Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Microsoft starts removing WMIC tool used by cybercriminals

0
Medium
Published: 08/18/2026 (08/18/2026, 08:12:08 UTC)
Source: Bleeping Computer

Description

Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, including beta builds. WMIC, a command-line utility for interacting with Windows Management Instrumentation, has been deprecated since Windows Server 2012 and Windows 10 21H1 and was converted to a Feature on Demand in Windows 11 22H2. The removal aims to improve security by eliminating a living-off-the-land binary (LOLBin) frequently abused by attackers for malicious activities such as deleting shadow copies, disabling security software, and evading detection. The underlying WMI system remains unaffected, and Microsoft recommends using PowerShell and other modern tools for management tasks previously done with WMIC.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 08:41:31 UTC

Technical Analysis

Microsoft has officially removed the WMIC tool from Windows 11 versions 24H2 and 25H2 and their beta builds as part of a phased deprecation process that began years ago. WMIC is a legacy command-line utility that interacts with the Windows Management Instrumentation system. It has been abused by cybercriminals as a LOLBin to perform malicious actions including deleting Shadow Volume Copies to prevent data recovery, querying and uninstalling security software, and adding exclusions to Microsoft Defender to evade detection. Microsoft disabled WMIC by default in earlier versions and removed it entirely in these recent releases. The removal does not affect the WMI system itself, and administrators are advised to use PowerShell, WMI COM APIs, .NET libraries, or scripting languages for equivalent functionality. This removal is intended to reduce the attack surface and hinder common malware tactics that rely on WMIC.

Potential Impact

The removal of WMIC reduces the availability of a tool commonly exploited by attackers for post-compromise activities such as disabling security defenses, deleting backup shadow copies, and evading detection. This limits attackers' ability to use this built-in Microsoft-signed executable for malicious purposes on Windows 11 24H2 and 25H2 systems. However, the underlying WMI infrastructure remains intact, so legitimate management and automation tasks can continue using supported modern tools. This change improves the security posture of affected Windows 11 versions by removing a frequently abused legacy utility.

Defensive Guidance

This change is an official removal by Microsoft in Windows 11 versions 24H2 and 25H2 and their beta builds. No action is required to remove WMIC as it is no longer included by default or available as a Feature on Demand in these versions. IT administrators should transition management scripts and automation workflows from WMIC to supported alternatives such as PowerShell cmdlets, WMI COM APIs, .NET libraries, or other scripting languages as recommended by Microsoft. Refer to Microsoft's official guidance for detailed instructions on migrating away from WMIC.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/","fetched":true,"fetchedAt":"2026-08-18T08:41:18.021Z","wordCount":694}

Threat ID: 6a841aaebf8831d539798a07

Added to database: 08/18/2026, 08:41:18 UTC

Last enriched: 08/18/2026, 08:41:31 UTC

Last updated: 08/18/2026, 10:57:44 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses