If you’ve invested in an EDR (Endpoint Detection and Response) platform, you’d expect it to catch most of what comes at your network. But a growing share of today’s breaches don’t involve malware at all. Attackers are logging in with stolen credentials and using the tools already sitting on your machines — PowerShell, WMI, remote management software — to move around, escalate privileges, and quietly exfiltrate data. Because none of that looks like “malware” to a traditional security tool, it often slides right past detection.
These are called Living-Off-the-Land (LOTL) attacks, and they’re no longer a niche concern. Bitdefender Labs analyzed 700,000 high-severity security incidents and found that living-off-the-land techniques were present in the vast majority of them, and other industry research puts LOTL involvement in successful breaches at somewhere between 70% and 85%. Separately, CrowdStrike’s 2026 threat research found that the large majority of intrusions it tracked used no malware whatsoever, relying instead on valid credentials and legitimate tools already inside the environment.
If you’re a small or mid-sized business owner reading that and thinking, “Do I need to rip out my EDR and start over?” you don’t. The good news is that stopping LOTL attacks isn’t about replacing what you already have. It’s about closing the gap that traditional detection-and-response tools were never designed to cover.
Most EDR platforms are built to spot something unusual: an unrecognized file, a suspicious process, a known malware signature. LOTL attacks don’t give them anything to flag. When an attacker uses PowerShell to move laterally through your network, PowerShell is a legitimate, signed, expected part of Windows. Your EDR sees a normal admin tool doing normal admin-tool things because, technically, it is. The difference is who is using it and why, and that context is exactly what signature- and behavior-alert-based tools struggle to evaluate in real time.
This is what security researchers increasingly describe as a “trust gap.” Attackers don’t need custom malware if they can simply borrow the credibility of tools you already trust. And because these techniques mimic normal IT activity, they can sit undetected in an environment for weeks — long enough to map out your network, locate valuable data, and stage a ransomware attack before anyone notices.
Common LOTL tools and techniques worth knowing:
None of this requires exotic hacking skills. It requires patience, and it requires a target whose defenses stop at “is this software known to be bad?”
A natural instinct is to tune your EDR to be more aggressive, or add another monitoring layer on top. In practice, this usually backfires for small businesses. Every legitimate use of PowerShell, every RMM connection, every admin login becomes a potential alert — and your team (or your IT provider) drowns in false positives long before they catch the one alert that actually matters. Detection-based tools, no matter how well-tuned, are reactive by design. They tell you something happened. They don’t stop the misuse of a trusted tool from being possible in the first place.
That’s the real gap: not a lack of visibility, but a lack of prevention for activity that looks legitimate on its face.
That’s exactly what a security assessment is for. Schedule a free consultation with the Black Diamond Solutions team, and we’ll walk through your existing stack and show you where the blind spots actually are — no obligation, no sales pitch.
Instead of trying to detect LOTL behavior after the fact, a newer category of security technology works by narrowing what’s possible before an attacker gets the chance to abuse it. Gartner refers to this emerging category as Dynamic Attack Surface Reduction (DASR) technology that continuously restricts which tools, privileges, and actions are actually available to each user and device, based on what that user or device normally does.
Instead of asking “does this activity look malicious?” a DASR tool asks “does this user or device normally need this tool, at this privilege level, doing this action?” If the answer is no, the tool or action gets restricted automatically before it can be used against you. Because this approach works on the opportunity for misuse rather than trying to spot the misuse itself, it closes off the exact blind spot that lets LOTL techniques succeed against otherwise well-run EDR deployments.
Critically, this type of technology is designed to sit alongside your existing EDR or XDR platform, not replace it. It doesn’t matter whether your business runs Bitdefender, CrowdStrike, Microsoft Defender, SentinelOne, or another platform — a DASR layer is meant to plug into what you already have and tighten the gaps around it.
One of the clearest examples of this approach in action is Bitdefender GravityZone PHASR (Proactive Hardening and Attack Surface Reduction). Bitdefender built PHASR specifically to combine behavior-based hardening with real-time threat intelligence, and notably released it as a standalone product that’s compatible with any third-party EDR or XDR tool, not just Bitdefender’s own platform. That means an organization running a completely different EDR vendor can still add PHASR as an additional layer without disrupting or reconfiguring what’s already in place.
