logo

Rainy Day Windows Command Research Results

ID: 13ca9739-1726-5fdb-9e9f-b0ed1f8a8ef9

STIX ID: report--13ca9739-1726-5fdb-9e9f-b0ed1f8a8ef9

Feed Name: Black Hills Infosec Blog

Date Published: 2019-11-13

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive summary:** This blog post highlights various built-in Windows command-line tools and demonstrates how they can be leveraged by red teams or attackers for tasks such as encoding/decoding payloads, transferring or archiving files, enumerating accounts and services, and interacting with WSL; it emphasizes that these "living off the land" utilities can be abused and suggests monitoring their use for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.