Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
-
Updated
Dec 6, 2025 - XSLT
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Encyclopedia for Executables
Awesome list of Living off the Land (LOL) methods, tools, and features commonly abused by attackers
A post-exploitation toolkit to simulate the weaponization and detection of native Windows binaries based on LOLBas framework.
Obfuscated PowerShell reverse shells for security research and testing purposes.
Ultra-lightweight (~4KB) CLI tool to control Windows media playback. Built natively using csc.exe (Living Off the Land / LOLBin) without external dependencies.
LOLGEN: Living Off The Land Payload Generator
Ransomware dataset, containing dynamic behaviour of more than 60 distinct ransomware families.
A collection of specific commands used by threat actors, detailing their procedural implementations of tactics and techniques from the MITRE ATT&CK framework.
A library of post-exploitation MacOS scripts based on threat emulation, LOObins, CTI, and MITRE ATT&CK.
A C2 server designed to run within Electron applications.
Script is written to fetch LOLBin Details from Security and Sysmon EVTX file.
lowest-common denominator binaries
PoC Script demonstrating various known User Account Control (UAC) bypass methods in Windows. Elevates user to Administrator and SYSTEM User
Add a description, image, and links to the lolbins topic page so that developers can more easily learn about it.
To associate your repository with the lolbins topic, visit your repo's landing page and select "manage topics."