SkillAgentSearch skills...

LOLBins

The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders understand how LOLBin binaries are used by threat actors during an intrusion in a graphical and digestible format for the TIPs platform using the STIX format.

Install / Use

/learn @CTI-Driven/LOLBins
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

LOLBins CTI-Driven

<p align="center"> <img src="logo.png" style="border-radius:60px;width:20%;height:auto"> </p>

The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders understand how LOLBin binaries are used by threat actors during an intrusion in a graphical and digestible format for the TIPs platform using the STIX format. Therefore providing valuable insights and context about LOLBins from a Cyber threat Intel and Cyber defence perspective.

This includes :

  • Associated campaigns
  • Associated APTs
  • Associated TTPs
  • Associated Malware
  • Associated commands
  • Associated Mitigations
  • Associated CVEs
</p> <p align="center"> Website: https://lolbins-ctidriven.vercel.app (Recommended browser: Firefox)</p>

Workflow diagram

Workflow

Output Samples:

STIX2 Visualizer

STIX2.1

JSON Crack Visualizer

JsonCrack

YouTube Video Demo:

Youtube Video

Agenda for 2023-2024:

  • Add the Top 15 LOLBins files that are being used by threat actors.
  • Add an API to streamline the passing of LOLBinCTI-Driven JSON files to the TIPs platform.

Author:

Linkedin : Nounou Mbeiri

Twitter : @Nounou Mbeiri

Related Living-Off-the-Land Binaries projects:

https://lolol.farm

Thanks:

Related Skills

View on GitHub
GitHub Stars130
CategoryDevelopment
Updated16d ago
Forks16

Languages

HTML

Security Score

95/100

Audited on Mar 6, 2026

No findings