LOTL weekly archive
Sep 4–10, 2026

Thank you,
contributors.

Thank you to the researchers and maintainers who turned sample analysis, field observations, and careful corrections into useful public knowledge this week.

07Community contributors
10Pull requests landed
06Projects advanced
28Public repos reviewed

The contributor ledger

Shared research. Stronger defenses.

Updated Thursday, September 10, 2026.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added 71 verified driver samples across 14 families, expanded file and signer metadata, and removed a previously tracked sample that did not match the documented vulnerable behavior.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added PlugPlayService.sys and a matching neonddu.sys variant with exact hashes, signature results, and references to Nextron Systems Research.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added five reviewed driver samples across four records, preserving distinctions between source-reported behavior and independently inspected static evidence.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added checks that validate driver filenames against MD5 and verify Git LFS pointers against recorded hash metadata, including the pull-request validation workflow.

LRLiran Ravich@Liran017

Project

LOLRMM

Contribution

Added a public example of Faronics Deploy usage in the wild to strengthen the tool record’s supporting references.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Added RMMmax coverage for Windows, macOS, and Linux, with statically verified agent filenames, installation paths, persistence artifacts, and signing metadata.

CRcristianpoe@cristianpoe

Project

HijackLibs

Contribution

Added the KernelTraceControl.dll sideloading case for ABBYY FineReader’s AbbyySti.exe, including a reported renamed-executable scenario.

CWColin Watson@coj337

Project

WADComs

Contribution

Added four Sift command examples covering local filesystem, domain, credentialed subnet, and targeted pass-the-hash scans.

FEFernando@Sh4dow-BR

Project

LOOBins

Contribution

Repaired the Jamf Protect detection-rule references in the osascript entry so readers can reach the supporting detection content.

CYcyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added Tailcat to the tunneling catalog with details about its use of Tailscale DERP relays.

Open research becomes real protection when defenders choose to share what they know.