Ross ROSS = Recommend OSS · open-source software intelligence for agents

LOLBAS-Project/LOLBAS resource

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) observed · 2026-08-28

github.com/LOLBAS-Project/LOLBAS · homepage · XSLT · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 99
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3008
  • days_rel: n/a
  • days_push: 7
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

8771 stars · 1172 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques like code execution, downloads, persistence, and UAC bypass. It powers a searchable frontend at lolbas-project.github.io with MITRE ATT&CK mappings.

Use cases

  • find windows binaries that can download files for red team tradecraft
  • look up which LOLBins map to a MITRE ATT&CK technique
  • hunt for abuse of signed microsoft binaries in DFIR investigations
  • document application whitelisting bypass techniques
  • find LOLBins for UAC bypass or credential theft
  • compare windows LOLBins against unix GTFOBins equivalents

When to choose

  • you need a reference of Microsoft-signed binaries with unexpected offensive functionality
  • you are doing red team, purple team, or detection engineering on Windows
  • you want ATT&CK-mapped documentation of LOLBin techniques

When to avoid

  • you need UNIX/Linux equivalents - use GTFOBins instead
  • you are looking for malicious Windows drivers - use loldrivers.io
  • you need an offensive tool that executes techniques rather than documents them

Facets

dataset · maturity active

security penetration-testing vulnerability-scanning documentation security penetration-testing windows developer-tools windows cli lolbins red-team blue-team dfir threat-hunting mitre-attack yml-database gtfobins web-server

2 sources

Member repositories

RepositoryRoleHealth v2
LOLBAS-Project/LOLBASmain77

For agents

markdown · JSON · MCP: product_card(name="LOLBAS-Project/LOLBAS")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem