Thank you,
contributors.
Thank you to the researchers and maintainers expanding the evidence defenders can use, documenting more tools, and making community catalogs easier to explore.
The contributor ledger
Shared research. Stronger defenses.
Updated Thursday, September 24, 2026.
| Contributor | Project | Contribution | Source |
|---|---|---|---|
RCRobel Campbell@x0rb3l | LOLDrivers | Added FortiClient driver coverage with the submitted sample, process-termination research, affected-release information, and upgrade guidance. | PR #427 |
SShiroko@ShirokoLEET | LOLDrivers | Added a verified driver sample and documentation for a process-termination interface lacking caller and target authorization checks. | PR #428 |
MHMichael Haag@MHaggis | LOLDrivers | Added SakDriver rootkit coverage and refined two Cruciferra driver records with sample-specific behavior, limitations, and research attribution. | PR #431 |
MHMichael Haag@MHaggis | LOLDrivers | Added five reviewed MiniTool, Prevx, AMD, Panda, and Malwarebytes driver samples with extracted metadata, source references, and scoped behavior descriptions. | PR #436 |
Jjacky@lzty | LOLDrivers | Added BIOSTAR driver coverage and a verified sample documenting physical-memory read and write operations, with access requirements kept explicit. | PR #445 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Improved catalog charts, recent-driver navigation, copy controls, and social previews, with keyboard and reduced-motion support. | PR #447 |
MHMichael Haag@MHaggis | LOLDrivers | Added Antiy ATool driver metadata and a verified sample, documenting a trusted-client validation weakness and its process-termination limits. | PR #446 |
MHMichael Haag@MHaggis | LOLRMM | Added Lavawall product coverage, signed-agent artifacts, network and persistence details, and scoped detection indicators. | PR #248 |
MHMichael Haag@MHaggis | LOLRMM | Added Zecurit artifacts across Windows, macOS, and Linux, and corrected Windows file-rule generation to respect platform scope. | PR #249 |
MHMichael Haag@MHaggis | LOLRMM | Added RG System coverage with verified Windows agent artifacts and qualified Linux and macOS information, preserving the delivery report’s limits. | PR #250 |
MHMichael Haag@MHaggis | LOLRMM | Added LightRmmAgent, RemoteAgentAgent, and RMMCRAT entries from published research, and corrected Level network and certificate evidence. | PR #252 |
MHMichael Haag@MHaggis | LOLRMM | Added 12 remote-management entries and PixoIT-branded Breeze coverage, distinguishing supported artifacts, platform gaps, and uncertain publisher context. | PR #251 |
Ccyberbuff@cyberbuff | LOT Tunnels | Added ZeroTier overlay-network coverage with client/service artifacts, network indicators, and research references. | PR #29 |
Ccyberbuff@cyberbuff | LOT Tunnels | Added Pydantic validation for changed binary entries in pull requests and corrected schema and YAML inconsistencies. | PR #30 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented wstunnel traffic tunneling with client/server examples, command-line indicators, and research references. | PR #28 |
Ccyberbuff@cyberbuff | LOT Tunnels | Added Twingate remote-access coverage with client/connector artifacts, service domains, and research references. | PR #27 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented Shootback reverse TCP tunneling, its Python components, and command-line indicators. | PR #26 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented Portmap.io port forwarding over OpenVPN, with configuration and domain indicators. | PR #25 |
Ccyberbuff@cyberbuff | LOT Tunnels | Added Packetriot tunneling coverage with client commands, service domains, and references for defenders. | PR #24 |
Ccyberbuff@cyberbuff | LOT Tunnels | Added NetBird overlay-network coverage, including enrollment commands, service domains, and research references. | PR #23 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented GOST proxying and chained tunnels, with command-line indicators and research references. | PR #22 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented frp reverse-proxy use, client/server artifacts, configuration indicators, and supporting research. | PR #21 |
Ccyberbuff@cyberbuff | LOT Tunnels | Documented Chisel tunneling, reverse forwarding, command-line indicators, and supporting research. | PR #20 |
KSKamran Saifullah@deFr0ggy | LOT Tunnels | Added a CSV export template for binary names, descriptions, supported operating systems, and source websites. | Commit 4d6d586 |
KSKamran Saifullah@deFr0ggy | LOT Tunnels | Added a domain CSV export linked from the homepage and a searchable domain-reference page. | Commit 64f0f0c |
KSKamran Saifullah@deFr0ggy | LOT Tunnels | Reworked contributor credits into cards with profile links, avatars, contribution totals, and contribution-history links. | Commit b923d11 |
KSKamran Saifullah@deFr0ggy | LOT Tunnels | Improved contributor-list initialization and GitHub API error handling while preserving paginated results. | Commit ec192bf |
KSKamran Saifullah@deFr0ggy | LOT Tunnels | Adjusted contributor cards and responsive grid widths for desktop, tablet, and narrow screens. | Commit 7082577 |
Project
LOLDriversContribution
Added FortiClient driver coverage with the submitted sample, process-termination research, affected-release information, and upgrade guidance.
