Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

The Hacker News by The Hacker News
May 15, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


The Hacker NewsMay 15, 2026Endpoint Security / Threat Detection

In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender’s analysis of 700,000 high-severity incidents found legitimate-tool abuse in 84% of them.

The reaction we heard most was a fair one: We know. So what do we actually do about it?

That’s what Bitdefender’s complimentary Internal Attack Surface Assessment is built to answer. It’s a 45-day, low-effort engagement available to organizations with 250 or more employees that turns the abstract problem of “living off the land” into a specific, prioritized list of users, endpoints, and tools you can safely take away from attackers without breaking the business.

Why This, Why Now

A clean Windows 11 install ships with 133 unique living-off-the-land binaries spread across 987 instances. Bitdefender Labs telemetry found PowerShell active on 73% of endpoints, much of it invoked silently by third-party applications. This isn’t a malware problem — it’s an over-entitlement problem, and you can’t patch your way out of it.

Gartner now projects that preemptive cybersecurity will account for 50% of IT security spending by 2030, up from less than 5% in 2024, and that 60% of large enterprises will adopt dynamic attack surface reduction (DASR) technologies by 2030, up from less than 10% in 2025. The reason is mechanical: when most intrusions involve no malware and adversaries move in minutes, “detect and respond” is too slow a loop. You have to remove the moves attackers can make in the first place.

How the Assessment Works

The engagement runs in four steps over roughly 45 days, powered by GravityZone PHASR — Bitdefender’s Proactive Hardening and Attack Surface Reduction technology — and sits alongside whatever endpoint stack you already run:

  1. Kickoff and behavioral learning. PHASR builds behavioral profiles for every machine-user pair, typically over 30 days.
  2. Attack Surface Dashboard review. You receive an exposure score (0–100) and a prioritized list of findings across five categories: living-off-the-land binaries, remote admin tools, tampering tools, cryptominers, and piracy tools — each mapped to the specific users and devices they affect.
  3. Optional reduction sprint. Apply controls manually or let PHASR’s Autopilot enforce them. Users can request access back through a built-in one-click approval workflow.
  4. Reduction review. A final session quantifies how much surface you’ve shrunk and what shadow IT and unauthorized binaries surfaced along the way.

Early-access customers have reduced their attack surface by 30% or more in the first 30 days, with one reporting close to 70% by locking down LOLBins and remote tools — without investigation overhead or end-user disruption.

What It Means for Different Stakeholders

  • For the CISO: a defensible, board-ready exposure number that moves week over week, mapped to behaviors attackers actually use.
  • For the SOC and IT admin: up to 50% less investigation and response workload, because entire classes of suspicious-but-legitimate behavior simply don’t occur on endpoints that don’t need them.
  • For the business decision-maker: documented, ongoing surface reduction — increasingly what regulators, auditors, and cyber-insurers want to see.

Start Where the Attackers Already Are

The previous article ended on a principle: the most significant risks are no longer external or unknown — they’re already inside your environment. This one ends on a practice: you can have a precise, prioritized map of those risks within 45 days, at no cost, without changing your existing stack.

If you run a Windows-heavy environment with 250 or more users, request your Internal Attack Surface Assessment here. Compromises will keep happening. Whether one becomes a breach depends almost entirely on what an attacker can reach once they’re in. The fastest way to shorten that list is to look at it.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source link

The Hacker News

The Hacker News

Next Post
Jaguar Land Rover profit slumps after cyber attack | Computer Weekly

Jaguar Land Rover profit slumps after cyber attack | Computer Weekly

Recommended.

UScellular announces expected name change to Array Digital Infrastructure

UScellular announces expected name change to Array Digital Infrastructure

July 24, 2025
Emergency Microsoft, Oracle patches point to wider cyber issues | Computer Weekly

Emergency Microsoft, Oracle patches point to wider cyber issues | Computer Weekly

March 26, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio