National Cyber Warfare Foundation (NCWF)

LOLRMM for cataloging abused remote monitoring and management tools in threat hunting


0 user ratings
2026-09-23 01:25:18
milo
Red Team (CNA)
"LOLRMM

LOLRMM is a curated, community-driven catalog of RMM (Remote Monitoring and Management) tools historically abused by threat actors, packaged as YAML profiles with Sigma detection rules for defenders.








Toolmagicsword-io/LOLRMM — curated catalog of RMM tools abused by threat actors, with YAML profiles and Sigma detections
Categorythreat intelligence / detection content repository
Primary UseThreat hunting, detection engineering and prevention policy creation built on YAML tool profiles and Sigma rules
Safe UsePurely defensive: designed for blue teams conducting authorized threat hunting, purple-team detection validation, and hardening of enterprise RMM policies
Telemetry NoteEach profile documents the artifacts the RMM tools themselves leave on disk, in event logs, registry and on the network — the exact telemetry defenders should baseline and monitor

LOLRMM, hosted at magicsword-io/LOLRMM, sits in the same family of defensive resources as LOLBAS and GTFOBins, but targets a category that has become a staple of intrusion tradecraft: commercial RMM (Remote Monitoring and Management) software. Rather than documenting native binaries, it catalogs third-party remote-access and management utilities — the kind used legitimately by IT departments everywhere — that threat actors have historically repurposed for persistence and command-and-control. The project, released under Apache-2.0 and written largely in MDX with YAML data files, is explicitly community-driven and positions itself as raw material for threat hunting, detection engineering and prevention policy work.


The core data model is a set of structured YAML files, one per RMM tool, living in the yaml/ directory with provided templates for contributors. Each profile is far richer than a simple name-and-link entry: it captures tool name and description, author and creation/modification dates, technical details such as the official website and PE metadata, required privileges, supported operating systems, capabilities, known vulnerabilities, and installation paths. This is the kind of structured intelligence that lets a detection engineer reason about a tool before ever seeing it in telemetry.


Where LOLRMM distinguishes itself from a plain list is its coverage of observable behavior. Every profile documents the artifacts a given RMM tool leaves behind on disk, in event logs, in the registry, and on the network. For a defender, this is the difference between knowing that a tool exists and knowing what its execution actually looks like in Sysmon, Windows Event Log, or proxy telemetry — the substrate on which practical detections get built.


On top of that, the project ships Sigma detection rules in the detections/sigma/ directory. Because Sigma is a vendor-agnostic rule format, these rules can be converted through pySigma pipelines into queries for a wide range of SIEM backends. The pairing of per-tool artifact documentation with ready-to-adapt detection logic makes the repository a genuine detection-content pipeline rather than a reference page, and the CI badge indicates contributions are automatically validated before merge.


Access is deliberately multi-channel. Human users can browse the catalog at lolrmm.io, while automation can consume the same dataset programmatically: curl https://lolrmm.io/api/rmm_tools.json returns the full catalog as a JSON array, and swapping the extension to .csv yields the same data as CSV. That makes it trivial to pull LOLRMM data into a threat-hunting platform, enrich asset inventories, or drive allowed/denied application policy for RMM binaries from a single scheduled fetch.


Operationally, the most common defensive play is policy enforcement: most enterprises need only a handful of RMM tools, so the catalog functions as a blocklist source for application control. Every other unsigned or unexpected RMM binary observed on an endpoint deserves scrutiny, and LOLRMM gives you the enumeration of what "legitimate but abused" looks like. Purple teams can equally use the profiles to validate that their Sigma rules fire on the documented artifacts during authorized exercises.


For anyone wanting to contribute or self-host, the repository is reproducible end to end. Requirements are Python 3.10 with Poetry and Node.js; after git clone https://github.com/magicsword-io/LOLRMM.git and poetry install, running python bin/site.py regenerates the site content from the files under yaml/, and the website itself runs locally with pnpm i followed by pnpm dev on port 3000. This build-from-data architecture means the website, the API, and the catalog stay in sync by construction — there is a single source of truth in the YAML files.


Automation is handled through GitHub Actions workflows in .github/workflows/, which validate contributions, build and test changes, run code-quality checks, manage deployment, and even keep the RMM-tools-count badge on the README current. Contributors fork, branch, edit or add YAML profiles using the templates, and open a pull request; the maintainers also document how to provision a PUSH_TOKEN personal access token in repository secrets for the badge-updating workflow — a small but telling detail about how seriously the project treats its own CI hygiene.


With roughly 396 stars and topics tagging cybersecurity, detections, lotl and remotemanagement, LOLRMM has clearly resonated with the detection community. The threat model it addresses is real and current: ransomware operators and access brokers routinely deploy legitimate RMM agents during intrusions precisely because they blend into normal IT administration traffic. A catalog that enumerates these tools, their footprint, and their detections closes a meaningful intelligence gap.


It is worth being precise about what this repository is not. It contains no exploit code, no payloads, and no operational guidance for abusing RMM software — it is a defensive knowledge base, and its value scales with community contributions keeping the catalog current as new RMM products enter attacker playbooks. Analysts should treat it as a living dataset, versioned through git, rather than a static list that will age gracefully on its own.


For detection engineers, threat hunters, and IT security teams weighing whether the RMM agent they just found on an endpoint is sanctioned software or an intruder's foothold, magicsword-io/LOLRMM is one of the most directly useful community resources in the Living-off-the-Land genre. The combination of structured YAML profiles, documented host and network artifacts, Sigma rules, and a clean JSON/CSV API means it plugs into existing workflows with minimal glue code — a rare quality in threat-intel repositories.



Official project repository for magicsword-io/LOLRMM.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/lolrmm-for-cataloging-abused-remote.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.