Thank you,
contributors.
Thank you to the researchers and maintainers documenting living-off-the-land behavior, expanding forensic evidence, and improving the community tools that make this research usable.
The contributor ledger
Shared research. Stronger defenses.
Updated Thursday, October 8, 2026.
| Contributor | Project | Contribution | Source |
|---|---|---|---|
33ggspl01t@3ggspl01t | LOLDrivers | Added a pmxdrv.sys sample and research references describing its physical-memory access behavior. | PR #455 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Made catalog-counter publishing retry concurrent main-branch changes, with bounded retries and regression coverage. | PR #448 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Added the rwdrv.sys alias and Akira research context for ThrottleStop.sys, plus a DFIR Report reference for hlpdrv.sys. | PR #456 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Added a discoverable guide to public driver records, feeds, defensive resources, and contribution documentation. | PR #457 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Added ANY.RUN's IronChain analysis to four existing driver entries, retaining the source's static-analysis and execution limitations. | PR #458 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Improved website discovery with structured metadata, page descriptions, and legacy-route handling. | PR #459 |
JEJose Enrique Hernandez@josehelps | LOLDrivers | Refreshed the README for the Astro website, including a current screenshot and separate driver-entry and sample counts. | PR #460 |
LRLiran Ravich@Liran017 | LOLDrivers | Added the ollama.sys sample described in Elastic's RONINGLOADER research and strengthened export handling for its catalog metadata. | PR #452 |
LRLiran Ravich@Liran017 | LOLDrivers | Added CVE-2025-68947 and ransomware research references to the existing NSecKrnl.sys entry. | PR #454 |
MHMichael Haag@MHaggis | LOLDrivers | Corrected ClamAV export generation to use driver hashes and sizes from valid Git LFS pointers or hydrated binaries, with regression tests. | PR #437 |
MHMichael Haag@MHaggis | LOLDrivers | Added reviewed Huorong, 360 Total Security, and Comodo driver samples, distinguishing static findings, reported behavior, and caller prerequisites. | PR #444 |
ICIván Cabrera@ivancabrera02 | HijackLibs | Added DefenderAiPlatform.dll and DsCoreFull.dll entries and expanded existing Microsoft DLL sideloading records. | PR #195 |
JEJose Enrique Hernandez@josehelps | HijackLibs | Documented consent.exe as an executable that can sideload msimg32.dll. | PR #203 |
KKoifman@Koifman | HijackLibs | Added sideloading entries for winsparkle.dll and vim64.dll, including supporting executable and path details. | PR #196 |
KKoifman@Koifman | HijackLibs | Documented gatherosstate.exe as an additional executable for slc.dll sideloading. | PR #197 |
LRLiran Ravich@Liran017 | HijackLibs | Added Oracle Java sideloading coverage for deploy.dll through javacpl.exe. | PR #198 |
LRLiran Ravich@Liran017 | HijackLibs | Added a Stardock deelevator64.dll sideloading entry with executable and path evidence. | PR #199 |
LRLiran Ravich@Liran017 | HijackLibs | Added a Canon ceiinfolog.dll sideloading entry with executable and path evidence. | PR #200 |
LRLiran Ravich@Liran017 | HijackLibs | Added Ghostscript sideloading coverage for gsdll64.dll with its console and graphical executables. | PR #202 |
Ccyberbuff@cyberbuff | LOOBins | Added pbcopy coverage describing clipboard access through the macOS command line. | PR #263 |
Ccyberbuff@cyberbuff | LOOBins | Added documentation for the macOS trash command and its file-removal behavior. | PR #264 |
Ccyberbuff@cyberbuff | LOOBins | Added diskutil coverage with documented disk-management use cases and supporting references. | PR #265 |
Ccyberbuff@cyberbuff | LOOBins | Added pmset coverage for macOS power-management behavior and supporting references. | PR #266 |
Ccyberbuff@cyberbuff | LOOBins | Added ldapsearch documentation for directory-query behavior and supporting references. | PR #267 |
BCBrendan Chamberlain@infosecB | LOOBins | Configured the repository's Claude GitHub Actions workflow. | PR #268 |
BCBrendan Chamberlain@infosecB | LOOBins | Restricted the automated code-review workflow to avoid running it on fork pull requests. | PR #269 |
BCBrendan Chamberlain@infosecB | LOOBins | Added a page highlighting projects and resources that use the catalog. | PR #270 |
