Calling the said executables and doing some work through them is a standard tactic that attackers have applied for many years, to fragment the attacks and fool the correlational logics, which in a behavioural blocking are the most crucial and very high amount of R&D is focused on them.
The initial vector can still be an executable file which Webroot through reputation, Infrared and so on can still detect. But it will be a different result if the same LOLBins are called through documents, scripts, exploits and other methods.
The Webroot protection against these is poor and needs to be layered with other products to fill the blind spots.
Furthermore, Webroot by default does not monitor the behaviour of these LOLBins.
The initial vector can still be an executable file which Webroot through reputation, Infrared and so on can still detect. But it will be a different result if the same LOLBins are called through documents, scripts, exploits and other methods.
The Webroot protection against these is poor and needs to be layered with other products to fill the blind spots.
Furthermore, Webroot by default does not monitor the behaviour of these LOLBins.




