# LOLBAS: The Reference Database for Living Off The Land Windows Binaries

> LOLBAS (Living Off The Land Binaries And Scripts) is a GPL-3.0 community project that catalogs Microsoft-signed Windows binaries, scripts, and libraries with capabilities beyond their documented purpose: code execution, file transfers, UAC bypass, credential theft, and persistence. The data lives in YML files and is rendered as a searchable frontend at lolbas-project.github.io.

**LOLBAS-Project/LOLBAS** — Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

- Repository: https://github.com/LOLBAS-Project/LOLBAS
- Website: https://lolbas-project.github.io
- Stars: 8,846 · Forks: 1,177
- Language: XSLT
- License: GPL-3.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/lolbas-project-lolbas

## What LOLBAS Covers and Who Uses It

Every Windows system ships with a collection of signed Microsoft binaries. Most of them have documented primary functions. Some of them can also do things that were never the intended use case: download files from the internet, execute arbitrary code, compile scripts, dump process memory, or modify persistence mechanisms. LOLBAS catalogs those secondary capabilities.

The README defines the project's goal directly: 'to document every binary, script, and library that can be used for Living Off The Land techniques.' The database covers three categories: LOLBins (executables), LOLScripts (scripts), and LOLLibs (libraries). All entries must meet the same criteria: Microsoft-signed, present on the OS or downloadable from Microsoft, and carrying functionality useful to an attacker or red team that goes beyond the file's documented purpose.

The primary users are offensive security practitioners, red team operators, and defenders building detection coverage. The database is not a set of attack tools itself; it is a structured reference that maps which existing Windows binaries can perform security-relevant actions.

## The Origin of Living Off The Land Techniques

The phrase 'living off the land' entered the security community's vocabulary at DerbyCon 3, where Christopher Campbell and Matt Graeber used it to describe the technique of using the target system's own tools rather than introducing external payloads. The README credits them with coining the phrase.

The specific term LOLBins came later, from a Twitter discussion about what to name executables with exploitable secondary functions. Philip Goh proposed the term, a community poll produced a 69 percent consensus in favor, and the name was made official. Jimmy Bayne followed up with LOLScripts by the same process.

The LOLBAS project as a repository was started by Oddvar Moe, who gave a talk at DerbyCon 2018 titled 'Lolbins Nothing to LOL about!' covering the project's history. The talk is referenced in the README and covers the conceptual development of the project from that origin to a structured database.

## Criteria for Inclusion in the Database

The README documents a precise set of inclusion criteria. A file must be Microsoft-signed, either native to Windows or downloadable from Microsoft's own infrastructure. It must have 'unexpected' functionality beyond its primary purpose, with one exception: application whitelisting bypasses qualify even if the bypass mechanism is technically intentional. The behavior must be useful to an advanced persistent threat or red team.

The README enumerates the categories of interesting functionality: arbitrary code execution, passing execution to another unsigned program, compiling code, downloading files, uploading files, copying files, establishing persistence, bypassing UAC, stealing credentials, dumping process memory, surveillance (keylogging or network tracing), evading or modifying logs, and DLL side-loading or hijacking.

NetNTLM credential coercing is explicitly excluded because most Windows binaries allow it under default conditions. The exception is a binary that allows coercing on non-default ports, or one that can directly steal credentials, which does qualify.

## Using the LOLBAS Database

The most accessible way to use LOLBAS is through the frontend website at lolbas-project.github.io. The README describes the frontend as a 'fancy frontend' maintained by Chris Spehn. It provides a searchable, filterable view of the YML entries.

The source data lives in the `yml/` directory of the repository. Each YML file documents one binary, script, or library, following the format defined in YML-Template.yml at the repository root. Security engineers building detection rules, automation pipelines, or hunting queries can consume the YML files programmatically rather than using the frontend.

The CategoryList.md file at the repository root documents the category taxonomy used in the YML entries. The Archive-Old-Version/ directory contains entries that were retired from the main collection.

## Contributing a New LOLBin or LOLScript

New entries go through a review process documented in CONTRIBUTING.md. Contributors must verify that the candidate file meets all inclusion criteria: Microsoft-signed, unexpected functionality, and usefulness to an attacker or red team.

