Microsoft starts removing WMIC tool used by cybercriminals
Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, including beta builds. WMIC, a command-line utility for interacting with Windows Management Instrumentation, has been deprecated since Windows Server 2012 and Windows 10 21H1 and was converted to a Feature on Demand in Windows 11 22H2. The removal aims to improve security by eliminating a living-off-the-land binary (LOLBin) frequently abused by attackers for malicious activities such as deleting shadow copies, disabling security software, and evading detection. The underlying WMI system remains unaffected, and Microsoft recommends using PowerShell and other modern tools for management tasks previously done with WMIC.
AI Analysis
Technical Summary
Microsoft has officially removed the WMIC tool from Windows 11 versions 24H2 and 25H2 and their beta builds as part of a phased deprecation process that began years ago. WMIC is a legacy command-line utility that interacts with the Windows Management Instrumentation system. It has been abused by cybercriminals as a LOLBin to perform malicious actions including deleting Shadow Volume Copies to prevent data recovery, querying and uninstalling security software, and adding exclusions to Microsoft Defender to evade detection. Microsoft disabled WMIC by default in earlier versions and removed it entirely in these recent releases. The removal does not affect the WMI system itself, and administrators are advised to use PowerShell, WMI COM APIs, .NET libraries, or scripting languages for equivalent functionality. This removal is intended to reduce the attack surface and hinder common malware tactics that rely on WMIC.
Potential Impact
The removal of WMIC reduces the availability of a tool commonly exploited by attackers for post-compromise activities such as disabling security defenses, deleting backup shadow copies, and evading detection. This limits attackers' ability to use this built-in Microsoft-signed executable for malicious purposes on Windows 11 24H2 and 25H2 systems. However, the underlying WMI infrastructure remains intact, so legitimate management and automation tasks can continue using supported modern tools. This change improves the security posture of affected Windows 11 versions by removing a frequently abused legacy utility.
Mitigation Recommendations
This change is an official removal by Microsoft in Windows 11 versions 24H2 and 25H2 and their beta builds. No action is required to remove WMIC as it is no longer included by default or available as a Feature on Demand in these versions. IT administrators should transition management scripts and automation workflows from WMIC to supported alternatives such as PowerShell cmdlets, WMI COM APIs, .NET libraries, or other scripting languages as recommended by Microsoft. Refer to Microsoft's official guidance for detailed instructions on migrating away from WMIC.
Microsoft starts removing WMIC tool used by cybercriminals
Description
Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 versions 24H2 and 25H2, including beta builds. WMIC, a command-line utility for interacting with Windows Management Instrumentation, has been deprecated since Windows Server 2012 and Windows 10 21H1 and was converted to a Feature on Demand in Windows 11 22H2. The removal aims to improve security by eliminating a living-off-the-land binary (LOLBin) frequently abused by attackers for malicious activities such as deleting shadow copies, disabling security software, and evading detection. The underlying WMI system remains unaffected, and Microsoft recommends using PowerShell and other modern tools for management tasks previously done with WMIC.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft has officially removed the WMIC tool from Windows 11 versions 24H2 and 25H2 and their beta builds as part of a phased deprecation process that began years ago. WMIC is a legacy command-line utility that interacts with the Windows Management Instrumentation system. It has been abused by cybercriminals as a LOLBin to perform malicious actions including deleting Shadow Volume Copies to prevent data recovery, querying and uninstalling security software, and adding exclusions to Microsoft Defender to evade detection. Microsoft disabled WMIC by default in earlier versions and removed it entirely in these recent releases. The removal does not affect the WMI system itself, and administrators are advised to use PowerShell, WMI COM APIs, .NET libraries, or scripting languages for equivalent functionality. This removal is intended to reduce the attack surface and hinder common malware tactics that rely on WMIC.
Potential Impact
The removal of WMIC reduces the availability of a tool commonly exploited by attackers for post-compromise activities such as disabling security defenses, deleting backup shadow copies, and evading detection. This limits attackers' ability to use this built-in Microsoft-signed executable for malicious purposes on Windows 11 24H2 and 25H2 systems. However, the underlying WMI infrastructure remains intact, so legitimate management and automation tasks can continue using supported modern tools. This change improves the security posture of affected Windows 11 versions by removing a frequently abused legacy utility.
Defensive Guidance
This change is an official removal by Microsoft in Windows 11 versions 24H2 and 25H2 and their beta builds. No action is required to remove WMIC as it is no longer included by default or available as a Feature on Demand in these versions. IT administrators should transition management scripts and automation workflows from WMIC to supported alternatives such as PowerShell cmdlets, WMI COM APIs, .NET libraries, or other scripting languages as recommended by Microsoft. Refer to Microsoft's official guidance for detailed instructions on migrating away from WMIC.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/","fetched":true,"fetchedAt":"2026-08-18T08:41:18.021Z","wordCount":694}
Threat ID: 6a841aaebf8831d539798a07
Added to database: 08/18/2026, 08:41:18 UTC
Last enriched: 08/18/2026, 08:41:31 UTC
Last updated: 08/18/2026, 10:57:44 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.