☧ DÆMONBins
the Off-the-Land Almanac
https://daemon-sec-lotl.vercel.app/
https://daemon-404.github.io/daemon-sec-lotl/
GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, and extended into one filterable catalog.
A static Astro site with Pagefind search, in the visual language of daemon-sec.xyz. Every living-off-the-land and offensive technique from four public references is flattened to one filterable atom — a Technique — and filterable by platform, capability, source, execution context, required access, service, environment, availability, and evidence state. The catalog supports grouped variants, saved commands, configurable templates, shareable URL state, and a compact details inspector. Per-tool pages group a binary's techniques.
All four upstreams are GPL-3.0, so this combined work is GPL-3.0. See
THIRD_PARTY_NOTICES.md and LICENSE.
❀ The five collections
| Deck | Source | Techniques | What it is |
|---|---|---|---|
| 🩵 GTFOBins | acd5246 |
2,125 | Unix binaries abused for shell, file r/w, and SUID / sudo / capabilities privesc |
| 💜 LOLBAS | 7aca936 |
481 | Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass |
| 💛 WADComs | a864cd1 |
100 | Offensive Windows / Active Directory tooling, indexed by what access you hold |
| 🩷 LOOBins | 399e3c4 |
183 | macOS binaries and documented use cases |
| ❤️ DÆMON | authored | 196 | 134 fact-checked WADComs additions + 17 documented command references, badged DÆMON |
| Total | 3,085 | 907 tools · all Zod-validated |
Everything is placeholder-only reference material (lab IPs, test.local, john / password123)
in the spirit of GTFOBins, LOLBAS, WADComs, LOOBins and MITRE ATT&CK.
☧ Layout
vendor/{gtfobins,lolbas,wadcoms} the three upstreams (vendored; see setup-vendor.sh)
src/data/sources/loobins.json pinned LOOBins snapshot (183 use cases)
src/data/sources/wadcoms-additions.json committed authored WADComs snapshot
scripts/build-dataset.mjs local ingestion → src/data/*.json + public/data
scripts/wadcoms-normalize.mjs WADComs family fixes (Impacket split, case-fold)
scripts/split-impacket.mjs one-shot, idempotent migration of the committed data
src/data/techniques.json the canonical, committed dataset (a Technique[])
src/data/tools.json per-tool metadata (aliases, Full_Path, contributors)
src/data/facets.json derived facet indexes + counts + upstream commits
src/data/catalog-additions.json documented DÆMON command references
src/pages/ home · /catalog · /<deck> · /<deck>/<tool> · credits · 404
src/scripts/catalog.ts the vanilla-TS catalog workspace island
src/lib/{taxonomy,techniques,highlight,url}.ts shared vocabulary + pure logic
src/styles, src/components, src/fonts design system (cloned from the cheatsheet)
Routing is by toolId namespace (gtfo:/lolbas:/wadcoms:/daemon:), so a tool always
resolves to one page even when a family mixes upstream and DