OPEN DATA / READY TO INTEGRATE

Your workflow. Our intelligence.

Access the same community research that powers the catalog. No API key required. All feeds are static files updated when the site is published.

Data feeds

ENDPOINTFORMATCONTENTS
/api/rmm_tools.json

Full catalog

JSONAll tools with details, artifacts, detections, and references.
/api/rmm_tools.csv

Full catalog

CSVA tabular export for spreadsheets and security pipelines.
/api/rmm_domains.csv

Network domains

CSVDomain indicators paired with their associated RMM tool.
/api/rmm_certificates.json

Code signing certificates

JSONThe existing certificate feed for application control research.
/api/rmm_tools_count.json

Catalog count

JSONThe number of tools in this build.
/api/detections/sigma/generic_rmm_detection.yml

Process detection

YAMLThe generated Sigma rule for RMM processes.
/api/detections/sigma/rmm_domains_dns_queries.yml

DNS detection

YAMLThe generated Sigma rule for RMM domain queries.

Fetch the catalog

curl https://lolrmm.io/api/rmm_tools.json

The response is a JSON array. Existing field names and CSV columns are preserved.

Fetch one tool

curl https://lolrmm.io/api/tools/anydesk.json

Use the slug from a tool's catalog URL. Each detail page includes a JSON download link.

Use the data thoughtfully

These entries describe tools and their potential for misuse. A match provides an investigative lead; evaluate it against your environment and approved software. Preserve the references and acknowledgements when incorporating research into your own workflow.

Tool, domain, and detection feeds are regenerated from the repository at build time. The certificate feed retains its existing publication process.

Explore the source repository ↗