Microsoft starts removing WMIC tool used by cybercriminals
Summary
Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from recent Windows 11 builds, including 24H2 and 25H2. This decision stems from the tool's frequent misuse by cybercriminals for malicious purposes.
IFF Assessment
The removal of a tool commonly used by attackers, while beneficial for defense in the long run, means that defenders may need to adapt their detection and response strategies.
Defender Context
Microsoft's proactive removal of WMIC highlights a trend of hardening operating systems by eliminating components known to be exploited. Defenders should be aware that attackers may shift to alternative tools or techniques to achieve similar objectives. Monitoring for unusual system command execution, particularly involving WMI, remains a critical defense posture.