LocalXpose
LocalXpose (loclx) is a free/subscription tunneling service from localxpose.io that exposes local TCP/UDP/HTTP services over the internet via the operator-controlled `*.localxpose.io` infrastructure. Marketed for developer use cases (webhook testing, local-server sharing), it is catalogued by the LOTTunnels project under the "shell access" category because the `loclx tunnel tcp/udp --port <PORT>` command pattern can expose an SSH or RDP listener through the operator's tenant subdomain, providing remote interactive access without a traditional RMM agent or open inbound firewall. Documented abuse cases include shell exposure for post-exploitation remote access, HTTP tunneling for data exfiltration, and tunnel-fronted phishing infrastructure.
Tool overview
- Category
- RAT
- Research authors
- @MHaggis
- Created
- 2026-05-18
- Last modified
- 2026-05-18
- Privileges
- User
- Free / availability
- Yes (free tier + paid subscription)
- Verification required
- Tenant signup required (free); API-key authenticated via `loclx account login`
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- loclx.exe
- OriginalFileName
- loclx.exe
- Description
- LocalXpose command-line client (Windows). Single static Go binary; invoked as `loclx tunnel <type> --port <PORT>` after `loclx account login`.
- Filename
- loclx
- OriginalFileName
- loclx
- Description
- LocalXpose command-line client (Linux/macOS).
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- loclx.exe
- Description
- LocalXpose CLI client (Go static binary). Often run from the user's Downloads or AppData directory rather than a system install path.
- OS
- Windows
- File
- %APPDATA%\loclx\config.yaml
- Description
- LocalXpose CLI configuration (account API key after `loclx account login`)
- OS
- Windows
- File
- ~/.loclx/config.yaml
- Description
- LocalXpose CLI configuration on Linux/macOS (account API key)
- OS
- Linux
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 4688
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- loclx.exe tunnel tcp --port <PORT>
- Description
- LocalXpose tunnel-create process invocation — `tcp` and `udp` tunnel subcommands are the high-signal abuse pattern (used to expose SSH/RDP for inbound remote access through the operator-controlled relay).
FORENSIC EVIDENCE
Network artifacts
- Description
- LocalXpose tenant tunnel control plane and per-tunnel relay endpoints (wildcard subdomain pattern matches all operator-assigned tunnel hostnames).
- Domains
- localxpose.io
- *.localxpose.io
- api.localxpose.io
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- Other
- Value
- Install via npm (`npm install -g loclx`), choco, snap, or direct binary download from localxpose.io
- Type
- Other
- Value
- LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/localxpose/
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_files_sigma.yml
- Description
- Detects potential file activity of LocalXpose RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_network_sigma.yml
- Description
- Detects potential network activity of LocalXpose RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_processes_sigma.yml
- Description
- Detects potential process activity of LocalXpose RMM tool
References
Acknowledgements
- Person
- rcKillam
- Handle
- @rcKillam
- Person
- Michael Haag
- Handle
- @MHaggis