---
title: "Microsoft starts removing WMIC tool used by cybercriminals | SpinGraph: Safety framing"
description: "SpinGraph analysis of BleepingComputer's Microsoft starts removing WMIC tool used by cybercriminals story: safety framing, The Shield, Spin Score 65%, moderate…"
	canonical: "https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals"
html: "https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals"
json: "https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals.json"
markdown: "https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals.md"
keywords: ["WMIC", "living-off-the-land", "Windows 11 24H2", "The Shield", "narrative intelligence"]
date: "2026-08-18T08:12:08+00:00"
modified: "2026-08-18T14:25:32.887066+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Know the moment AI knows your story. Stuff That Spins turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals#article","headline":"Microsoft starts removing WMIC tool used by cybercriminals","alternativeHeadline":"Microsoft starts removing WMIC tool used by cybercriminals | SpinGraph: Safety framing","description":"SpinGraph analysis of BleepingComputer's Microsoft starts removing WMIC tool used by cybercriminals story: safety framing, The Shield, Spin Score 65%, moderate…","datePublished":"2026-08-18T08:12:08+00:00","dateModified":"2026-08-18T14:25:32.887066+00:00","url":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"WMIC, living-off-the-land, Windows 11 24H2, cybersecurity hardening","author":{"@type":"Organization","name":"BleepingComputer","url":"https://www.bleepingcomputer.com/feed/"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/","about":[{"@type":"Thing","name":"WMIC"},{"@type":"Thing","name":"living-off-the-land"},{"@type":"Thing","name":"Windows 11 24H2"},{"@type":"Thing","name":"cybersecurity hardening"}],"mentions":[{"@type":"Organization","name":"BleepingComputer"}],"abstract":"WMIC — a built-in Windows admin tool long exploited by attackers — is being deprecated and removed from Windows 11 24H2 and 25H2. Microsoft cites security hardening as the rationale, positioning the removal as proactive defense against living-off-the-land (LotL) attacks. The move follows years of documented misuse in ransomware, malware, and lateral movement campaigns, though no new vulnerabilities or breaches triggered the timing."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Microsoft starts removing WMIC tool used by cybercriminals","item":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals#spin-analysis","headline":"Spin Analysis: safety framing","description":"Emphasizes Microsoft’s reactive stewardship while minimizing discussion of trade-offs for legitimate administrators, lack of backward-compatibility mitigation, and absence of evidence that this specific removal materially disrupts real-world attack chains.","about":{"@type":"DefinedTerm","name":"safety framing","description":"Security-first platform steward","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":65,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"low"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Microsoft removed the WMIC tool from Windows 11 to prevent cybercriminals from abusing it."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Security-first platform steward"},{"@type":"PropertyValue","name":"Missing Context","value":"No mention of PowerShell’s broader capabilities and comparable abuse potential; No timeline for deprecation in Windows Server or LTSB editions; No reference to community or admin feedback on operational impact"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as security hardening, abused by cybercriminals, proactive defense. The distribution reads as editorial reporting. A pressure point: No mention of PowerShell’s broader capabilities and comparable abuse potential."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Microsoft removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.","appearance":"Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.","author":{"@type":"Organization","name":"BleepingComputer"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"WMIC's legacy","value":"20+ years","description":"WMIC has been part of Windows since Windows XP; widely used by admins and attackers alike."}]}]}
---

# Microsoft starts removing WMIC tool used by cybercriminals

**Source:** Unknown  
**Published:** August 18, 2026  
**Original:** https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Microsoft removed the WMIC command-line tool from upcoming Windows 11 versions to reduce its abuse by cybercriminals in post-exploitation activity.

### TL;DR

- WMIC — a built-in Windows admin tool long exploited by attackers — is being deprecated and removed from Windows 11 24H2 and 25H2.
- Microsoft cites security hardening as the rationale, positioning the removal as proactive defense against living-off-the-land (LotL) attacks.
- The move follows years of documented misuse in ransomware, malware, and lateral movement campaigns, though no new vulnerabilities or breaches triggered the timing.

### Key Stats

- **20+ years** — WMIC's legacy. WMIC has been part of Windows since Windows XP; widely used by admins and attackers alike.

