The antivirus never fired. Event logs looked normal. PowerShell was running scripts, certutil was downloading files, scheduled tasks were doing their thing — all Windows doing Windows things. Until someone looked closely and realized that “Windows” had been working for someone else for weeks.
Attacks the antivirus cannot see
Traditional malware — a malicious executable that gets downloaded and run — is relatively easy to catch. Signature-based antivirus identifies it if the signature is registered. But over the last five years, sophisticated attackers have almost entirely abandoned file-based malware in favor of a technique called “living off the land” (LOTL): using the operating system’s own legitimate tools to execute malicious operations.
PowerShell, WMI, certutil, mshta, regsvr32, BITS — all legitimate Windows tools. All weaponized as attack vectors. When an attacker uses them, the antivirus sees a system tool doing system things. There is no malicious file to detect.
How it works in practice
The most common scenario: an employee receives an email with an Office document containing a macro. The document looks legitimate — a vendor quote, a purchase order, a bank notification. The employee enables macros because the document asks them to. The macro executes PowerShell in the background. PowerShell, using BITS or certutil, downloads a second payload from an external server. That payload establishes persistence through a system scheduled task. The command-and-control connection exits through port 443 (HTTPS) to blend with legitimate traffic. The attacker now has remote access to the machine, with the credentials of the user who opened the document.
All of this happens in seconds. The antivirus does not intervene because each individual component is legitimate.
What the IT manager finds weeks later
In the worst case — the most common in SMBs without active monitoring — the incident is discovered when the attacker decides to act: encrypting files with ransomware, exfiltrating data for sale or blackmail, or using the company’s resources to attack third parties. For the IT manager, the hardest conversation is explaining how someone had network access for weeks without anyone noticing. Without EDR, without behavioral logs, there is no satisfying technical answer. Only uncertainty about what was accessed, modified, and stolen.
The defense: visibility, not just blocking
The only effective defense against LOTL attacks is behavioral visibility — shifting the focus from “block what is bad” to “log everything and analyze anomalies.” The tools that provide that visibility include:
- EDR (Endpoint Detection and Response): logs every process, every network connection, every registry modification. When PowerShell does something unusual — connecting to an external IP, writing to a system directory — the EDR logs it and can alert in real time.
- Macro restrictions via Group Policy: disabling macros for documents from external sources is one of the most effective measures to block the most common initial vector.
- PowerShell detailed logging: Script Block Logging and Module Logging generate telemetry that allows detecting malicious use even of legitimate tools.
The question every IT manager must answer
If an attacker had access to a device on your network for the past two weeks, would you know? Would you have the logs to confirm it? If the answer is not “yes, with certainty,” your company has a visibility gap that needs to be addressed.
AVN Networks implements detection and response strategies that go well beyond antivirus. If your company does not have behavioral visibility on its endpoints, let’s talk before circumstances force it.