Microsoft starts removing WMIC tool used by cybercriminals

Summary

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from recent Windows 11 builds, including 24H2 and 25H2. This decision stems from the tool's frequent misuse by cybercriminals for malicious purposes.

IFF Assessment

FOE

The removal of a tool commonly used by attackers, while beneficial for defense in the long run, means that defenders may need to adapt their detection and response strategies.

Defender Context

Microsoft's proactive removal of WMIC highlights a trend of hardening operating systems by eliminating components known to be exploited. Defenders should be aware that attackers may shift to alternative tools or techniques to achieve similar objectives. Monitoring for unusual system command execution, particularly involving WMI, remains a critical defense posture.

Read Full Story →