LOTL weekly archive
Oct 1–8, 2026

Thank you,
contributors.

Thank you to the researchers and maintainers documenting living-off-the-land behavior, expanding forensic evidence, and improving the community tools that make this research usable.

12Community contributors
45Pull requests landed
04Projects advanced
34Public repos reviewed

The contributor ledger

Shared research. Stronger defenses.

Updated Thursday, October 8, 2026.

33ggspl01t@3ggspl01t

Project

LOLDrivers

Contribution

Added a pmxdrv.sys sample and research references describing its physical-memory access behavior.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Made catalog-counter publishing retry concurrent main-branch changes, with bounded retries and regression coverage.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added the rwdrv.sys alias and Akira research context for ThrottleStop.sys, plus a DFIR Report reference for hlpdrv.sys.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added a discoverable guide to public driver records, feeds, defensive resources, and contribution documentation.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Added ANY.RUN's IronChain analysis to four existing driver entries, retaining the source's static-analysis and execution limitations.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Improved website discovery with structured metadata, page descriptions, and legacy-route handling.

JEJose Enrique Hernandez@josehelps

Project

LOLDrivers

Contribution

Refreshed the README for the Astro website, including a current screenshot and separate driver-entry and sample counts.

LRLiran Ravich@Liran017

Project

LOLDrivers

Contribution

Added the ollama.sys sample described in Elastic's RONINGLOADER research and strengthened export handling for its catalog metadata.

LRLiran Ravich@Liran017

Project

LOLDrivers

Contribution

Added CVE-2025-68947 and ransomware research references to the existing NSecKrnl.sys entry.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Corrected ClamAV export generation to use driver hashes and sizes from valid Git LFS pointers or hydrated binaries, with regression tests.

MHMichael Haag@MHaggis

Project

LOLDrivers

Contribution

Added reviewed Huorong, 360 Total Security, and Comodo driver samples, distinguishing static findings, reported behavior, and caller prerequisites.

ICIván Cabrera@ivancabrera02

Project

HijackLibs

Contribution

Added DefenderAiPlatform.dll and DsCoreFull.dll entries and expanded existing Microsoft DLL sideloading records.

JEJose Enrique Hernandez@josehelps

Project

HijackLibs

Contribution

Documented consent.exe as an executable that can sideload msimg32.dll.

KKoifman@Koifman

Project

HijackLibs

Contribution

Added sideloading entries for winsparkle.dll and vim64.dll, including supporting executable and path details.

KKoifman@Koifman

Project

HijackLibs

Contribution

Documented gatherosstate.exe as an additional executable for slc.dll sideloading.

LRLiran Ravich@Liran017

Project

HijackLibs

Contribution

Added Oracle Java sideloading coverage for deploy.dll through javacpl.exe.

LRLiran Ravich@Liran017

Project

HijackLibs

Contribution

Added a Stardock deelevator64.dll sideloading entry with executable and path evidence.

LRLiran Ravich@Liran017

Project

HijackLibs

Contribution

Added a Canon ceiinfolog.dll sideloading entry with executable and path evidence.

LRLiran Ravich@Liran017

Project

HijackLibs

Contribution

Added Ghostscript sideloading coverage for gsdll64.dll with its console and graphical executables.

Ccyberbuff@cyberbuff

Project

LOOBins

Contribution

Added pbcopy coverage describing clipboard access through the macOS command line.

Ccyberbuff@cyberbuff

Project

LOOBins

Contribution

Added documentation for the macOS trash command and its file-removal behavior.

Ccyberbuff@cyberbuff

Project

LOOBins

Contribution

Added diskutil coverage with documented disk-management use cases and supporting references.

Ccyberbuff@cyberbuff

Project

LOOBins

Contribution

Added pmset coverage for macOS power-management behavior and supporting references.

Ccyberbuff@cyberbuff

Project

LOOBins

Contribution

Added ldapsearch documentation for directory-query behavior and supporting references.

BCBrendan Chamberlain@infosecB

Project

LOOBins

Contribution

Configured the repository's Claude GitHub Actions workflow.

BCBrendan Chamberlain@infosecB

Project

LOOBins

Contribution

Restricted the automated code-review workflow to avoid running it on fork pull requests.

BCBrendan Chamberlain@infosecB

Project

LOOBins

Contribution

Added a page highlighting projects and resources that use the catalog.

BCBrendan Chamberlain@infosecB

Project

LOOBins

Contribution

Improved the binary catalog with filters and a table view, and refined navigation and detail-page presentation.

JJasonPhang98@JasonPhang98

Project

LOOBins

Contribution

Added killall documentation covering its use to terminate macOS processes.

CCaio@clivoa

Project

LOLRMM

Contribution

Fixed executable-name extraction in generic RMM detections and made domain output deterministic, with handling for empty installation paths.

DDev101x@DevCop95

Project

LOLRMM

Contribution

Added AnyDesk custom-client installation paths, file and registry artifacts, and service-event coverage.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Migrated the public catalog to Astro with static detail pages, catalog-growth exploration, responsive filters, and preserved tool links and downloads.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Expanded RustDesk and Cloudflare Tunnel records with source-backed service, command-line, configuration, and forensic artifacts.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Added Overlord coverage and expanded ngrok references using ANY.RUN's published research.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Expanded ScreenConnect forensic artifacts using published research into a disguised feedback-tool installer.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Added a GitHub icon to the website navigation and checked its appearance across desktop and mobile themes.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Added a discoverable guide to public catalog records, feeds, detection guidance, and contribution sources.

JEJose Enrique Hernandez@josehelps

Project

LOLRMM

Contribution

Improved sitemap metadata, canonical links, structured data, and crawler guidance for the public catalog.

LRLiran Ravich@Liran017

Project

LOLRMM

Contribution

Added N-able N-central coverage with documented agent paths, platform details, and network indicators.

LRLiran Ravich@Liran017

Project

LOLRMM

Contribution

Added Vicarius vRx catalog coverage with remote-management indicators and supporting references.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Separated tested site deployment from generated-data publishing and added release-workflow regression checks.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Updated generated-data publishing to use a scoped GitHub App so its pull requests can start normal checks automatically.

MHMichael Haag@MHaggis

Project

LOLRMM

Contribution

Required directory context for generic process names in generated detections to reduce known indicator collisions.

AAAyush Anand@Securityinbits

Project

LOLRMM

Contribution

Expanded AnyDesk coverage with direct-connection behavior, file-transfer logs, connection-approval context, and detection references.

AAAyush Anand@Securityinbits

Project

LOLRMM

Contribution

Expanded ScreenConnect coverage with relay behavior, service and application events, configuration files, and staging artifacts.

Open research becomes real protection when defenders choose to share what they know.