Here’s roughly how it works in practice:
The goal is to make it materially harder for an attacker to succeed with the exact playbook that traditional EDR alone tends to miss — locking down risky, unnecessary access to tools like PowerShell and WMI on a per-user basis — while leaving your existing endpoint protection and detection tools fully intact and doing their job.
For a deeper look at how PHASR’s behavioral hardening works, the licensing paths available (standalone, GravityZone add-on, or MDR-included), and how it fits into your existing stack, see BDS’s Bitdefender PHASR page.
Schedule a free demo with Black Diamond Solutions, a Bitdefender Gold Partner and US Partner of the Year, and we’ll show you what it looks like running alongside the EDR you already have — no rip-and-replace required.
If you’re exploring this category of tool for the first time, a few questions are worth asking any vendor or partner before you commit:
The practical path most small businesses take looks like this:
LOTL attacks succeed by hiding inside the tools you already trust, which is precisely why detection-only tools — no matter how good — will always be playing catch-up against them. The fix isn’t a bigger, more complicated security stack. It’s adding a layer that’s purpose-built to shrink the attacker’s opportunity in the first place, without touching the EDR investment you’ve already made.
Black Diamond Solutions has been a Bitdefender Gold Partner for years, and we work with businesses running Bitdefender, Huntress, Blackpoint Cyber, and other EDR platforms every day. If LOTL attacks are on your radar — or if you’re just not sure whether your current setup would catch one — we’re happy to walk through it with you.
LOTL attacks are a technique where attackers use legitimate, pre-installed tools on your systems like PowerShell, WMI, or remote access software to carry out malicious activity, instead of installing custom malware. Because the tools themselves are trusted and expected, this activity often blends in with normal IT operations.
Most EDR tools are built to flag suspicious files or known-bad behavior. LOTL techniques use software your systems already trust, so there’s often nothing “abnormal” for the tool to flag — the activity looks like routine admin work unless something is specifically watching for context, like who’s using the tool and whether that matches their normal behavior.
No. The most effective approach is adding a dynamic attack surface reduction (DASR) layer that runs alongside your existing EDR or XDR platform, rather than replacing it. Tools like Bitdefender GravityZone PHASR are specifically built to be vendor-agnostic add-ons.
EDR primarily detects and responds to threats after suspicious activity occurs. Attack surface reduction works proactively, restricting which tools, privileges, and actions are available to a user or device in the first place so there’s less for an attacker to exploit, regardless of whether it gets detected.
PHASR (Proactive Hardening and Attack Surface Reduction) is a Bitdefender security solution that builds behavioral baselines for users and devices, then automatically restricts tools or actions that fall outside normal patterns. It’s available as a standalone product compatible with third-party EDR and XDR platforms, not just Bitdefender’s own tools. See BDS’s PHASR page for a full breakdown of capabilities and licensing options.
Well-designed DASR tools restrict specific actions or tools that fall outside a user’s normal behavior, rather than locking down entire accounts or devices. A short baselining period and a phased rollout (starting with a subset of devices) helps confirm normal workflows aren’t disrupted before a company-wide deployment.
No. PHASR is available as a standalone license specifically designed to work alongside any third-party EDR or XDR tool, in addition to being available as an add-on for Bitdefender’s own GravityZone platform.
LOTL techniques aren’t limited to large enterprises. Because they exploit tools present in nearly every Windows environment, small businesses without dedicated security operations staff are often more exposed — they’re less likely to have someone actively distinguishing legitimate admin activity from misuse.
If you’re relying solely on EDR or antivirus without a managed security team actively reviewing behavior, or if you handle sensitive client, financial, or healthcare data, it’s worth having your environment assessed. A short conversation with a managed security provider can usually tell you where you stand.
The best first step is a no-obligation conversation about your current environment. Black Diamond Solutions can review what you have in place, identify where LOTL-style techniques could slip through, and if it makes sense for your business — show you how an attack surface reduction layer like PHASR would fit in without disrupting your existing tools.
Living-off-the-land attacks are built to slip past the tools you already trust. Black Diamond Solutions can assess your current environment, show you exactly where the coverage gaps are, and help you decide whether adding a layer like Bitdefender GravityZone PHASR makes sense — all without disrupting the EDR platform you’ve already invested in.
Black Diamond Solutions
Free consultation • No obligation • Typically same-day response