LOTL weekly archive
Sep 17–24, 2026

Thank you,
contributors.

Thank you to the researchers and maintainers expanding the evidence defenders can use, documenting more tools, and making community catalogs easier to explore.

07Community contributors
23Pull requests landed
03Projects advanced
35Public repos reviewed

The contributor ledger

Shared research. Stronger defenses.

Updated Thursday, September 24, 2026.

RCRobel Campbell@x0rb3l

Project

LOLDrivers

Contribution

Added FortiClient driver coverage with the submitted sample, process-termination research, affected-release information, and upgrade guidance.

SShiroko@ShirokoLEET

Project

LOLDrivers

Contribution

Added a verified driver sample and documentation for a process-termination interface lacking caller and target authorization checks.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added SakDriver rootkit coverage and refined two Cruciferra driver records with sample-specific behavior, limitations, and research attribution.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added five reviewed MiniTool, Prevx, AMD, Panda, and Malwarebytes driver samples with extracted metadata, source references, and scoped behavior descriptions.

Jjacky@lzty

Project

LOLDrivers

Contribution

Added BIOSTAR driver coverage and a verified sample documenting physical-memory read and write operations, with access requirements kept explicit.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Improved catalog charts, recent-driver navigation, copy controls, and social previews, with keyboard and reduced-motion support.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added Antiy ATool driver metadata and a verified sample, documenting a trusted-client validation weakness and its process-termination limits.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added Lavawall product coverage, signed-agent artifacts, network and persistence details, and scoped detection indicators.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added Zecurit artifacts across Windows, macOS, and Linux, and corrected Windows file-rule generation to respect platform scope.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added RG System coverage with verified Windows agent artifacts and qualified Linux and macOS information, preserving the delivery report’s limits.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added LightRmmAgent, RemoteAgentAgent, and RMMCRAT entries from published research, and corrected Level network and certificate evidence.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Added 12 remote-management entries and PixoIT-branded Breeze coverage, distinguishing supported artifacts, platform gaps, and uncertain publisher context.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added ZeroTier overlay-network coverage with client/service artifacts, network indicators, and research references.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added Pydantic validation for changed binary entries in pull requests and corrected schema and YAML inconsistencies.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented wstunnel traffic tunneling with client/server examples, command-line indicators, and research references.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added Twingate remote-access coverage with client/connector artifacts, service domains, and research references.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented Shootback reverse TCP tunneling, its Python components, and command-line indicators.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented Portmap.io port forwarding over OpenVPN, with configuration and domain indicators.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added Packetriot tunneling coverage with client commands, service domains, and references for defenders.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Added NetBird overlay-network coverage, including enrollment commands, service domains, and research references.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented GOST proxying and chained tunnels, with command-line indicators and research references.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented frp reverse-proxy use, client/server artifacts, configuration indicators, and supporting research.

Ccyberbuff@cyberbuff

Project

LOT Tunnels

Contribution

Documented Chisel tunneling, reverse forwarding, command-line indicators, and supporting research.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Added a CSV export template for binary names, descriptions, supported operating systems, and source websites.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Added a domain CSV export linked from the homepage and a searchable domain-reference page.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Reworked contributor credits into cards with profile links, avatars, contribution totals, and contribution-history links.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Improved contributor-list initialization and GitHub API error handling while preserving paginated results.

KSKamran Saifullah@deFr0ggy

Project

LOT Tunnels

Contribution

Adjusted contributor cards and responsive grid widths for desktop, tablet, and narrow screens.

Open research becomes real protection when defenders choose to share what they know.