# LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Repository: https://github.com/LOLBAS-Project/LOLBAS
Canonical: https://ross.abutalabs.com/products/lolbas
Homepage: https://lolbas-project.github.io
Language: XSLT
License: GPL-3.0
License Family: copyleft
Topics: lolbins, lolscripts, redteam, blueteam, purpleteam, dfir, living-off-the-land
Last push: 2026-08-26T18:11:51+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 35, longevity 100
- inputs: {"age_days": 3008, "days_push": 7, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 8771, forks 1172 (observed 2026-08-28T04:10:25.695675+00:00)

## What it is
A curated dataset of YML files documenting Windows binaries, scripts, and libraries that can be abused for 'Living Off The Land' techniques like code execution, downloads, persistence, and UAC bypass. It powers a searchable frontend at lolbas-project.github.io with MITRE ATT&CK mappings.

## Use cases
- find windows binaries that can download files for red team tradecraft
- look up which LOLBins map to a MITRE ATT&CK technique
- hunt for abuse of signed microsoft binaries in DFIR investigations
- document application whitelisting bypass techniques
- find LOLBins for UAC bypass or credential theft
- compare windows LOLBins against unix GTFOBins equivalents

## When to choose
- you need a reference of Microsoft-signed binaries with unexpected offensive functionality
- you are doing red team, purple team, or detection engineering on Windows
- you want ATT&CK-mapped documentation of LOLBin techniques

## When to avoid
- you need UNIX/Linux equivalents - use GTFOBins instead
- you are looking for malicious Windows drivers - use loldrivers.io
- you need an offensive tool that executes techniques rather than documents them

## Facets
- artifact type: dataset
- maturity: active
- function: security, penetration-testing, vulnerability-scanning, documentation
- domain: security, penetration-testing, windows, developer-tools
- platform: windows, cli
- tags: lolbins, red-team, blue-team, dfir, threat-hunting, mitre-attack, yml-database, gtfobins, web-server

## Member repositories
- LOLBAS-Project/LOLBAS (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:25.695675+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:25:14.030591+00:00, confidence not recorded.
  - readme: https://github.com/LOLBAS-Project/LOLBAS (fetched 2026-08-28T04:10:25.695675+00:00, sha 6c589d93b681)
  - homepage: https://lolbas-project.github.io (fetched 2026-08-29T08:25:25.411444+00:00, sha 1c5b1e78e5c9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
