Less malware is being used in the biggest, most sophisticated attacks. Instead, malicious intruders are using legitimate tools built into operating systems to do their dirty work. Legitimate tools, including remote management tools and scripting engines, are harder to detect than single-purpose malware. Antivirus software is close to useless for detecting brand-new malware on day two, but it does well in detecting common attack tools. Anomalyous activity is any activity outside of your normal range or expectation, says author.”]
Source: https://www.csoonline.com/article/2983975/catch-attackers-even-when-they-dont-use-malware.html

