LOTL weekly archive
Aug 28–Sep 4, 2026

Thank you,
contributors.

Thank you to the researchers and maintainers who turned careful testing, field observations, and cleanup into public defensive knowledge this week.

08Community contributors
16Pull requests landed
04Projects advanced
27Public repos reviewed

The contributor ledger

Another week of shared defense.

Updated Friday, September 4, 2026.

ICivancabrera02@ivancabrera02

Project

LOLBAS

Contribution

Added dotnet-trace.exe and dotnet-counters.exe, documenting child-process execution behavior available through the .NET diagnostic tools.

HGHarry Godridge@InfoSecHarry

Project

HijackLibs

Contribution

Added the maxkernl.dll sideloading case for Nuance PaperPort PPScanMg.exe, including the observed renamed executable scenario.

DKDaniel Koifman@Koifman

Project

HijackLibs

Contribution

Added QnWallpaper.exe and QnwPlayer.exe as libcef.dll sideloading cases, with hashes tied to published ValleyRAT research.

DKDaniel Koifman@Koifman

Project

HijackLibs

Contribution

Added MpDefenderCoreService.exe as another Windows Defender mpclient.dll sideloading case, linked to SilkParasite reporting.

WBWietze Beukema@wietze

Project

HijackLibs

Contribution

Strengthened HijackLibs quality-control checks for project data and schema consistency.

WBWietze Beukema@wietze

Project

HijackLibs

Contribution

Added direct SilkParasite-related HijackLibs updates and followed with a correction to the Calibre launcher entry.

JHJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Corrected reported installation-path typos in RMM tool records.

CLclivoa@clivoa

Project

LOLRMM

Contribution

Anchored generated Sigma process-name matches to Windows path separators, deduplicated values, and added regression coverage for the generator.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added OpsBridge Agent with verified Windows paths, persistence artifacts, service and registry indicators, network details, hashes, and signer metadata.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added SetMe PRO and refreshed Adobe Connect and Chrome Remote Desktop records with current artifacts, signing details, paths, and platform coverage.

E2Element2023H@Element2023H

Project

LOLDrivers

Contribution

Added zntport.sys, documenting its caller-controlled physical-memory mapping path and related unchecked copy behavior.

JHJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added Alinubx.sys and DCRCVDrv.sys, documenting two signed drivers used as process killers by the Cruciferra MaaS loader.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added newly disclosed and in-the-wild driver research, including xhunter variants, Tjbxld kernel utilities, Sxav, and ardrv.sys, with updated YARA coverage where applicable.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added 14 non-duplicate OPSWAT AppRemover ardrv variants to the CVE-2026-36425 family and preserved the original contributor credit.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added four verified driver samples covering a reflective kernel loader, HP hardware-access primitives, SpeedFan giveio.sys, and PCIScope kernel-memory access.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Completed the DirectIo64.sys PerformanceTest 11.1 b1008 record with the exact sample, signature and PE metadata, and documented privileged hardware-access primitives.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Corrected the NeacSafe64.sys research attribution to the original NeacController work and credited the CVE-2025-45737 researcher.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added 72 verified driver samples across 32 records, including ten previously unrepresented driver families and additional affected-version, signer, hash, and behavior evidence.

Open research becomes real protection when defenders choose to share what they know.