Project
LOLDriversContribution
Added a verified driver sample and documentation for a process-termination interface lacking caller and target authorization checks.
Project
LOLDriversContribution
Added SakDriver rootkit coverage and refined two Cruciferra driver records with sample-specific behavior, limitations, and research attribution.
Project
LOLDriversContribution
Added five reviewed MiniTool, Prevx, AMD, Panda, and Malwarebytes driver samples with extracted metadata, source references, and scoped behavior descriptions.
Project
LOLDriversContribution
Added BIOSTAR driver coverage and a verified sample documenting physical-memory read and write operations, with access requirements kept explicit.
Project
LOLDriversContribution
Improved catalog charts, recent-driver navigation, copy controls, and social previews, with keyboard and reduced-motion support.
Project
LOLDriversContribution
Added Antiy ATool driver metadata and a verified sample, documenting a trusted-client validation weakness and its process-termination limits.
Project
LOLRMMContribution
Added Lavawall product coverage, signed-agent artifacts, network and persistence details, and scoped detection indicators.
Project
LOLRMMContribution
Added Zecurit artifacts across Windows, macOS, and Linux, and corrected Windows file-rule generation to respect platform scope.
Project
LOLRMMContribution
Added RG System coverage with verified Windows agent artifacts and qualified Linux and macOS information, preserving the delivery report’s limits.
Project
LOLRMMContribution
Added LightRmmAgent, RemoteAgentAgent, and RMMCRAT entries from published research, and corrected Level network and certificate evidence.
Project
LOLRMMContribution
Added 12 remote-management entries and PixoIT-branded Breeze coverage, distinguishing supported artifacts, platform gaps, and uncertain publisher context.
Project
LOT TunnelsContribution
Added ZeroTier overlay-network coverage with client/service artifacts, network indicators, and research references.
Project
LOT TunnelsContribution
Added Pydantic validation for changed binary entries in pull requests and corrected schema and YAML inconsistencies.
Project
LOT TunnelsContribution
Documented wstunnel traffic tunneling with client/server examples, command-line indicators, and research references.
Project
LOT TunnelsContribution
Added Twingate remote-access coverage with client/connector artifacts, service domains, and research references.
Project
LOT TunnelsContribution
Documented Shootback reverse TCP tunneling, its Python components, and command-line indicators.
Project
LOT TunnelsContribution
Documented Portmap.io port forwarding over OpenVPN, with configuration and domain indicators.
Project
LOT TunnelsContribution
Added Packetriot tunneling coverage with client commands, service domains, and references for defenders.
Project
LOT TunnelsContribution
Added NetBird overlay-network coverage, including enrollment commands, service domains, and research references.
Project
LOT TunnelsContribution
Documented GOST proxying and chained tunnels, with command-line indicators and research references.
Project
LOT TunnelsContribution
Documented frp reverse-proxy use, client/server artifacts, configuration indicators, and supporting research.
Project
LOT TunnelsContribution
Documented Chisel tunneling, reverse forwarding, command-line indicators, and supporting research.
Project
LOT TunnelsContribution
Added a CSV export template for binary names, descriptions, supported operating systems, and source websites.
Project
LOT TunnelsContribution
Added a domain CSV export linked from the homepage and a searchable domain-reference page.
Project
LOT TunnelsContribution
Reworked contributor credits into cards with profile links, avatars, contribution totals, and contribution-history links.
Project
LOT TunnelsContribution
Improved contributor-list initialization and GitHub API error handling while preserving paginated results.
Project
LOT TunnelsContribution
Adjusted contributor cards and responsive grid widths for desktop, tablet, and narrow screens.
Open research becomes real protection when defenders choose to share what they know.