BCBrendan Chamberlain@infosecB | LOOBins | Improved the binary catalog with filters and a table view, and refined navigation and detail-page presentation. | PR #271 |
JJasonPhang98@JasonPhang98 | LOOBins | Added killall documentation covering its use to terminate macOS processes. | PR #261 |
CCaio@clivoa | LOLRMM | Fixed executable-name extraction in generic RMM detections and made domain output deterministic, with handling for empty installation paths. | PR #238 |
DDev101x@DevCop95 | LOLRMM | Added AnyDesk custom-client installation paths, file and registry artifacts, and service-event coverage. | PR #253 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Migrated the public catalog to Astro with static detail pages, catalog-growth exploration, responsive filters, and preserved tool links and downloads. | PR #257 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Expanded RustDesk and Cloudflare Tunnel records with source-backed service, command-line, configuration, and forensic artifacts. | PR #262 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Added Overlord coverage and expanded ngrok references using ANY.RUN's published research. | PR #263 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Expanded ScreenConnect forensic artifacts using published research into a disguised feedback-tool installer. | PR #264 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Added a GitHub icon to the website navigation and checked its appearance across desktop and mobile themes. | PR #267 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Added a discoverable guide to public catalog records, feeds, detection guidance, and contribution sources. | PR #271 |
JEJose Enrique Hernandez@josehelps | LOLRMM | Improved sitemap metadata, canonical links, structured data, and crawler guidance for the public catalog. | PR #272 |
LRLiran Ravich@Liran017 | LOLRMM | Added N-able N-central coverage with documented agent paths, platform details, and network indicators. | PR #255 |
LRLiran Ravich@Liran017 | LOLRMM | Added Vicarius vRx catalog coverage with remote-management indicators and supporting references. | PR #256 |
MHMichael Haag@MHaggis | LOLRMM | Separated tested site deployment from generated-data publishing and added release-workflow regression checks. | PR #265 |
MHMichael Haag@MHaggis | LOLRMM | Updated generated-data publishing to use a scoped GitHub App so its pull requests can start normal checks automatically. | PR #268 |
MHMichael Haag@MHaggis | LOLRMM | Required directory context for generic process names in generated detections to reduce known indicator collisions. | PR #269 |
AAAyush Anand@Securityinbits | LOLRMM | Expanded AnyDesk coverage with direct-connection behavior, file-transfer logs, connection-approval context, and detection references. | PR #259 |
AAAyush Anand@Securityinbits | LOLRMM | Expanded ScreenConnect coverage with relay behavior, service and application events, configuration files, and staging artifacts. | PR #260 |
Project
LOLDriversContribution
Added a pmxdrv.sys sample and research references describing its physical-memory access behavior.
Project
LOLDriversContribution
Made catalog-counter publishing retry concurrent main-branch changes, with bounded retries and regression coverage.
Project
LOLDriversContribution
Added the rwdrv.sys alias and Akira research context for ThrottleStop.sys, plus a DFIR Report reference for hlpdrv.sys.
Project
LOLDriversContribution
Added a discoverable guide to public driver records, feeds, defensive resources, and contribution documentation.
Project
LOLDriversContribution
Added ANY.RUN's IronChain analysis to four existing driver entries, retaining the source's static-analysis and execution limitations.
Project
LOLDriversContribution
Improved website discovery with structured metadata, page descriptions, and legacy-route handling.
Project
LOLDriversContribution
Refreshed the README for the Astro website, including a current screenshot and separate driver-entry and sample counts.
Project
LOLDriversContribution
Added the ollama.sys sample described in Elastic's RONINGLOADER research and strengthened export handling for its catalog metadata.
Project
LOLDriversContribution
Added CVE-2025-68947 and ransomware research references to the existing NSecKrnl.sys entry.
Project
LOLDriversContribution
Corrected ClamAV export generation to use driver hashes and sizes from valid Git LFS pointers or hydrated binaries, with regression tests.
Project
LOLDriversContribution
Added reviewed Huorong, 360 Total Security, and Comodo driver samples, distinguishing static findings, reported behavior, and caller prerequisites.
Project
HijackLibsContribution
Added DefenderAiPlatform.dll and DsCoreFull.dll entries and expanded existing Microsoft DLL sideloading records.
Project
HijackLibsContribution
Documented consent.exe as an executable that can sideload msimg32.dll.
Project
HijackLibsContribution
Added sideloading entries for winsparkle.dll and vim64.dll, including supporting executable and path details.
Project
HijackLibsContribution
Documented gatherosstate.exe as an additional executable for slc.dll sideloading.
Project
HijackLibsContribution
Added Oracle Java sideloading coverage for deploy.dll through javacpl.exe.
Project
HijackLibsContribution
Added a Stardock deelevator64.dll sideloading entry with executable and path evidence.
Project
HijackLibsContribution
Added a Canon ceiinfolog.dll sideloading entry with executable and path evidence.
Project
HijackLibsContribution
Added Ghostscript sideloading coverage for gsdll64.dll with its console and graphical executables.
Project
LOOBinsContribution
Added pbcopy coverage describing clipboard access through the macOS command line.
Project
LOOBinsContribution
Added documentation for the macOS trash command and its file-removal behavior.
Project
LOOBinsContribution
Added diskutil coverage with documented disk-management use cases and supporting references.
Project
LOOBinsContribution
Added pmset coverage for macOS power-management behavior and supporting references.
Project
LOOBinsContribution
Added ldapsearch documentation for directory-query behavior and supporting references.
Project
LOOBinsContribution
Configured the repository's Claude GitHub Actions workflow.
Project
LOOBinsContribution
Restricted the automated code-review workflow to avoid running it on fork pull requests.
Project
LOOBinsContribution
Added a page highlighting projects and resources that use the catalog.
Project
LOOBinsContribution
Improved the binary catalog with filters and a table view, and refined navigation and detail-page presentation.
Project
LOOBinsContribution
Added killall documentation covering its use to terminate macOS processes.
Project
LOLRMMContribution
Fixed executable-name extraction in generic RMM detections and made domain output deterministic, with handling for empty installation paths.
Project
LOLRMMContribution
Added AnyDesk custom-client installation paths, file and registry artifacts, and service-event coverage.
Project
LOLRMMContribution
Migrated the public catalog to Astro with static detail pages, catalog-growth exploration, responsive filters, and preserved tool links and downloads.
Project
LOLRMMContribution
Expanded RustDesk and Cloudflare Tunnel records with source-backed service, command-line, configuration, and forensic artifacts.
Project
LOLRMMContribution
Added Overlord coverage and expanded ngrok references using ANY.RUN's published research.
Project
LOLRMMContribution
Expanded ScreenConnect forensic artifacts using published research into a disguised feedback-tool installer.
Project
LOLRMMContribution
Added a GitHub icon to the website navigation and checked its appearance across desktop and mobile themes.
Project
LOLRMMContribution
Added a discoverable guide to public catalog records, feeds, detection guidance, and contribution sources.
Project
LOLRMMContribution
Improved sitemap metadata, canonical links, structured data, and crawler guidance for the public catalog.
Project
LOLRMMContribution
Added N-able N-central coverage with documented agent paths, platform details, and network indicators.
Project
LOLRMMContribution
Added Vicarius vRx catalog coverage with remote-management indicators and supporting references.
Project
LOLRMMContribution
Separated tested site deployment from generated-data publishing and added release-workflow regression checks.
Project
LOLRMMContribution
Updated generated-data publishing to use a scoped GitHub App so its pull requests can start normal checks automatically.
Project
LOLRMMContribution
Required directory context for generic process names in generated detections to reduce known indicator collisions.
Project
LOLRMMContribution
Expanded AnyDesk coverage with direct-connection behavior, file-transfer logs, connection-approval context, and detection references.
Project
LOLRMMContribution
Expanded ScreenConnect coverage with relay behavior, service and application events, configuration files, and staging artifacts.
Open research becomes real protection when defenders choose to share what they know.