← Back to Research
Research

Living off the Land: Abuse of Native Windows Binaries in Q3

AuthorDetection Engineering
PublishedJul 22, 2024

Certutil, Bitsadmin, and PowerShell remain the top abused binaries. Our statistical analysis highlights the need for robust execution control and command-line logging (Event ID 4688).