LOTL weekly archive
Aug 21–28, 2026

Thank you,
contributors.

You turned research into shared defense—and made the industry a little safer this week. Here’s to the people improving the Living Off the Land projects defenders rely on.

08Community contributors
08Pull requests landed
05Projects advanced
27Public repos reviewed

The contributor ledger

Research that moved defense forward.

Updated Friday, August 28, 2026.

MMMario Madersbacher@mmadersbacher

Project

LOLBAS

Contribution

Added Vssadmin.exe, documenting shadow-copy deletion and T1490 recovery inhibition.

NSnasawyer7@nasawyer7

Project

LOLBAS

Contribution

Added AppLaunch.exe for ClickOnce execution and application-control and SmartScreen bypass.

KOKoifman@Koifman

Project

HijackLibs

Contribution

Added the OneDrive wtsapi32.dll sideloading case associated with C2Looper.

FFFaraday / Austin@0xFFaraday

Project

HijackLibs

Contribution

Added Macrium Reflect reflecttheme.dll sideloading observed with a fake Teams installer.

CJChrisJr404@ChrisJr404

Project

LOLRMM

Contribution

Added BreezeRMM, including agent filenames, installation paths, and vendor domains for detection.

JHJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Fixed deployment, Sigma generation, and badge workflows by regenerating against current main.

JHJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added Alinubx.sys and DCRCVDrv.sys, documenting two Cruciferra MaaS BYOVD process-killer drivers.

JTJeffrey Tigchelaar@jeffreytigch

Project

LOT Tunnels

Contribution

Added SSH-J, Gsocket, Qsocket, and Tailscale tunnel or service entries with their associated domains.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Made four direct follow-up commits correcting categories and metadata for the new tunnel entries.

Open research becomes real protection when defenders choose to share what they know.