COMMUNITY INTELLIGENCE / SHARED DEFENSE

Know more. Defend together.

LOLRMM is a community-driven catalog of remote monitoring and management tools that could be abused by threat actors.

About LOLRMM

Living Off the Land Remote Monitoring and Management helps researchers, incident responders, and system administrators understand remote access tools and their potential for misuse. Explore the tools, investigate their forensic artifacts, and use the evidence to inform detection and prevention.

The catalog includes RMM and RAT classifications as recorded in the source research. Inclusion does not mean that every use of a tool is malicious. Assess activity in the context of your environment and approved software.

Built in the open

Contributions from the security community keep this project useful. Share new tools, detection rules, and forensic findings, or help improve an existing entry.

Submit a finding ↗ · Contribute on GitHub ↗

Explore our companion project LOLDrivers for malicious and vulnerable Windows drivers.

Meet the maintainers

Michael Haag

Michael Haag

Michael Haag is a Principal Threat Researcher at Splunk. Michael has more than a decade of experience in security architecture and operations. His specialties include advanced threat hunting and investigations, atomic testing, and technological evaluations and detection engineering. Michaels is the co-founder of the Atomic Red Team project and co-host of Atomics on a Friday.

Nasreddine Bencherchali

Nasreddine Bencherchali

Currently, Nasreddine Bencherchali is a Threat Researcher at Nextron Systems, with a focus in Detection Engineering and Threat Hunting. Nasreddine is also currently one of the maintainers of the SIGMA project and the co-founder of the EVTX-ETW-Resources project, he also writes a blog about Detection and other security topics.

Kostas

Kostas

Kostas is a security researcher who tweets and follows topics related to Threat Intelligence, malware, Incident Response, and Threat Hunting. He is known for his contributions to various open-source security projects and is an active member of the cybersecurity community. Opinions are his own.

Hare Sudhan

Hare Sudhan

Hare Sudhan is a Senior Software/Security Engineer specializing in developing applications for Security Operations, Cyber Deception, and Adversary Emulation. He is passionate about contributing to open-source projects and is also one of the maintainers for the Atomic Red Team project.