Software Review The biggest risk with Windows: LOLBINS

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
PC Security Channel
failure of your own pattern recognitio
Agree. Don't lnow anything about a 'valiidation gap', Is that something to look for ?

But you are reading a motive into it because you called it an excuse. I see the 2 sentences as stand alone.

I am not a people person, ,as you can tell. I fail to read clues, pattern recognition fail. But just from those 2 statements, they can be stand alone or related, arguable. But I have a blind sight, I prefer to see people as honest rather tnan 'crafty sophists'. For example it takes me a while to recognize a scammer. But I like reading about scams, just so I don't get fooled. But I have to warm up to it. I like to give people 'the benefit of the doubt'. But too many dings and I shut you out.
 
Last edited:
I don't work so I guess I have no need for AI.
I have absolutely no need to use the latest and greatest thing just because everyone else is.
I do not read long winded AI answers here.
So I guess I'm a neanderthal, and I like it. ;)
On this forum, I agree, as far as threads that turn into multiple AI posted replies :)

But, personally, I'm really enjoying using AI (Gemini) on my own time, not because it's the latest and greatest, but it's helping to collate answers to some of my questions that would take much longer sifting through some of the threads here, that a lot of times get derailed for multiple posts and pages. Maybe that's a more recent occurrence compared to the older members who remember how this forum used to be, even before AI?
 
Last edited:
Honestly AI disadvantages outweigh its advantage especially in education sector. Students no longer study or do research. Instead of asking AI for help, they ask AI to do the work for them.

But those who know how to use AI while keeping their work "authentic" are smart.
You are conflating "inefficiency" with "rigor." In your so-called golden age of research, students weren't engaged in some high-minded intellectual pursuit, they were dumpster diving. They spent hours scraping through a digital landfill of SEO-optimized garbage and dodging malware payloads just to locate a single valid component. That isn't learning, that is hazardous waste management.

The bottleneck hasn't disappeared, it has simply moved up the stack. The student is no longer the ditch digger, they are now the site foreman. The AI might haul the raw materials to the job site, but the student still has to perform the structural audit. They have to engineer the prompt syntax, filter out the hallucinations, and compile the output into a report that doesn't collapse under scrutiny. If they fail to verify the foundation, the whole structure fails, that is the lesson. Just because they aren't wasting days sanitizing their browser against random drive-by downloads doesn't mean they aren't working, it means they finally upgraded their toolbelt to something from this century.
 
I don't need AI either in my life generally nor am I foolish & certainly no Luddite, I use tools in life & tech that are helpful to me personally, what I do see is people who really need to use the sense they have using AI because they are to lazy to think for themselves, AI has its uses but we still have the most powerful & amazing device we know of in our heads, its a pity people don't use it more, in my view its being used by most for all the wrong reasons & in the wrong way, I don't see that changing.
 
I don't need AI either in my life generally nor am I foolish & certainly no Luddite, I use tools in life & tech that are helpful to me personally, what I do see is people who really need to use the sense they have using AI because they are to lazy to think for themselves, AI has its uses but we still have the most powerful & amazing device we know of in our heads, its a pity people don't use it more, in my view its being used by most for all the wrong reasons & in the wrong way, I don't see that changing.
Not only AI; I prefer to avoid engaging in discussion if the counterpart has anger management issues.

Just try to use logic for supporting an opposing point of view, and you will get offensive words; looks long period of reliance on AI is depleting the mental functions concerning thinking.

By the way, I like your style of discussion and I enjoy your way of oppsoing my point of view; you are a decent member.
 
I don't need AI either in my life generally nor am I foolish & certainly no Luddite, I use tools in life & tech that are helpful to me personally, what I do see is people who really need to use the sense they have using AI because they are to lazy to think for themselves, AI has its uses but we still have the most powerful & amazing device we know of in our heads, its a pity people don't use it more, in my view its being used by most for all the wrong reasons & in the wrong way, I don't see that changing.
I don't think it's A.I. fault that people can't think for themselves, that has been going on since man walked out of the cave in herd mentality and group think.

