Why antivirus misses modern attacks (living off the land)
Updated 10/5/2026 · 5 min read
Antivirus is built to recognise known malicious files. But many attacks today don't bring a malicious file at all. They use the legitimate, signed tools already on your computer — a technique called "living off the land" (LotL).
The tools they borrow - **PowerShell / cmd** — to download and run code. - **mshta.exe, rundll32.exe, regsvr32.exe** — to run scripts while looking like normal Windows activity. - **certutil.exe, bitsadmin.exe** — to download files. - **Remote-access apps** (AnyDesk, TeamViewer) and **tunnels** (ngrok, cloudflared) — to get in and stay in.
Because these are trusted, signed programs, antivirus usually lets them run. What matters is how they're being used: what started them, and what they're connecting to.
How to spot it - A built-in Windows tool making an outbound internet connection you can't explain. - A scheduled task or startup entry that launches PowerShell or mshta. - Remote-access software you didn't install. - A tunnelling tool (ngrok, rclone) on a machine that has no reason to run one.
What to do Behaviour-based checks catch this where signature-based antivirus doesn't — so keep your antivirus **and** add a check that looks at behaviour. Keepvik flags exactly these patterns and a security expert reviews them with you.
Want to check your own PC?
The free Quick Scan looks for everything in this guide in about a minute.
Free Quick Scan