daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

☧ DÆMONBins

the Off-the-Land Almanac

https://daemon-sec-lotl.vercel.app/

https://daemon-404.github.io/daemon-sec-lotl/

GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, and extended into one filterable catalog.


License Built with Astro Search: Pagefind Deploy: Vercel Theme: Rosé Pine

Techniques Tools DÆMON additions Sources

Open the catalog →


A static Astro site with Pagefind search, in the visual language of daemon-sec.xyz. Every living-off-the-land and offensive technique from four public references is flattened to one filterable atom — a Technique — and filterable by platform, capability, source, execution context, required access, service, environment, availability, and evidence state. The catalog supports grouped variants, saved commands, configurable templates, shareable URL state, and a compact details inspector. Per-tool pages group a binary's techniques.

All four upstreams are GPL-3.0, so this combined work is GPL-3.0. See THIRD_PARTY_NOTICES.md and LICENSE.

❀ The five collections

Deck Source Techniques What it is
🩵 GTFOBins acd5246 2,125 Unix binaries abused for shell, file r/w, and SUID / sudo / capabilities privesc
💜 LOLBAS 7aca936 481 Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass
💛 WADComs a864cd1 100 Offensive Windows / Active Directory tooling, indexed by what access you hold
🩷 LOOBins 399e3c4 183 macOS binaries and documented use cases
❤️ DÆMON authored 196 134 fact-checked WADComs additions + 17 documented command references, badged DÆMON
Total 3,085 907 tools · all Zod-validated

Everything is placeholder-only reference material (lab IPs, test.local, john / password123) in the spirit of GTFOBins, LOLBAS, WADComs, LOOBins and MITRE ATT&CK.

☧ Layout

vendor/{gtfobins,lolbas,wadcoms}   the three upstreams (vendored; see setup-vendor.sh)
src/data/sources/loobins.json      pinned LOOBins snapshot (183 use cases)
src/data/sources/wadcoms-additions.json  committed authored WADComs snapshot
scripts/build-dataset.mjs          local ingestion → src/data/*.json + public/data
scripts/wadcoms-normalize.mjs      WADComs family fixes (Impacket split, case-fold)
scripts/split-impacket.mjs         one-shot, idempotent migration of the committed data
src/data/techniques.json           the canonical, committed dataset (a Technique[])
src/data/tools.json                per-tool metadata (aliases, Full_Path, contributors)
src/data/facets.json               derived facet indexes + counts + upstream commits
src/data/catalog-additions.json    documented DÆMON command references
src/pages/                         home · /catalog · /<deck> · /<deck>/<tool> · credits · 404
src/scripts/catalog.ts             the vanilla-TS catalog workspace island
src/lib/{taxonomy,techniques,highlight,url}.ts   shared vocabulary + pure logic
src/styles, src/components, src/fonts             design system (cloned from the cheatsheet)

Routing is by toolId namespace (gtfo:/lolbas:/wadcoms:/daemon:), so a tool always resolves to one page even when a family mixes upstream and DÆMON-authored techniques; a per-technique NEW badge conveys authorship.

Impacket is a suite, not one tool, so its ~48 WADComs techniques are split back out by their actual examples/<script>.py — one page per script (Impacket-secretsdump, Impacket-ntlmrelayx, …). Case-duplicate WADComs families (e.g. Enum4Linux / enum4linux) are folded onto one canonical page so the static router never silently drops a tool. Both normalisations live in scripts/wadcoms-normalize.mjs and are applied by npm run data and the one-shot scripts/split-impacket.mjs.

🩵 Develop

npm install
npm run data     # regenerate the dataset from vendor/ + committed source snapshots
npm run dev      # local dev server
npm run build    # astro build + pagefind index → dist/
npm run preview  # serve the production build

npm run build (what CI runs) only consumes the committed src/data/techniques.json; it never re-runs ingestion, so there is no cross-repo dependency at deploy time.

💛 Regenerating the dataset

npm run data reads the vendored upstreams, the committed authored snapshots in src/data/sources/, and src/data/catalog-additions.json. It normalizes everything to the unified Technique model, validates every record with Zod (failing on any bad or duplicate record), and writes src/data/{techniques,tools,facets}.json plus public/data/techniques.json. Commit the result.

npm run data:enrich reapplies the metadata pass without re-reading upstreams. It normalizes access labels, execution contexts, environments, availability, evidence state, and compatibility notes, then rebuilds the indexes. The catalog's bookmarks, saved views, density, font size, line wrapping, and reduced-motion preference stay in the browser's local storage.

To refresh against the latest upstreams (submodule route):

git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms
npm run data

💜 Deploy

The site is a static build hosted on Vercel at the domain root — no base path. Import the GitHub repo as a Vercel project (framework preset: Astro) and it deploys on every push to main; vercel.json pins the build:

{
  "framework": "astro",
  "buildCommand": "npm run build",   // data:public + astro build + pagefind index
  "installCommand": "npm ci",
  "outputDirectory": "dist",
  "cleanUrls": true,
  "trailingSlash": false
}

npm run build runs Pagefind over dist/ and copies the index back into public/, so offline search ships with the static output — no adapter, no serverless functions. Set the production origin in one place — SITE in astro.config.mjs (used for the sitemap, canonical URLs and Open Graph) — to the project's real Vercel domain (custom domain, or the default *.vercel.app URL).

Web Analytics / Speed Insights are wired in src/layouts/Base.astro (production only, cookieless, zero-dependency) and light up once you enable them under the Vercel project's Analytics / Speed Insights tabs.

Because there is no base path, src/lib/url.ts's url() helper is a passthrough (it only guarantees a leading slash); if the site is ever moved back under a sub-path, set base in astro.config.mjs and every internal link already routes through url().

❤️ Scope

For authorized testing, CTFs, detection engineering and education only. Know your scope; get permission first.


☧ DΛΣMӨП//SEC · built with Astro + Pagefind · themed with Rosé Pine · GPL-3.0 ❀