#LOLDriver
A single, searchable directory of the community's Living-Off-the-Land security research — every LOLBin, LOLDriver, and adjacent project, indexed and cross-referenced by platform and focus area.

lolol.farm

#infosec #cybersecurity #redteam #pentest #threatintel
lolol.farm — Living Off the Living Off the Land
A curated index of Living Off the Land security research projects.
lolol.farm
May 28, 2026 at 7:58 AM
Reverse engineering of Windows Defender BTR.sys shows its encrypted boot-time transaction format can be abused for arbitrary file and registry operations from Ring 0, enabling EDR bypass and Defender neutralization. #BTRsys #WindowsDefender #Ring0
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
This research reverse engineers Windows Defender’s BTR.sys boot-time remediation driver and shows how its encrypted transaction format can be abused to perform arbitrary file and registry operations from Ring 0. The paper also introduces BTR_CLI, demonstrates EDR/AV bypass and boot-time neutralization against Microsoft Defender, and highlights the defensive implications of a signed built-in LOLDriver. #BTR.sys #BTR_CLI #MicrosoftDefender #MsMpEng.exe #WdFilter.sys #WdBoot.sys #WdNisDrv.sys #Mimikatz #mimidrv.sys #MSRC
www.hendryadrian.com
August 20, 2026 at 2:00 PM
DetectRaptor - vql - LolDriversYara.yaml: Scans system driver directories using Malware and Vulnerability Yara rules from LolDriver project.
DetectRaptor - vql - LolDriversYara.yaml: Scans system driver directories using Malware and Vulnerability Yara rules from LolDriver project.
github.com
June 27, 2025 at 12:09 PM
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video

Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed…
One Person, 1,500 Endpoints, Two Hours a Week: How a Financial Services Firm Killed Its LOLBin & LOLDriver Exposure Without Adding a Single Agent + Video
Introduction: Living Off the Land (LOTL) attacks have become the cornerstone of modern adversarial tradecraft. By weaponizing legitimate, signed binaries (LOLBins), vulnerable kernel drivers (LOLDrivers), and dual-use remote management tools (RMM), attackers can bypass traditional antivirus and EDR solutions entirely. For a U.S.-based financial services firm with 1,500 Windows endpoints and a mature security posture that already included AppLocker and WDAC, the gap wasn't a lack of tools—it was the operational burden of managing prevention at scale.
undercodetesting.com
June 28, 2026 at 3:15 PM