Thank you,
contributors.
Thank you to the researchers and maintainers who turned sample analysis, field observations, and careful corrections into useful public knowledge this week.
The contributor ledger
Shared research. Stronger defenses.
Updated Thursday, September 10, 2026.
| Contributor | Project | Contribution | Source |
|---|---|---|---|
MHMichael Haag@MHaggis | LOLDrivers | Added 71 verified driver samples across 14 families, expanded file and signer metadata, and removed a previously tracked sample that did not match the documented vulnerable behavior. | PR #421 |
MHMichael Haag@MHaggis | LOLDrivers | Added PlugPlayService.sys and a matching neonddu.sys variant with exact hashes, signature results, and references to Nextron Systems Research. | PR #423 |
MHMichael Haag@MHaggis | LOLDrivers | Added five reviewed driver samples across four records, preserving distinctions between source-reported behavior and independently inspected static evidence. | PR #424 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Added checks that validate driver filenames against MD5 and verify Git LFS pointers against recorded hash metadata, including the pull-request validation workflow. | PR #425 |
LRLiran Ravich@Liran017 | LOLRMM | Added a public example of Faronics Deploy usage in the wild to strengthen the tool record’s supporting references. | PR #245 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Added RMMmax coverage for Windows, macOS, and Linux, with statically verified agent filenames, installation paths, persistence artifacts, and signing metadata. | PR #246 |
CRcristianpoe@cristianpoe | HijackLibs | Added the KernelTraceControl.dll sideloading case for ABBYY FineReader’s AbbyySti.exe, including a reported renamed-executable scenario. | PR #194 |
CWColin Watson@coj337 | WADComs | Added four Sift command examples covering local filesystem, domain, credentialed subnet, and targeted pass-the-hash scans. | PR #60 |
FEFernando@Sh4dow-BR | LOOBins | Repaired the Jamf Protect detection-rule references in the osascript entry so readers can reach the supporting detection content. | PR #262 |
CYcyberbuff@cyberbuff | LOT Tunnels | Added Tailcat to the tunneling catalog with details about its use of Tailscale DERP relays. | PR #18 |
Project
LOLDriversContribution
Added 71 verified driver samples across 14 families, expanded file and signer metadata, and removed a previously tracked sample that did not match the documented vulnerable behavior.
Project
LOLDriversContribution
Added PlugPlayService.sys and a matching neonddu.sys variant with exact hashes, signature results, and references to Nextron Systems Research.
Project
LOLDriversContribution
Added five reviewed driver samples across four records, preserving distinctions between source-reported behavior and independently inspected static evidence.
Project
LOLDriversContribution
Added checks that validate driver filenames against MD5 and verify Git LFS pointers against recorded hash metadata, including the pull-request validation workflow.
Project
LOLRMMContribution
Added a public example of Faronics Deploy usage in the wild to strengthen the tool record’s supporting references.
Project
LOLRMMContribution
Added RMMmax coverage for Windows, macOS, and Linux, with statically verified agent filenames, installation paths, persistence artifacts, and signing metadata.
Project
HijackLibsContribution
Added the KernelTraceControl.dll sideloading case for ABBYY FineReader’s AbbyySti.exe, including a reported renamed-executable scenario.
Project
WADComsContribution
Added four Sift command examples covering local filesystem, domain, credentialed subnet, and targeted pass-the-hash scans.
Project
LOOBinsContribution
Repaired the Jamf Protect detection-rule references in the osascript entry so readers can reach the supporting detection content.
Project
LOT TunnelsContribution
Added Tailcat to the tunneling catalog with details about its use of Tailscale DERP relays.
Open research becomes real protection when defenders choose to share what they know.