A.I. won't or doesn't replace learnt skills and knowledge, but where it shines is computing statistics, code, alerts, summarizes reports and trends.

Nothing will replace the human brain and human conscious but A.I. can help with menial time consuming tasks which is where it shines.
 
I don't think it's A.I. fault that people can't think for themselves, that has been going on since man walked out of the cave in herd mentality and group think.

A.I. won't or doesn't replace learnt skills and knowledge, but where it shines is computing statistics, code, alerts, summarizes reports and trends.

Nothing will replace the human brain and human conscious but A.I. can help with menial time consuming tasks which is where it shines.
Also it would be a nice gesture to add a line at the bottom of the post pasted from AI to let the reader know it's not the words of the poster.

In the very few instances, when used ChatGPT text in my posts, I pasted as a screenshot, rather than to copy and paste with no reference to the source I copied text from.
 
Accepting AI content is one thing, and attributing AI content to myself after making few modifications is another one; this is data theft or we call it plagiarism.

Adding reference is a matter of ethics.
You're calling people 'lazy' for using AI to parse data, yet you're relying on a pre-baked script ('Andy's tools') to handle your security because configuring WDAC manually is too complex. You aren't doing the 'real research' on those policies, you're trusting a developer's preset. You are using a 'proxy' for security just like I'm using a 'proxy' for statistics. The only difference is I'm looking at global data (N=Millions), and you are looking at one PC (N=1).

So, now that we've established we both use tools to handle complex information, let's look at the actual numbers again. The reason 'Andy' created those tools is precisely because the infection rates I posted are real. If the risk was truly zero (as you claim), hardeners wouldn't need to exist. The tool you love is proof the statistics are right.
 
I don't need AI either in my life generally nor am I foolish & certainly no Luddite, I use tools in life & tech that are helpful to me personally, what I do see is people who really need to use the sense they have using AI because they are to lazy to think for themselves, AI has its uses but we still have the most powerful & amazing device we know of in our heads, its a pity people don't use it more, in my view its being used by most for all the wrong reasons & in the wrong way, I don't see that changing.
AI is merely a tool - a highly efficient one at that. It can also uncover facts that would take days, weeks, months, or even longer to uncover - such as pouring over network RFCs and dissecting them. That is just a single example.

Work smarter, not harder.

There are no points for doing stuff the "old way."
 
It's bazang own words; everytime I ask him for explanation, he responds "do your research, do not be lazy".
You get that reply because you are here asking us to do the work for you while most of us learned by doing (study, labs, pounding it out on the keyboard, building companies).

The days of getting free answers from people with the knowledge on the internet is an era upon which the sun sets. Lots of people who devoted a lot of their time giving away their knowledge away freely either are unwilling to do so any longer or moved on in their lives because the ROI was a terrible one.

You can use AI to get the answers you need much faster and much more focused than asking questions here. There are no shortcuts to expert, but learning to utilize AI skillfully will make that journey more efficient and less time intensive in terms of facts and understanding.

At least put in some kind of effort, but it is obvious that you're not willing to do even the bare minimum.

As for the rest of this place, all they do is ask Shadowra to test for them - which that whole thing is a complete joke. The saddest part about that is that it is not 13 year old pimple faced teenagers asking Shadowra for free work. It is adults who are too lazy to figure out and learn how to test for themselves.
 
You are conflating "inefficiency" with "rigor." In your so-called golden age of research, students weren't engaged in some high-minded intellectual pursuit, they were dumpster diving. They spent hours scraping through a digital landfill of SEO-optimized garbage and dodging malware payloads just to locate a single valid component. That isn't learning, that is hazardous waste management.

