4 items
Quick lookup for Living-off-the-Land Binaries during authorized red team engagements. LOLBin Reference is a fast, fully offline lookup tool for Living-off-the-Land Binaries (LOLBins) — the built-in OS binaries that can be abused to execute code, download payloads, escalate privileges, or bypass defenses using functionality Microsoft, Apple, and Linux distributions ship on every machine. It works the same way as LOLBAS.github.io and GTFOBins.github.io, but packaged as a searchable browser popup so red teamers, pentesters, and detection engineers don't have to leave the browser tab they're already in. ⚠️ FOR AUTHORIZED SECURITY TESTING AND EDUCATIONAL USE ONLY. This is a reference/lookup tool — it does not execute commands, deploy payloads, or connect to any remote system. It only displays information about techniques, exactly like the public LOLBAS and GTFOBins project sites. WHAT'S INSIDE • 142 curated entries — 58 Windows LOLBAS binaries + 84 Linux/Unix GTFOBins-style binaries — each linking back to its authoritative source (lolbas-project.github.io or gtfobins.github.io). • Example commands for each technique, with one-click copy to clipboard. • Sigma-style detection engineering notes on almost every entry, so blue teams and detection engineers can turn a technique lookup directly into an alerting rule. • Instant client-side search across binary name, category, technique, and description — no page reloads, no loading spinners. • Windows / Linux / All filter toggle to narrow results to one platform. WHY IT'S OFFLINE-ONLY The entire database ships inside the extension package. There are no host permissions, no network requests, and no telemetry — everything renders from the bundled, git-versioned dataset. Reference links open the original LOLBAS/GTFOBins pages in a new tab only when you click them. WHO IT'S FOR • Red teamers and penetration testers who need a fast, authoritative technique reference during an authorized engagement. • Detection engineers writing Sigma rules or SIEM alerts for LOLBin abuse. • Students and blue teamers learning how native OS tooling gets abused, and how to detect it. HOW TO USE IT Click the extension icon, type a binary name (e.g. "certutil"), a technique category (e.g. "privilege escalation"), or a keyword from the description. Use the Windows/Linux toggle to narrow the platform. Click any example command to copy it to your clipboard. RESPONSIBLE USE Use only against systems you own or are explicitly authorized to test. This extension is a reference utility, not an exploitation tool — it never sends, receives, or executes anything on your behalf. Source available and open to review: see the project repository linked below.
Jul 8, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.