COMMUNITY INTELLIGENCE / SHARED DEFENSE
Know more. Defend together.
LOLRMM is a community-driven catalog of remote monitoring and management tools that could be abused by threat actors.
About LOLRMM
Living Off the Land Remote Monitoring and Management helps researchers, incident responders, and system administrators understand remote access tools and their potential for misuse. Explore the tools, investigate their forensic artifacts, and use the evidence to inform detection and prevention.
The catalog includes RMM and RAT classifications as recorded in the source research. Inclusion does not mean that every use of a tool is malicious. Assess activity in the context of your environment and approved software.
Built in the open
Contributions from the security community keep this project useful. Share new tools, detection rules, and forensic findings, or help improve an existing entry.
Submit a finding ↗ · Contribute on GitHub ↗
Explore our companion project LOLDrivers for malicious and vulnerable Windows drivers.
Meet the maintainers

Michael Haag
Michael Haag is a Principal Threat Researcher at Splunk. Michael has more than a decade of experience in security architecture and operations. His specialties include advanced threat hunting and investigations, atomic testing, and technological evaluations and detection engineering. Michaels is the co-founder of the Atomic Red Team project and co-host of Atomics on a Friday.

Nasreddine Bencherchali
Currently, Nasreddine Bencherchali is a Threat Researcher at Nextron Systems, with a focus in Detection Engineering and Threat Hunting. Nasreddine is also currently one of the maintainers of the SIGMA project and the co-founder of the EVTX-ETW-Resources project, he also writes a blog about Detection and other security topics.

Kostas
Kostas is a security researcher who tweets and follows topics related to Threat Intelligence, malware, Incident Response, and Threat Hunting. He is known for his contributions to various open-source security projects and is an active member of the cybersecurity community. Opinions are his own.

Hare Sudhan
Hare Sudhan is a Senior Software/Security Engineer specializing in developing applications for Security Operations, Cyber Deception, and Adversary Emulation. He is passionate about contributing to open-source projects and is also one of the maintainers for the Atomic Red Team project.

Jose Hernandez
Currently, Jose Enrique Hernandez is the Director of Threat Research at Splunk. Jose is known for creating several security-related projects, including: Splunk Attack Range, Splunk Security Content, Git-Wild-Hunt, Melting-Cobalt, and BlackCert projects. He also works as a maintainer to security industry critical repositories such as Atomic Red Team and lolbas-project.github.io.