Most small businesses have antivirus software installed and assume that covers them. It is an understandable assumption, but the threats businesses face today have moved well beyond what traditional antivirus was built to handle.
14,846
High-severity EDR alerts across managed client networks
375
Security incidents flagged over six months
>90%
Of attacks use tools the operating system already trusts
Frontline-managed network data collected from December 2025 through June 2026.
Over the past six months, Frontline’s security monitoring flagged more than 14,000 high-severity alerts across client networks. In the majority of those cases, nothing new was installed on the affected machines.
The attackers used legitimate tools that were already there, which is exactly the kind of activity traditional antivirus is not designed to catch.
What Antivirus Was Built to Do
Antivirus software works by comparing files against a database of known malware. Each known threat has a unique signature, and the antivirus checks new files against those signatures. If there is a match, the file gets blocked. If there is not, the software generally assumes the file is safe.
That model worked reasonably well for two decades. Attackers wrote malware, security researchers identified it, databases were updated, and businesses that kept their antivirus current were protected against most known threats.
That changed when attackers realized they could use software already installed on a machine to carry out an attack without introducing a file that antivirus would recognize as a threat.
The Threat Your Antivirus Cannot See
Modern attackers increasingly rely on what security professionals call “living off the land”: using legitimate software already installed on a computer to carry out attacks. PowerShell, Windows’ built-in scripting engine, is one of the most common examples.
From Our Live Data
PowerShell-related alerts are among the most frequent signals across Frontline client environments, with more than 620 connection and rule-violation alerts recorded in the past 180 days.
These events are not automatically blocked by antivirus because PowerShell is not malware. It is a legitimate Windows tool doing what it was designed to do.
Attackers use PowerShell to download additional malicious code, move through networks, and disable security controls, all while appearing to be normal system activity. The same pattern applies to Windows Task Scheduler, network-scanning utilities, and standard command-line tools included with Windows.
Because these tools are also used by system administrators every day, distinguishing malicious activity from legitimate administration is not straightforward, even in environments with strong cyber hygiene.
Because these tools can be abused without immediately triggering security alerts, it’s important to recognize common signs of a cyberattack and take proactive steps to identify suspicious activity early.
What DNS Tunneling Looks Like From Inside Your Network
One of the more striking patterns in Frontline’s recent data involves browser-based DNS anomalies: standard web browsers generating unusual volumes of DNS traffic that may indicate data exfiltration or communication with an attacker’s server.
Highest-volume alert category
Browser-based DNS anomalies were the most common signal in Frontline’s EDR data. Firefox alone generated more than 11,366 flagged DNS alerts across client environments during a six-month period.
This is another type of activity that traditional antivirus is unlikely to catch. The browser is carrying the attacker’s traffic, so there may be no malicious file for antivirus to scan. Identifying the threat requires monitoring patterns of behavior, including unusual destinations, connection frequency, and data volume.
The Gap EDR Fills
Endpoint Detection and Response, or EDR, approaches security differently. Instead of matching files against a list of known threats, EDR watches what processes actually do.
EDR examines questions such as:
- Is this PowerShell script making an unusual outbound connection?
- Is a scheduled task being created at an unusual time?
- Is a process creating scheduled tasks when it normally should not?
- Is a browser generating a volume of DNS requests that does not match normal user activity?
When behavior looks suspicious, EDR flags it regardless of whether the tool involved appears on a malware list.
The difference matters in practice. Ransomware often begins by using legitimate Windows tools before any malware is written to disk. EDR monitors the activity leading up to an attack, while traditional antivirus may have nothing to scan.
Reconnaissance, where attackers map a network and gather information before acting, frequently relies on the same legitimate administrative tools. Persistence, the method attackers use to retain access after a restart, may involve changes to scheduled tasks, startup entries, and registry keys that EDR monitors continuously.
The key distinction
Antivirus checks the bag. EDR watches the behavior. If an attacker uses your own tools against you, antivirus may have nothing to check. EDR watches what those tools actually do.
Why This Matters for Small Businesses
There is a persistent belief that sophisticated attacks target only large corporations and that small businesses are not worth the effort. The data does not support that assumption. Around 70% of cyberattacks now target small and midsized businesses, largely because many are not adequately prepared.
Automated attack toolkits make it easy to scan for and exploit vulnerabilities at scale. A business with 15 employees can face the same attack patterns as one with 1,500. The difference is that larger organizations have had the budget and staff to move beyond antivirus for years.
This exposure does not start and end with endpoint software. A properly configured business firewall and cybersecurity strategy provide an important first layer of defense, while properly configured network infrastructure and segmentation can limit how far an attacker moves if access is gained.
What This Means for Your Business
If antivirus is your primary form of endpoint protection, it is worth understanding its limitations. Many modern attacks do not rely on identifiable malware, which means traditional antivirus may never flag anything suspicious.
That does not make antivirus obsolete. It means antivirus is no longer sufficient on its own. Adding a firewall protection for your small business provides another critical layer of protection by filtering malicious network traffic before it reaches your devices.
In addition, EDR adds visibility into system activity that signature-based detection cannot provide. When it is supported by continuous cybersecurity monitoring, suspicious behavior can be investigated before it develops into a larger incident.
For many small businesses, that means working with a managed IT services provider that runs EDR across the environment and has a team available to investigate what it surfaces.
For businesses that are unsure where those responsibilities differ, the distinction between IT support and cybersecurity services is often more significant than expected.
See What’s Running on Your Network Right Now
A 30-minute conversation is enough to understand your current exposure and identify the biggest security and performance gaps across your network.

