lotl
Here are 21 public repositories matching this topic...
GitHub-native command-and-control framework for authorized security research, with encrypted multi-channel transport and resilient failover.
-
Updated
Jul 18, 2026 - TypeScript
Living Off The Land (LOTL) persistent Reverse shell
-
Updated
Jan 14, 2024 - HTML
SysWhispers & HellsGate successor, executing protected Indirect & Direct syscalls in EDR protected settings
-
Updated
Aug 15, 2026 - Rust
BypassIT is a framework for covert malware delivery and post-exploitation using AutoIT for red / blue team self assessment.
-
Updated
Jul 6, 2025 - AutoIt
Advanced Living Off the Land (LotL) tactics, tools, and abuse techniques for red teams, defenders, and cyber researchers. Stealth over payload.
-
Updated
Aug 18, 2025
A kotlin library for verifying certificate chains using trusted lists
-
Updated
Sep 18, 2026 - Kotlin
LotL-Watcher is a lightweight security monitoring tool designed to detect and mitigate "Living-off-the-Land" attacks. Instead of relying on traditional file signatures, this tool monitors the behavior of trusted Windows binaries (like certutil, powershell, wmic, mshta).
-
Updated
Aug 7, 2026 - C#
Zero-file, LotL command for memory-resident binary execution. Bypasses EDR vectors by leveraging memfd_create and os.execve to pivot from an obfuscated Base85/Bit-Shift one-liner to a fileless process execution masquerading as a kernel thread without disk footprints.
-
Updated
Aug 11, 2026 - Python
A Purple Team simulation framework demonstrating Windows persistence mechanisms, evasion, and behavioral EDR detection
-
Updated
May 5, 2026 - PowerShell
Detection engineering lab: simulating a Living off the Land (LotL) attack (vssadmin shadow copy deletion) on a Windows Server 2022 EC2 instance, capturing it with Sysmon, and building a validated Splunk SPL detection rule. Maps to MITRE ATT&CK T1490 & T1218.
-
Updated
Sep 15, 2026
Endpoint investigation of a PowerShell LotL attack reconstructing persistence via Windows services, extracting IOCs, and mapping to MITRE ATT&CK using Kibana and Windows event logs.
-
Updated
Mar 16, 2026
POC framework for detecting LOLBin abuse in Sysmon logs using Splunk SPL. Implements 12 layered checks (signature matching, parent-child anomalies, threat intel, statistical baselines) with risk scoring for automated alert prioritization. Supports standalone Splunk or distributed n8n architecture.
-
Updated
Dec 2, 2025 - Python
Worshop en Red Team Space, Ekoparty 2023
-
Updated
Sep 14, 2024
Sanitized DFIR case study of a fake CAPTCHA malware delivery chain involving mshta, obfuscated PowerShell, LOTL behavior, IOC analysis, and remediation actions.
-
Updated
May 25, 2026
Source code for a deprecated "LOTL file transfer technique" which would utilize the Windows BITS subsystem
-
Updated
Sep 19, 2024 - C
Trust Registry: EU LOTL and national Trusted Lists (ETSI TS 119 612) aggregated with the private List of Trusted Entities (ETSI TS 119 602), published as a signed snapshot
-
Updated
Sep 18, 2026 - Java
Add this topic to your repo
To associate your repository with the lotl topic, visit your repo's landing page and select "manage topics."