Microsoft starts removing WMIC tool used by cybercriminals
Microsoft removes legacy WMIC tool from Windows 11 to enhance security.
Summary
Microsoft has begun removing the legacy Windows Management Instrumentation Command-line (WMIC) tool from recent Windows 11 versions, including 24H2 and 25H2. This move aims to improve OS security by preventing cybercriminals from abusing WMIC, a known living-off-the-land binary (LOLBIN), for malicious activities such as deleting shadow copies, querying security software, and adding exclusions to Microsoft Defender. Administrators are advised to transition to modern tools like PowerShell.
Full text
Microsoft starts removing WMIC tool used by cybercriminals By Sergiu Gatlan August 18, 2026 04:12 AM 0 Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. WMIC is a legacy built-in Windows command-line utility that helps interact with the Windows Management Instrumentation (WMI) system using text commands. This move is part of a process announced in September, when the company said that WMIC will be removed after upgrading to Windows 11 25H2 and later. Microsoft deprecated WMIC in Windows Server 2012 (in 2016) and Windows 10 21H1 (in 2021), and it converted it into a Feature on Demand (FoD) starting with Windows 11 22H2 (in 2022), and announced in January 2024 that it would be removed altogether after first disabling it by default. "Windows Management Instrumentation Command-line (WMIC) has been removed in this release. This change is part of the ongoing deprecation and removal of WMIC from Windows," Microsoft noted on Monday. Three days earlier, on Friday, it also revealed that the tool is "already removed by default in new installations of Windows 11, versions 24H2 and 25H2, and is no longer available as a Feature on Demand (FoD)." However, these changes apply only to the legacy WMIC component, as Windows Management Instrumentation (WMI) itself remains unaffected. Further guidance for IT administrators who use WMIC is available in this support document, which recommends using PowerShell and other modern tools (e.g., WMI's COM API, .NET libraries, or scripting languages) for tasks previously done with WMIC. WMIC's removal aims to improve the operating system's overall security by thwarting a wide range of malware and attack tactics that will no longer work. The tool has long been considered a LOLBIN (living-off-the-land binary), a built-in Microsoft-signed executable that threat actors have abused for a wide range of malicious activities during attacks targeting Windows devices. For instance, ransomware encryptors commonly use the WMIC command to delete Shadow Volume Copies to ensure that the victims can't recover encrypted data. Other threat actors have also used WMIC to query for the list of installed security solutions and antivirus software and uninstall them. Malware has also been observed using WMIC to add exclusions to Microsoft Defender, which helps evade detection on compromised systems. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Windows KB5121767 OOB update fixes shutdowns on some Dell PCsNew Windows RasMan zero-day flaw gets free, unofficial patchesWindows 11 24H2 Home and Pro reach end of support in 90 daysMicrosoft: Some Dell PCs shut down after recent Windows updatesMicrosoft starts testing cleaner Windows Search without ads