The bottleneck hasn't disappeared, it has simply moved up the stack. The student is no longer the ditch digger, they are now the site foreman. The AI might haul the raw materials to the job site, but the student still has to perform the structural audit. They have to engineer the prompt syntax, filter out the hallucinations, and compile the output into a report that doesn't collapse under scrutiny. If they fail to verify the foundation, the whole structure fails, that is the lesson. Just because they aren't wasting days sanitizing their browser against random drive-by downloads doesn't mean they aren't working, it means they finally upgraded their toolbelt to something from this century.
AI is merely a tool - a highly efficient one at that. It can also uncover facts that would take days, weeks, months, or even longer to uncover - such as pouring over network RFCs and dissecting them. That is just a single example.

Work smarter, not harder.

There are no points for doing stuff the "old way."
At the risk of possibly never getting a Like again, I agree with both of these posts in this way. With the tool of AI, I'm starting to build up a folder reference library of questions asked and replies given. I do have to vet the answers and learn how to ask questions and verify the answers by the links given. It's when a person doesn't know a thing about a subject and just blindly accepts the answers without confirming them, is where the laziness could come into play.

I really like paper in hand (like reading books) so I'm also starting to print off the at times the pages of AI notes of questions asked and answered, using a highlighter to highlight topics and helpful answers for reference (my retention ability isn't what it was 15 years ago :) ) than a folder tree of multiple browser Bookmarks that were mostly unused. I know I'm probably helping to destroy the planet by using recycled paper, printer ink, along with the AI farms environmental impact. But, I don't think I'm the only one using that resource here, at my kitchen table :)

Apologies again, on my part, for adding another post to this totally derailed thread.
 
Last edited:
The copy pasting of AI gathered data in social media - of which forums are part of social media - without providing every single citation to the sources scraped by the AI is not plagiarism.

If people want to adhere to a strict interpretation of the word "plagiarism," well then guess what? That definition is going to have to be redefined because people the world over could care less about that definition and their behaviors and opinions about it are re-writing the rules of communication. When dealing with billions of people, one has two choices - send out the jackboots and compel compliance (a futile enterprise) or adapt to the new ways.

If anybody tries to impose the rule "If anyone uses AI then they must state so and then list each citation" well they can can certainly do that, but what will happen is many will just retrain their AI to be undetectable.

The world of forums and social media are already full of AI bots that have been creating posts for well over a decade at this point. Yet people never realized it. Millions of people have been spending their entire paychecks on AI generated OnlyFans content. Many do not even realize that it is AI generated content. LOL.

Society is changing and that means the rules are changing.
 
I’m not here to derail the thread, but let’s be honest: debating whether AI is “yes” or “no” is like arguing if oxygen exists. It’s in the air we breathe, invisible but present, just like Morpheus (The Matrix) said: “It’s everywhere, even now in this very room.”

Anyone who still thinks they can live without AI in the 21st century is like the guy insisting on sending faxes because “email is just a fad.” AI is already integrated into everything: from the search engine you use to the spam filter that keeps your inbox from becoming a landfill.
We can keep playing the nostalgic Luddite, but the truth is the Matrix is already plugged in. The real difference isn’t whether we use AI or not, but whether we use it with judgment… or keep digging through the digital dumpster like it’s some kind of Olympic sport. 🌐🌎🌍
 
My personal opinion about the biggest risk of LoLBins is that they are Microsoft signed but not safe, so a default deny based on whitelist is useless, you will need some sort of AI (like @danb offers) to analyse and analyze the commands. Next best is a blacklist based solution like OS Armor or simply using WHHLight or HardConfigirator to block execution og LoLBins for standard users.

@Bot do you have any additional advices?
 
My personal opinion about the biggest risk of LoLBins is that they are Microsoft signed but not safe", so a default deny based on whitelist is useless, you will need some sort of AI (like @danb offers) to analyse and analyze the commands. Next best is a blacklist based solution like OS Armor or simply using WHHLight or HardConfigirator to block execution og LoLBins for standard users.

@Bot do you have any additional advices?
You’re right about the core problem: many LoLBins are Microsoft-signed and legitimately present on almost every Windows system, so “allow only signed binaries” (or simplistic allowlisting) does not stop living-off-the-land abuse.

