{
  "Name": "LocalXpose",
  "Category": "RAT",
  "Description": "LocalXpose (loclx) is a free/subscription tunneling service from localxpose.io that exposes local TCP/UDP/HTTP services over the internet via the operator-controlled `*.localxpose.io` infrastructure. Marketed for developer use cases (webhook testing, local-server sharing), it is catalogued by the LOTTunnels project under the \"shell access\" category because the `loclx tunnel tcp/udp --port <PORT>` command pattern can expose an SSH or RDP listener through the operator's tenant subdomain, providing remote interactive access without a traditional RMM agent or open inbound firewall. Documented abuse cases include shell exposure for post-exploitation remote access, HTTP tunneling for data exfiltration, and tunnel-fronted phishing infrastructure.\n",
  "Author": "@MHaggis",
  "Created": "2026-05-18",
  "LastModified": "2026-05-18",
  "Details": {
    "Website": "https://localxpose.io/",
    "PEMetadata": [
      {
        "Filename": "loclx.exe",
        "OriginalFileName": "loclx.exe",
        "Description": "LocalXpose command-line client (Windows). Single static Go binary; invoked as `loclx tunnel <type> --port <PORT>` after `loclx account login`."
      },
      {
        "Filename": "loclx",
        "OriginalFileName": "loclx",
        "Description": "LocalXpose command-line client (Linux/macOS)."
      }
    ],
    "Privileges": "User",
    "Free": "Yes (free tier + paid subscription)",
    "Verification": "Tenant signup required (free); API-key authenticated via `loclx account login`",
    "SupportedOS": [
      "Windows",
      "Linux",
      "MacOS"
    ],
    "Capabilities": [
      "TCP tunnel (`loclx tunnel tcp --port <PORT>`) — used to expose SSH/RDP/other shell-access services",
      "UDP tunnel (`loclx tunnel udp --port <PORT>`)",
      "HTTP/HTTPS tunnel (`loclx tunnel http --port <PORT>`) — used for webhook testing or to front phishing infrastructure",
      "Custom domain support (paid tier)",
      "Reserved tunnel addresses"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "loclx.exe",
      "loclx",
      "*\\loclx.exe",
      "C:\\Users\\*\\AppData\\Local\\Programs\\loclx\\loclx.exe",
      "/usr/local/bin/loclx",
      "%APPDATA%\\loclx\\*"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "loclx.exe",
        "Description": "LocalXpose CLI client (Go static binary). Often run from the user's Downloads or AppData directory rather than a system install path.",
        "OS": "Windows"
      },
      {
        "File": "%APPDATA%\\loclx\\config.yaml",
        "Description": "LocalXpose CLI configuration (account API key after `loclx account login`)",
        "OS": "Windows"
      },
      {
        "File": "~/.loclx/config.yaml",
        "Description": "LocalXpose CLI configuration on Linux/macOS (account API key)",
        "OS": "Linux"
      }
    ],
    "EventLog": [
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "loclx.exe tunnel tcp --port <PORT>",
        "Description": "LocalXpose tunnel-create process invocation — `tcp` and `udp` tunnel subcommands are the high-signal abuse pattern (used to expose SSH/RDP for inbound remote access through the operator-controlled relay)."
      }
    ],
    "Registry": [],
    "Network": [
      {
        "Description": "LocalXpose tenant tunnel control plane and per-tunnel relay endpoints (wildcard subdomain pattern matches all operator-assigned tunnel hostnames).",
        "Domains": [
          "localxpose.io",
          "*.localxpose.io",
          "api.localxpose.io"
        ],
        "Ports": [
          443
        ]
      }
    ],
    "Other": [
      {
        "Type": "Other",
        "Value": "Install via npm (`npm install -g loclx`), choco, snap, or direct binary download from localxpose.io"
      },
      {
        "Type": "Other",
        "Value": "LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/localxpose/"
      }
    ]
  },
  "Detections": [
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_files_sigma.yml",
      "Description": "Detects potential file activity of LocalXpose RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_network_sigma.yml",
      "Description": "Detects potential network activity of LocalXpose RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_processes_sigma.yml",
      "Description": "Detects potential process activity of LocalXpose RMM tool"
    }
  ],
  "References": [
    "https://localxpose.io/",
    "https://lottunnels.github.io/lottunnels/Binaries/localxpose/"
  ],
  "Acknowledgement": [
    {
      "Person": "rcKillam",
      "Handle": "@rcKillam"
    },
    {
      "Person": "Michael Haag",
      "Handle": "@MHaggis"
    }
  ]
}