Community Projects

Built by Defenders,for Defenders

Created by former threat researchers and security analysts, cited by CISA and Microsoft in security guidance on abused admin tools and vulnerable drivers.

We believe intelligence should be free. Our open-source projects are actively developed so teams can adopt and detect immediately. When the community levels up together, the entire industry benefits.

Our goal is to eliminate entire threat vectors where possible and remove tools from attackers. #ThisEndsWithUs. We welcome contributions and feedback, join the community on GitHub.

See how this research powers our product on the threat intelligence page.

Adopted by teams hardening high-risk, bandwidth-constrained endpoints
Open Source

The Projects the IndustryRelies On

Open-source intelligence projects referenced by CISA, Microsoft, and security teams worldwide. The research DNA behind every MagicSword policy.

LOLDrivers logo

LOLDrivers

Living Off The Land Drivers is a curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks. The project helps security professionals stay informed and mitigate potential threats.

1,900+VULNERABLE DRIVERS TRACKED
Visit
Sigconverter logo

Sigconverter

sigconverter.io is a user-friendly converter for Sigma rules. Designed to stay in sync with pySigma backends, it provides an easy-to-use interface for converting Sigma rules across detection platforms.

Open SourceSIGMA RULE CONVERTER
Visit
LOLRMM logo

LOLRMM

Living Off The Land Remote Management Tools is a curated list of RMM tools that could be abused by threat actors. Assists security professionals in threat hunting, detection, and prevention policy creation.

280+RMM TOOLS CATALOGED
Visit
Bootloaders logo

Bootloaders

bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security professionals in staying informed and mitigating potential threats associated with bootloaders.

ActiveMALICIOUS BOOTLOADER DATABASE
Visit
Get Started

Protect Your Endpoints withCommunity-Driven Intel

Every open-source project feeds directly into the MagicSword enforcement engine. Get coverage from day one with zero manual configuration.

No credit card required · Deploy in 48 hours · Windows, macOS, and Linux coverage