Bitdefender’s newly released 2026 Cybersecurity Assessment has confirmed something the industry has suspected for a while: the biggest active threat to most businesses is not exotic new malware. It is attackers quietly using the tools already installed on your network.
The report, based on an independent survey of 1,200 IT and cybersecurity professionals across six countries, found that 84% of high-severity attacks analysed by Bitdefender Labs used Living off the Land (LOTL) techniques. Yet only one in five of the professionals surveyed ranked LOTL attacks among their top three concerns. That gap between what is actually happening and what security teams are watching for is the real story here.
What a living off the land attack actually looks like
LOTL attacks abuse legitimate software and system utilities that are already present in an environment, rather than introducing new malicious files. Tools such as PowerShell, Windows Management Instrumentation, and remote desktop protocol get repurposed by attackers to move through a network undetected.
The reason this technique is so effective is straightforward. Traditional antivirus and signature-based detection is built to spot unfamiliar files and known malware patterns. A LOTL attack does not look unfamiliar. It looks like normal admin activity, because in most cases it is using the same tools your own IT team relies on every day.
For Mac-first and hybrid businesses, this matters just as much as it does in Windows-heavy environments. macOS has its own set of built-in scripting and remote management tools that can be misused in the same way if endpoint monitoring is not configured to flag unusual behaviour rather than just unusual files.
Why AI is getting the attention, and LOTL is not
The Bitdefender survey found that security professionals rank AI-related threats, including self-mutating malware, public LLM data leakage, and AI-driven evasion, as their top concerns. That instinct is not wrong. AI is changing how attacks are built and delivered.
But the report is clear that AI is mostly being used to make existing attack techniques faster and more convincing, rather than to invent entirely new categories of threat. Meanwhile, LOTL techniques, which do not need any AI at all, are already responsible for the overwhelming majority of severe attacks. The attention is on tomorrow’s threat while today’s most common one goes comparatively unwatched.
Dr Logic’s perspective
In Dr Logic’s experience, the businesses most exposed to LOTL-style attacks are not the ones without security tools. They are the ones whose device management and monitoring only flags known bad files, rather than unusual patterns of legitimate tool use. A properly configured DMS (formerly MDM) platform, paired with endpoint monitoring that tracks behaviour rather than just file signatures, closes a large part of this gap.
We recommend treating built-in admin and scripting tools as a monitored asset class in their own right, not an afterthought behind antivirus and firewall spend. If nobody is watching how those tools are being used, an attacker does not need to bring anything new into your environment at all.
What this means for your business
Reducing LOTL exposure does not require ripping out existing tools. It requires visibility into how they are being used, and a plan for restricting or alerting on unusual activity. That is a configuration and monitoring conversation, not a new product purchase.
If your current setup would not flag someone unusually using a legitimate admin tool, that is worth raising with your IT provider this quarter, not after an incident forces the question.
Talk to Dr Logic about strengthening your endpoint monitoring and attack surface visibility.



















