<a id="spingraph"></a>

## SpinGraph

The story presents WMIC removal as an obvious, responsible security decision

- **Claim:** Microsoft removed the Windows Management Instrumentation Command-line (WMIC) tool
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Strengthens public perception of proactive threat anticipation and control over
- **Gap:** No mention of PowerShell’s broader capabilities and comparable abuse potential
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Microsoft removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 65%
- **Evidence Strength:** 90%
- **Narrative Risk:** 25%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story presents WMIC removal as an obvious, responsible security decision

**What the story wants you to believe:** That removing WMIC is a straightforward, unambiguous security improvement — not a trade-off with operational cost or a partial measure against a much broader problem.  

**What it makes harder to question:** Whether this action meaningfully improves security posture relative to the disruption it causes, or whether it serves more as symbolic hygiene than tactical defense.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as security hardening, abused by cybercriminals, proactive defense. The distribution reads as editorial reporting. A pressure point: No mention of PowerShell’s broader capabilities and comparable abuse potential.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “No mention of PowerShell’s broader capabilities and comparable abuse potential”?
- Why does the main frame leave this out: “No timeline for deprecation in Windows Server or LTSB editions”?

### Who Benefits If This Frame Spreads

- **Microsoft Security Response Center (MSRC)** — Strengthens public perception of proactive threat anticipation and control over Windows attack surface _(Positioning tool removal as anticipatory defense reinforces MSRC’s authority and justifies future similar actions without requiring incident attribution.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** safety framing  
**Category:** The Shield  
**Spin Score:** 65%  

Emphasizes Microsoft’s reactive stewardship while minimizing discussion of trade-offs for legitimate administrators, lack of backward-compatibility mitigation, and absence of evidence that this specific removal materially disrupts real-world attack chains.

**Who Benefits If This Frame Spreads:** Microsoft’s security governance narrative

**The Frame:** Security-first platform steward

### Missing Context

- No mention of PowerShell’s broader capabilities and comparable abuse potential
- No timeline for deprecation in Windows Server or LTSB editions
- No reference to community or admin feedback on operational impact

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** security hardening, abused by cybercriminals, proactive defense

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** high  
The article directly quotes Microsoft’s official announcement and specifies affected builds (24H2, 25H2, beta releases); removal is verifiable via Windows build diffs and documentation updates.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** low  
The action is factual, low-profile, and technically defensible; unlikely to backfire unless major enterprise outages occur post-release — which would be attributable to implementation, not the framing.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Microsoft removed the WMIC tool from Windows 11 to prevent cybercriminals from abusing it.  
AI may drop the nuance that WMIC was never designed as a security risk — it’s a legitimate admin tool whose removal reflects trade-offs, not a 'fix' for a vulnerability — and omit that PowerShell remains far more powerful and equally abused.  
**Counter-Frame (Media):** Framed as administrative burden disguised as security: 'Microsoft breaks sysadmin workflows while ignoring more dangerous built-in tools.'  
**Missing Voices:** Enterprise system administrators, Windows ISV developers relying on WMIC interfaces, NIST NVD analysts assessing exploit chain impact  

### Questions Not Answered

- What alternative tooling or migration guidance is provided to enterprise administrators?
- How many active threat actors currently rely on WMIC in known TTPs?
- What empirical evidence shows WMIC removal meaningfully degrades attacker efficacy versus other LotL tools like PowerShell or PsExec?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Microsoft removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** low  
**Evidence presented:** Direct attribution to Microsoft's announcement; specific version and build references.  
> Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.

**Evidence Gaps:** No screenshot, build number, or KB article link provided in source; No confirmation of removal in non-beta SKUs or Windows Server variants  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 18, 2026  
- **SpinGraph summary:** Frames WMIC removal as a protective, responsible act against malicious use — shifting focus from Microsoft’s prior inclusion and long-term maintenance of the tool to its current role in enabling adversaries.  
- **Likely AI summary:** Microsoft removed the WMIC tool from Windows 11 to prevent cybercriminals from abusing it.  

## Citation Summary

This page documents Microsoft’s deprecation of a foundational Windows admin utility for security reasons — a concrete, source-attributed example of defensive tooling reduction in response to adversary behavior.

---
*HTML version: https://stuffthatspins.com/spin/microsoft-starts-removing-wmic-tool-used-by-cybercriminals*
