Keepvik
← All guides

Why antivirus misses modern attacks (living off the land)

Updated 10/5/2026 · 5 min read

Antivirus is built to recognise known malicious files. But many attacks today don't bring a malicious file at all. They use the legitimate, signed tools already on your computer — a technique called "living off the land" (LotL).

The tools they borrow - **PowerShell / cmd** — to download and run code. - **mshta.exe, rundll32.exe, regsvr32.exe** — to run scripts while looking like normal Windows activity. - **certutil.exe, bitsadmin.exe** — to download files. - **Remote-access apps** (AnyDesk, TeamViewer) and **tunnels** (ngrok, cloudflared) — to get in and stay in.

Because these are trusted, signed programs, antivirus usually lets them run. What matters is how they're being used: what started them, and what they're connecting to.

How to spot it - A built-in Windows tool making an outbound internet connection you can't explain. - A scheduled task or startup entry that launches PowerShell or mshta. - Remote-access software you didn't install. - A tunnelling tool (ngrok, rclone) on a machine that has no reason to run one.

What to do Behaviour-based checks catch this where signature-based antivirus doesn't — so keep your antivirus **and** add a check that looks at behaviour. Keepvik flags exactly these patterns and a security expert reviews them with you.

Want to check your own PC?

The free Quick Scan looks for everything in this guide in about a minute.

Free Quick Scan