#
lotl
Here are 3 public repositories matching this topic...
Zero-file, LotL command for memory-resident binary execution. Bypasses EDR vectors by leveraging memfd_create and os.execve to pivot from an obfuscated Base85/Bit-Shift one-liner to a fileless process execution masquerading as a kernel thread without disk footprints.
obfuscation ram cybersecurity pentesting ttps mitre-attack red-teaming fileless lotl edr-evasion zero-file-execution
-
Updated
Aug 11, 2026 - Python
POC framework for detecting LOLBin abuse in Sysmon logs using Splunk SPL. Implements 12 layered checks (signature matching, parent-child anomalies, threat intel, statistical baselines) with risk scoring for automated alert prioritization. Supports standalone Splunk or distributed n8n architecture.
splunk cybersecurity sysmon siem soar detection-rules mitre-attack threat-detection lolbins n8n lotl
-
Updated
Dec 2, 2025 - Python
Add this topic to your repo
To associate your repository with the lotl topic, visit your repo's landing page and select "manage topics."