Thank you,
contributors.
Thank you to the researchers and maintainers who turned careful testing, field observations, and cleanup into public defensive knowledge this week.
The contributor ledger
Another week of shared defense.
Updated Friday, September 4, 2026.
| Contributor | Project | Contribution | Source |
|---|---|---|---|
ICivancabrera02@ivancabrera02 | LOLBAS | Added dotnet-trace.exe and dotnet-counters.exe, documenting child-process execution behavior available through the .NET diagnostic tools. | PR #522 |
HGHarry Godridge@InfoSecHarry | HijackLibs | Added the maxkernl.dll sideloading case for Nuance PaperPort PPScanMg.exe, including the observed renamed executable scenario. | PR #191 |
DKDaniel Koifman@Koifman | HijackLibs | Added QnWallpaper.exe and QnwPlayer.exe as libcef.dll sideloading cases, with hashes tied to published ValleyRAT research. | PR #192 |
DKDaniel Koifman@Koifman | HijackLibs | Added MpDefenderCoreService.exe as another Windows Defender mpclient.dll sideloading case, linked to SilkParasite reporting. | PR #193 |
WBWietze Beukema@wietze | HijackLibs | Strengthened HijackLibs quality-control checks for project data and schema consistency. | Commit |
WBWietze Beukema@wietze | HijackLibs | Added direct SilkParasite-related HijackLibs updates and followed with a correction to the Calibre launcher entry. | Commit |
JHJose Enrique Hernandez@josehelps | LOLRMM | Corrected reported installation-path typos in RMM tool records. | PR #232 |
CLclivoa@clivoa | LOLRMM | Anchored generated Sigma process-name matches to Windows path separators, deduplicated values, and added regression coverage for the generator. | PR #237 |
MHMichael Haag@MHaggis | LOLRMM | Added OpsBridge Agent with verified Windows paths, persistence artifacts, service and registry indicators, network details, hashes, and signer metadata. | PR #243 |
MHMichael Haag@MHaggis | LOLRMM | Added SetMe PRO and refreshed Adobe Connect and Chrome Remote Desktop records with current artifacts, signing details, paths, and platform coverage. | PR #244 |
E2Element2023H@Element2023H | LOLDrivers | Added zntport.sys, documenting its caller-controlled physical-memory mapping path and related unchecked copy behavior. | PR #404 |
JHJose Enrique Hernandez@josehelps | LOLDrivers | Added Alinubx.sys and DCRCVDrv.sys, documenting two signed drivers used as process killers by the Cruciferra MaaS loader. | PR #413 |
MHMichael Haag@MHaggis | LOLDrivers | Added newly disclosed and in-the-wild driver research, including xhunter variants, Tjbxld kernel utilities, Sxav, and ardrv.sys, with updated YARA coverage where applicable. | PR #414 |
MHMichael Haag@MHaggis | LOLDrivers | Added 14 non-duplicate OPSWAT AppRemover ardrv variants to the CVE-2026-36425 family and preserved the original contributor credit. | PR #415 |
MHMichael Haag@MHaggis | LOLDrivers | Added four verified driver samples covering a reflective kernel loader, HP hardware-access primitives, SpeedFan giveio.sys, and PCIScope kernel-memory access. | PR #416 |
MHMichael Haag@MHaggis | LOLDrivers | Completed the DirectIo64.sys PerformanceTest 11.1 b1008 record with the exact sample, signature and PE metadata, and documented privileged hardware-access primitives. | PR #417 |
MHMichael Haag@MHaggis | LOLDrivers | Corrected the NeacSafe64.sys research attribution to the original NeacController work and credited the CVE-2025-45737 researcher. | PR #419 |
MHMichael Haag@MHaggis | LOLDrivers | Added 72 verified driver samples across 32 records, including ten previously unrepresented driver families and additional affected-version, signer, hash, and behavior evidence. | PR #420 |
Project
LOLBASContribution
Added dotnet-trace.exe and dotnet-counters.exe, documenting child-process execution behavior available through the .NET diagnostic tools.
Project
HijackLibsContribution
Added the maxkernl.dll sideloading case for Nuance PaperPort PPScanMg.exe, including the observed renamed executable scenario.
Project
HijackLibsContribution
Added QnWallpaper.exe and QnwPlayer.exe as libcef.dll sideloading cases, with hashes tied to published ValleyRAT research.
Project
HijackLibsContribution
Added MpDefenderCoreService.exe as another Windows Defender mpclient.dll sideloading case, linked to SilkParasite reporting.
Project
HijackLibsContribution
Strengthened HijackLibs quality-control checks for project data and schema consistency.
Project
HijackLibsContribution
Added direct SilkParasite-related HijackLibs updates and followed with a correction to the Calibre launcher entry.
Project
LOLRMMContribution
Corrected reported installation-path typos in RMM tool records.
Project
LOLRMMContribution
Anchored generated Sigma process-name matches to Windows path separators, deduplicated values, and added regression coverage for the generator.
Project
LOLRMMContribution
Added OpsBridge Agent with verified Windows paths, persistence artifacts, service and registry indicators, network details, hashes, and signer metadata.
Project
LOLRMMContribution
Added SetMe PRO and refreshed Adobe Connect and Chrome Remote Desktop records with current artifacts, signing details, paths, and platform coverage.
Project
LOLDriversContribution
Added zntport.sys, documenting its caller-controlled physical-memory mapping path and related unchecked copy behavior.
Project
LOLDriversContribution
Added Alinubx.sys and DCRCVDrv.sys, documenting two signed drivers used as process killers by the Cruciferra MaaS loader.
Project
LOLDriversContribution
Added newly disclosed and in-the-wild driver research, including xhunter variants, Tjbxld kernel utilities, Sxav, and ardrv.sys, with updated YARA coverage where applicable.
Project
LOLDriversContribution
Added 14 non-duplicate OPSWAT AppRemover ardrv variants to the CVE-2026-36425 family and preserved the original contributor credit.
Project
LOLDriversContribution
Added four verified driver samples covering a reflective kernel loader, HP hardware-access primitives, SpeedFan giveio.sys, and PCIScope kernel-memory access.
Project
LOLDriversContribution
Completed the DirectIo64.sys PerformanceTest 11.1 b1008 record with the exact sample, signature and PE metadata, and documented privileged hardware-access primitives.
Project
LOLDriversContribution
Corrected the NeacSafe64.sys research attribution to the original NeacController work and credited the CVE-2025-45737 researcher.
Project
LOLDriversContribution
Added 72 verified driver samples across 32 records, including ten previously unrepresented driver families and additional affected-version, signer, hash, and behavior evidence.
Open research becomes real protection when defenders choose to share what they know.