The YML-Template.yml file at the repository root defines the required fields and format for a submission. Pull requests that add new files or correct existing ones are the primary contribution mechanism. Issues can be used to flag candidates before writing a full YML entry.

The README's exclusion of NetNTLM coercing entries reflects an editorial judgment that most submissions of that type would add noise rather than signal, given that most Windows binaries share that capability.

## LOLBAS vs GTFOBins

The README's Thanks section explicitly credits the team at gtfobins.github.io, calling out the frontend similarity. GTFOBins is the Unix and Linux equivalent of LOLBAS: it documents Unix binaries that can be abused for privilege escalation, file read or write, or shell escape on systems with restricted environments. The maintainer group of LOLBAS acknowledges GTFOBins as a parallel project covering a different operating system.

The practical difference is platform scope. LOLBAS covers Windows and requires Microsoft signing as a hard criterion. GTFOBins covers Unix-like systems and focuses on binaries commonly available in restricted shell environments, such as after gaining access to a system running a limited account. An operator working across both Windows and Linux environments would use both databases for their respective targets.

Both projects use a similar data model: structured files per binary, rendered to a searchable website.

## Maintenance Status and Licensing

The last push to the master branch was on 2026-09-26, two days before this writing, confirming active maintenance. The project has seven named maintainers listed in the README, each with documented Twitter handles: Oddvar Moe, Jimmy Bayne, Conor Richard, Chris Spehn, Liam Somerville, Wietze, and Jose Hernandez.

LOLBAS is licensed under GPL-3.0. The README includes a NOTICE.md file for additional license information. The primary language in the repository is XSLT, which is used to transform the YML data into the website output.

The hashtags #LOLBin, #LOLBins, #LOLScript, #LOLScripts, #LOLLib, and #LOLLibs are documented in the README as the standard tags for community discussion and discovery of new candidates.

## Conclusion

LOLBAS is the primary reference for security teams mapping or defending against living-off-the-land techniques on Windows systems. Red teams use it to identify available tools on a compromised host without needing to upload additional software. Defenders use it to build detection rules targeting the unexpected behaviors documented here. The database is not a vulnerability list; the behaviors it documents exist in signed, legitimate software by design. Run detection validation against the YML files at lolbas-project.github.io rather than building rules from memory.

## FAQ

### What is the LOLBAS project?

LOLBAS is a community database that catalogs Microsoft-signed Windows binaries, scripts, and libraries with capabilities beyond their documented purpose, including code execution, file downloads, UAC bypass, and credential theft. The data is maintained as YML files in the GitHub repository and browsable at lolbas-project.github.io.

### What does LOLBAS stand for?

LOLBAS stands for Living Off The Land Binaries And Scripts. The phrase 'living off the land' was coined by Christopher Campbell and Matt Graeber at DerbyCon 3 to describe attackers using the target system's own signed tools rather than uploading external payloads.

### What is a LOLBAS attack?

A living-off-the-land attack uses Microsoft-signed binaries already present on a Windows system to perform actions such as downloading payloads, executing code, or escalating privileges, rather than introducing external tools that would be flagged by antivirus or application whitelisting. LOLBAS documents the specific binaries and their abuse techniques.

### How does LOLBAS differ from GTFOBins?

LOLBAS covers Windows and requires that documented binaries be Microsoft-signed. GTFOBins covers Unix and Linux binaries that can be abused in restricted shell environments. The README credits the GTFOBins team for the shared frontend design approach. Both maintain structured data per binary and render it to a searchable website.

## Sources

- [Issues](https://github.com/LOLBAS-Project/LOLBAS/issues)
- [License: GPL-3.0](https://github.com/LOLBAS-Project/LOLBAS/blob/master/LICENSE)
- [LOLBAS-Project/LOLBAS on GitHub](https://github.com/LOLBAS-Project/LOLBAS)
- [Project website](https://lolbas-project.github.io)
- [README](https://github.com/LOLBAS-Project/LOLBAS/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/lolbas-project-lolbas
