, netsh.exe's prevalence among attackers was unexpected compared to its more typical use by administrators for network management, firewall configuration, and routing.
Other tools often targeted by attackers include reg.exe, used to query and modify Windows registry entries; csc.exe, the Microsoft C# Compiler; and rundll32.exe, which loads and executes functions from DLL files, frequently facilitating DLL sideloading attacks.
Some tools, such as mshta.exe, pwsh.exe, and bitsadmin.exe, were found to be used often by threat actors but rarely by administrators, presenting an additional challenge for traditional security monitoring, which tends to focus on more familiar administration tools.
The research also identified a subset of tools primarily used by developers, such as msbuild.exe and ngen.exe, that are less recognised by security monitoring systems focused only on administration binaries. Their legitimate use in development environments allows them to evade detection more easily.
Analysis also revealed that PowerShell was not used solely by administrators.
The study found that 96 per cent of organisations in the dataset legitimately utilise PowerShell, with activity detected on 73 per cent of endpoints. Many third-party applications were discovered invoking PowerShell code without any visible interface, blurring the distinction between routine and potentially malicious use.
A similar pattern was found with wmic.exe, an older management tool now largely superseded by PowerShell but still in use by third-party applications to gather system information, despite its planned deprecation by Microsoft.
Geographical comparisons demonstrated varying patterns in tool usage.
In the Asia-Pacific (APAC) region, PowerShell was present in only 53.3 per cent of organisations studied, contrasting with a rate of 97.3 per cent in the Europe-Middle East-Africa (EMEA) region. Conversely, use of reg.exe was higher in APAC compared with other regions.
The report noted the significance of such differences. It said, "This underscores the importance of nuanced understanding, as even tools appearing outdated or unused can be critical for specific functions and disabling them can cause unforeseen disruptions."
The findings directly informed the design of Bitdefender's PHASR technology, which adopts a targeted, behaviour-based approach to endpoint security. Rather than indiscriminately blocking entire utilities, PHASR analyses the actions performed within tools like powershell.exe, wmic.exe, or certutil.exe, and allows or blocks specific behaviours based on baseline use and known malicious patterns.
The report detailed PHASR's methodology: the technology monitors typical user and application behaviour on each endpoint, comparing ongoing activity with patterns characteristic of cyberattacks.
This allows for proactive blocking of suspicious actions without impeding legitimate business operations or requiring constant policy updates.
Highlighting the threat posed by the use of trusted tools, the report quoted the leader of the BlackBasta ransomware group, known as 'gg': "If we use standard utilities, we won't be detected... We never drop tools on machines."
Referring to this observation, the report stated, "The staggering 84 per cent prevalence of Living off the Land (LOTL) techniques in major attacks directly validates this adversary perspective."
The assessment of the ongoing challenge provided by these techniques was summarised as, "Attackers are demonstrably successful in evading traditional defences by expertly manipulating the very system utilities we trust and rely on daily – and threat actors operate with a confident assertion of undetectability."
"This stark reality demands a fundamental shift towards security solutions like Bitdefender's PHASR, which moves beyond blunt blocking to discern and neutralise malicious intent within these tools."

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security
Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security

Scoop

time2 days ago

  • Scoop

Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security

Designed as an add-on to Bitdefender GravityZone, the companys flagship unified security and risk analytics platform, GravityZone Compliance Manager minimises complexity by unifying compliance, risk, and security operations in a single platform. GravityZone Compliance Manager Reduces the Cost and Complexity of Regulatory Compliance Requirements Across All Environments and Industries Bitdefender, a global cybersecurity leader, today announced GravityZone Compliance Manager, a new addition to its GravityZone platform that helps organisations reduce the burden of compliance and streamline audit readiness. Designed specifically for today's complex regulatory landscape, the solution provides real-time visibility, automated remediation, audit-ready reports, and one-click compliance documentation fully integrated with Bitdefender endpoint security and risk analytics. 'GravityZone Compliance Manager performed well for us during early access. The continuous monitoring and assessment feature reduced our reliance on manual scans, saving valuable time. Because it's integrated into our existing security stack, we've avoided the additional cost and complexity of using external tools. It has simplified our operations by eliminating the need for multiple point solutions,' stated Alin Paunescu, chief information security officer at Patria Bank. In recent research, Gartner® recommends that organisations, 'Combine compliance and risk management effectively by prioritising the implementation of impact-based assessments and automated, continuous monitoring capabilities¹.' With regulations like GDPR, PCI DSS, NIS2 and DORA introducing stricter penalties, organisations can no longer afford fragmented or manual compliance approaches. The financial consequences of non-compliance are severe with fines up to €20 million or four per cent of global annual turnover under GDPR and US$100 thousand per month under PCI DSS. These penalties come in addition to significant reputational damage organisations face that often follows regulatory violations. Regulatory demands are increasing, but most organisations still rely on fragmented tools and manual processes. Designed as an add-on to Bitdefender GravityZone, the company's flagship unified security and risk analytics platform, GravityZone Compliance Manager minimises complexity by unifying compliance, risk, and security operations in a single platform. It delivers real-time compliance scoring, automated reporting, and guided remediation, all without the need for specialised in-house expertise. Key Benefits of GravityZone Compliance Manager: Automated Audit-Ready Reports in Seconds –Instantly generate compliance reports aligned with auditor requirements using existing Bitdefender tooling. GravityZone Compliance Manager simplifies audit preparation by automating evidence collection and removing reporting complexity. Reports are structured for auditor review and include an executive summary of the organisation's overall compliance score, a breakdown of compliant versus non-compliant checks, and a risk overview detailing the severity of high, medium, and low risks. One Platform for Security, Risk Management, and Compliance – GravityZone Compliance Manager builds on Bitdefender's unified platform by adding compliance management to a foundation that already includes prevention, detection, response, and risk analytics. Combined with Bitdefender Proactive Hardening and Attack Surface Reduction (PHASR), which proactively reduces exposure by disabling unused or risky system tools, organisations can both harden their environments and stay continuously aligned with compliance requirements. When risks are resolved, compliance status updates automatically which streamlines operations and improves organisations' cybersecurity posture. Supports Major Industry and Geo Specific Compliance Standards – GravityZone Compliance Manager provides immediate visibility into endpoint compliance posture and streamlines regulatory alignment with out-of-the-box support for major frameworks—including region and industry-specific standards such as GDPR, HIPAA, DORA, NIS 2 Directive, PCI DSS, SOC 2, ISO 27001, CISv8, CMMC 2.0 and more. Businesses quickly identify and remediate compliance gaps with a single click and can drill down further into specific standards or benchmarks to view detailed information on associated risks and affected assets. 'The consequences of non-compliance, including financial loss, operational disruption, and reputational damage, rival those of a data breach or ransomware attack, yet most businesses lack the resources or specialised talent needed to manage compliance with confidence,' said Andrei Florescu, president and general manager of Bitdefender Business Solutions Group. 'GravityZone Compliance Manager is a game-changer that consolidates compliance, risk management, and endpoint security on a single platform, enabling businesses to meet regulatory demands effortlessly and reduce complexity to strengthen cyber resilience.' Availability Bitdefender GravityZone Compliance Manager is available now for new and existing customers. All Risk Management users receive automatic access to a basic standard with real-time insights and best-practice guidelines. A full Compliance Manager add-on license unlocks support for advanced compliance frameworks, detailed scoring, full compliance visibility, and exportable reports. For more information visit here. Notes: ¹Gartner, 2025 Strategic Roadmap for Cyber GRC, Jie Zhang, Michael Kranawetter, October 4, 2024. Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. * Legal Notice Bitdefender GravityZone Compliance Manager features and reports are designed to help organisations with compliance-related security activities, in particular with assessing and helping maintain compliance with its listed standards and baselines but can neither fully replace internal efforts nor guarantee that an organisation will pass a compliance audit. Bitdefender recommends working with an approved auditor to obtain any official compliance certifications. About Bitdefender Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumers, enterprises, and government environments, Bitdefender is one of the industry's most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioural analytics, and artificial intelligence and its technology is licensed by more than 180 of the world's most recognised technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit

Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security
Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security

Scoop

time2 days ago

  • Scoop

Bitdefender Launches Powerful Compliance Management Solution Unified With Endpoint Security

GravityZone Compliance Manager Reduces the Cost and Complexity of Regulatory Compliance Requirements Across All Environments and Industries Bitdefender, a global cybersecurity leader, today announced GravityZone Compliance Manager, a new addition to its GravityZone platform that helps organisations reduce the burden of compliance and streamline audit readiness. Designed specifically for today's complex regulatory landscape, the solution provides real-time visibility, automated remediation, audit-ready reports, and one-click compliance documentation fully integrated with Bitdefender endpoint security and risk analytics. 'GravityZone Compliance Manager performed well for us during early access. The continuous monitoring and assessment feature reduced our reliance on manual scans, saving valuable time. Because it's integrated into our existing security stack, we've avoided the additional cost and complexity of using external tools. It has simplified our operations by eliminating the need for multiple point solutions,' stated Alin Paunescu, chief information security officer at Patria Bank. In recent research, Gartner® recommends that organisations, 'Combine compliance and risk management effectively by prioritising the implementation of impact-based assessments and automated, continuous monitoring capabilities¹.' With regulations like GDPR, PCI DSS, NIS2 and DORA introducing stricter penalties, organisations can no longer afford fragmented or manual compliance approaches. The financial consequences of non-compliance are severe with fines up to €20 million or four per cent of global annual turnover under GDPR and US$100 thousand per month under PCI DSS. These penalties come in addition to significant reputational damage organisations face that often follows regulatory violations. Regulatory demands are increasing, but most organisations still rely on fragmented tools and manual processes. Designed as an add-on to Bitdefender GravityZone, the company's flagship unified security and risk analytics platform, GravityZone Compliance Manager minimises complexity by unifying compliance, risk, and security operations in a single platform. It delivers real-time compliance scoring, automated reporting, and guided remediation, all without the need for specialised in-house expertise. Key Benefits of GravityZone Compliance Manager: Automated Audit-Ready Reports in Seconds –Instantly generate compliance reports aligned with auditor requirements using existing Bitdefender tooling. GravityZone Compliance Manager simplifies audit preparation by automating evidence collection and removing reporting complexity. Reports are structured for auditor review and include an executive summary of the organisation's overall compliance score, a breakdown of compliant versus non-compliant checks, and a risk overview detailing the severity of high, medium, and low risks. One Platform for Security, Risk Management, and Compliance – GravityZone Compliance Manager builds on Bitdefender's unified platform by adding compliance management to a foundation that already includes prevention, detection, response, and risk analytics. Combined with Bitdefender Proactive Hardening and Attack Surface Reduction (PHASR), which proactively reduces exposure by disabling unused or risky system tools, organisations can both harden their environments and stay continuously aligned with compliance requirements. When risks are resolved, compliance status updates automatically which streamlines operations and improves organisations' cybersecurity posture. Supports Major Industry and Geo Specific Compliance Standards – GravityZone Compliance Manager provides immediate visibility into endpoint compliance posture and streamlines regulatory alignment with out-of-the-box support for major frameworks—including region and industry-specific standards such as GDPR, HIPAA, DORA, NIS 2 Directive, PCI DSS, SOC 2, ISO 27001, CISv8, CMMC 2.0 and more. Businesses quickly identify and remediate compliance gaps with a single click and can drill down further into specific standards or benchmarks to view detailed information on associated risks and affected assets. 'The consequences of non-compliance, including financial loss, operational disruption, and reputational damage, rival those of a data breach or ransomware attack, yet most businesses lack the resources or specialised talent needed to manage compliance with confidence,' said Andrei Florescu, president and general manager of Bitdefender Business Solutions Group. 'GravityZone Compliance Manager is a game-changer that consolidates compliance, risk management, and endpoint security on a single platform, enabling businesses to meet regulatory demands effortlessly and reduce complexity to strengthen cyber resilience.' Availability Bitdefender GravityZone Compliance Manager is available now for new and existing customers. All Risk Management users receive automatic access to a basic standard with real-time insights and best-practice guidelines. A full Compliance Manager add-on license unlocks support for advanced compliance frameworks, detailed scoring, full compliance visibility, and exportable reports. For more information visit here. Notes: ¹Gartner, 2025 Strategic Roadmap for Cyber GRC, Jie Zhang, Michael Kranawetter, October 4, 2024. Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. * Legal Notice Bitdefender GravityZone Compliance Manager features and reports are designed to help organisations with compliance-related security activities, in particular with assessing and helping maintain compliance with its listed standards and baselines but can neither fully replace internal efforts nor guarantee that an organisation will pass a compliance audit. Bitdefender recommends working with an approved auditor to obtain any official compliance certifications. About Bitdefender Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumers, enterprises, and government environments, Bitdefender is one of the industry's most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioural analytics, and artificial intelligence and its technology is licensed by more than 180 of the world's most recognised technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit

Bitdefender unveils GravityZone tool for easier compliance
Bitdefender unveils GravityZone tool for easier compliance

Techday NZ

time2 days ago

  • Techday NZ

Bitdefender unveils GravityZone tool for easier compliance

Bitdefender has released a new compliance management solution designed to address the growing regulatory and audit requirements faced by organisations across industries. The company has introduced GravityZone Compliance Manager, which aims to assist businesses in reducing the costs and operational obstacles associated with compliance while streamlining the process of achieving audit readiness. The solution comes at a time when regulations such as GDPR, PCI DSS, NIS2, and DORA are enforcing stricter penalties for non-compliance, including fines up to EUR €20 million or 4% of global annual turnover under GDPR, and USD $100,000 per month under PCI DSS. These penalties are in addition to reputational harm that can result from regulatory breaches. GravityZone Compliance Manager provides real-time visibility into an organisation's compliance posture, automates remediation tasks, generates audit-ready reports, and allows for one-click compliance documentation. The solution is fully integrated with Bitdefender's existing endpoint security and risk analytics platform. Andrei Florescu, President and General Manager of Bitdefender Business Solutions Group, commented on the release: "The consequences of non-compliance, including financial loss, operational disruption, and reputational damage, rival those of a data breach or ransomware attack, yet most businesses lack the resources or specialised talent needed to manage compliance with confidence." "GravityZone Compliance Manager is a game-changer that consolidates compliance, risk management, and endpoint security on a single platform, enabling businesses to meet regulatory demands effortlessly and reduce complexity to strengthen cyber resilience." Patria Bank has served as an early access client for GravityZone Compliance Manager. Alin Paunescu, Chief Information Security Officer at Patria Bank, shared insights on the tool's impact: "GravityZone Compliance Manager performed well for us during early access. The continuous monitoring and assessment feature reduced our reliance on manual scans, saving valuable time. Because it's integrated into our existing security stack, we've avoided the additional cost and complexity of using external tools. It has simplified our operations by eliminating the need for multiple point solutions." Recent guidance from Gartner has underscored the importance of integrating compliance and risk management via automated, continuous monitoring and impact-based assessments. According to research cited by Bitdefender, organisations increasingly risk severe consequences for fragmented or manual approaches to regulatory compliance. Despite escalating regulatory demands globally, many organisations continue to rely on siloed tools and manual processes that may be insufficient to address comprehensive compliance requirements. GravityZone Compliance Manager is designed as an add-on to the company's core GravityZone platform to provide a unified approach, bringing together compliance, risk, and security operations in one system. This integration includes real-time compliance scoring, automated reporting, and guided remediation without requiring specialised in-house compliance expertise. The solution's features include automated audit-ready reports that can be generated in seconds, using information already collected by Bitdefender tools. These reports are structured to meet auditor standards and include an executive summary, an analysis of compliant versus non-compliant checks, and a risk overview with a severity breakdown. Additionally, the platform integrates compliance management with security and risk analytics alongside tools like Bitdefender Proactive Hardening and Attack Surface Reduction (PHASR). This combination allows organisations to reduce system vulnerabilities and maintain ongoing alignment with compliance requirements. Whenever risks are mitigated, the platform automatically updates compliance status, enhancing operational efficiency and cybersecurity posture. GravityZone Compliance Manager supports immediate alignment with a broad range of industry and geography-specific frameworks, such as GDPR, HIPAA, DORA, NIS 2 Directive, PCI DSS, SOC 2, ISO 27001, CISv8, and CMMC 2.0. Organisations can identify and address compliance gaps with a single click and access detailed information on risks and affected assets per standard. The solution's full feature set is available to new and existing GravityZone customers. Organisations using the platform's risk management functions gain immediate access to a standard set of compliance tools, while a full Compliance Manager add-on licence provides support for advanced frameworks, comprehensive scoring, enhanced visibility, and exportable reports. Bitdefender has indicated that while GravityZone Compliance Manager is intended to assist organisations with compliance-related activities, it does not replace internal compliance efforts or guarantee the outcome of external audits. The company recommends that organisations work with approved auditors for formal compliance certification processes.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store