Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Mitigating Advanced Malware Attacks with Least Privilege current page
Link copied

Mitigating Advanced Malware Attacks with Least Privilege

Oct 20, 2017
Author:
Mark Austin
Blog banner default
Mitigating Advanced Malware Attacks with Least Privilege
Mark Austin

Targeted malware attacks and Advanced Persistent Threats (APTs) are making malware detection and removal much more challenging. It is common knowledge that good security requires a defense-in-depth strategy, as no single solution can provide adequate protection from malware. Traditional approaches to malware detection should still be kept in place, to ensure that known threats and applications that exhibit malicious characteristics are quarantined at the earliest possible stage, but these need to be complimented by more advanced methods and best practices to deal with the ever changing threat landscape.

One of the biggest steps that can be taken to mitigate malware threats is to implement a least privilege approach. The most dangerous and persistent threats often look to bury themselves deep inside the operating system, using root-kits and other kernel level techniques. Once malware operates at this level it can cloak itself from security solutions, making subsequent detection and removal extremely difficult.

In order for malware to infect the kernel it must run in a privileged context or gain access to a privileged account, such as a local administrator or SYSTEM account. If a user logs on with a local administrator account then malware can gain access to a privileged context with ease, whereas if a user logs on with a standard user account it becomes much more difficult for the malware to gain privileged access to the system. It's no surprise that over 90% of Microsoft's critical vulnerabilities state that users who log on to systems with fewer privileges will be less impacted.

So if least privilege is such a good way to mitigate malware threats then why do so many users still log on with local administrator accounts?

The answer is the age-old problem of getting the right balance between security and usability. The more a system is locked down the more secure it becomes, but usability starts to suffer. Taking this to the extreme, if you were to remove the Internet connection and disallow removal storage devices then an endpoint would become extremely secure, but it would become unusable in the interconnected world we live in today. The removal of local administrator rights from a user may not seem quite so extreme, but many users will simply struggle to perform their role or at best will be faced with frequent over-the-shoulder administration, leading to frustration and a loss of productivity.

A privilege management solution is required to strike the balance between the two extremes of standard user and local administrator rights. Instead of assigning privileges to a user's account, the necessary privileges are assigned directly to the applications that actually require them, based on centrally managed policies. This approach ensures that malware will find it extremely difficult to gain access to a privileged account, because all users log on with standard user accounts. More over only the applications that require elevated privileges are granted them, which significantly reduces the application attack surface.

In addition to increasing the risk of malware infection, users who log on with local administrator accounts will significantly reduce the effectiveness of many security solutions, as they are more likely to be compromised, although few vendors will point this out.

Embracing least privilege will not only increase the security posture of the endpoint, it will also lead to reduced desktop operating costs, as under-locked or over-locked desktops are more costly to support. So now you have two very good reasons to implement least privilege - reduced malware threats and reduced operating costs. Improved security doesn't have to come at a price - with a well managed least privilege solution you can save money and improve user satisfaction too!

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • How Secure Are These Digital Assistants Anyway?
    Dec 27, 2016 How Secure Are These Digital Assistants Anyway?
    Blog
    1m
  • XOXO in Cybersecurity Is Binary and so Is Paying Taxes
    Mar 20, 2018 XOXO in Cybersecurity Is Binary and so Is Paying Taxes
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.