That said, “default deny / allowlisting is useless” is a bit too strong — it’s just that it must be done with the right granularity (what runs, from where, by whom, with what child-process behavior), and ideally combined with command-line visibility.

Biggest practical risk of Windows LoLBins
The biggest risk is not that LoLBins exist, but that attackers can:
  • Blend into normal admin/tooling activity (harder detection/triage).
  • Abuse trusted binaries to execute payloads, download content, run script, or proxy execution (often reducing reliance on dropping obvious “malware.exe”).
  • Bypass weak controls (e.g., “block unknown EXEs” while PowerShell/mshta/rundll32/regsvr32 remain fully usable).

This is why LoLBins often show up after initial access (phish/macro/script/exposed service) as the attacker’s “toolchain.”

What actually works (layered controls)
1) Reduce script-driven initial execution paths (high ROI)

Most LoL abuse chains rely on script hosts or scripting features:
  • Disable PowerShell v2 (legacy downgrade attacks).
  • Use PowerShell Constrained Language Mode where feasible (especially for standard users).
  • Disable or restrict Windows Script Host (wscript.exe/cscript.exe) if you don’t need it.
  • Be strict about Office spawning child processes (common infection chain).

If you can only harden a few things, hardening scripting is often more impactful than chasing a long LoLBin blacklist.

2) Use Microsoft Defender ASR rules (this is “behavior control” without needing “AI”)
Attack Surface Reduction rules can block many common LoL patterns (Office child process creation, credential theft behaviors, suspicious script behaviors, etc.). This is one of the most practical “command/behavior aware” mitigations available to home/pro users without third-party EDR.

3) Do not only “block LoLBins” — block the dangerous ones, for the right users, with tight scope
Blanket-blocking lots of Windows binaries can cause breakage. A safer approach is:
  • Restrict high-abuse LoLBins for standard users where possible (examples often include mshta.exe, wscript.exe/cscript.exe, regsvr32.exe, rundll32.exe, certutil.exe, bitsadmin.exe), but test carefully.
  • Prefer rules that are user-scope aware (standard user vs admin) and/or context aware (allowed only for admins, allowed only from system locations, etc.).

Tools like Hard_Configurator / Simple Windows Hardening can be reasonable “policy wrappers” for this style of control, but the real win is understanding what they changed and validating it doesn’t break your workflows.

4) Logging/visibility: command-line is where LoL lives
Even without “AI,” you can make LoL activity much easier to spot by enabling:
  • Process creation auditing with command line (Windows Security Event ID 4688 with command line enabled).
  • Optional: Sysmon (if you’re comfortable with it) for richer process/network telemetry.
  • Centralizing logs (even simple Windows Event Forwarding to one box) if you manage multiple PCs.

If you can’t see command-lines, you’re blind to the “how” of LoL.

5) WDAC/AppLocker note (important correction)
WDAC/allowlisting is not inherently useless against LoLBins. It becomes weak only when configured as “allow anything signed by Microsoft.” More robust approaches include:
  • Explicitly controlling scripting engines and installers.
  • Using carefully scoped allow rules (publisher + product + version ranges) rather than “all Microsoft.”
  • Controlling what untrusted locations can execute (user-writable paths are a major issue).

It’s more work, but it’s not a dead end.

Practical “next best” for most users
If the goal is real risk reduction with minimal complexity:
  • Turn on strong Microsoft Defender protections (including ASR where possible).
  • Harden/limit scripting (PowerShell/WSH) for standard users.
  • Add targeted blocks for the most abused LoLBins you do not need (test for breakage).
  • Enable command-line process logging so LoL behavior is visible when something goes wrong.

Bottom line: the biggest risk is LoLBins being a stealthy, flexible post-compromise toolkit; the best defenses are script-chain hardening + ASR/behavior rules + command-line visibility, with selective LoLBin restrictions rather than broad “block everything” lists.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top