OPEN DATA / READY TO INTEGRATE
Your workflow. Our intelligence.
Access the same community research that powers the catalog. No API key required. All feeds are static files updated when the site is published.
Data feeds
| ENDPOINT | FORMAT | CONTENTS |
|---|---|---|
| /api/rmm_tools.json Full catalog | JSON | All tools with details, artifacts, detections, and references. |
| /api/rmm_tools.csv Full catalog | CSV | A tabular export for spreadsheets and security pipelines. |
| /api/rmm_domains.csv Network domains | CSV | Domain indicators paired with their associated RMM tool. |
| /api/rmm_certificates.json Code signing certificates | JSON | The existing certificate feed for application control research. |
| /api/rmm_tools_count.json Catalog count | JSON | The number of tools in this build. |
| /api/detections/sigma/generic_rmm_detection.yml Process detection | YAML | The generated Sigma rule for RMM processes. |
| /api/detections/sigma/rmm_domains_dns_queries.yml DNS detection | YAML | The generated Sigma rule for RMM domain queries. |
Fetch the catalog
curl https://lolrmm.io/api/rmm_tools.jsonThe response is a JSON array. Existing field names and CSV columns are preserved.
Fetch one tool
curl https://lolrmm.io/api/tools/anydesk.jsonUse the slug from a tool's catalog URL. Each detail page includes a JSON download link.
Use the data thoughtfully
These entries describe tools and their potential for misuse. A match provides an investigative lead; evaluate it against your environment and approved software. Preserve the references and acknowledgements when incorporating research into your own workflow.
Tool, domain, and detection feeds are regenerated from the repository at build time. The certificate feed retains its existing publication process.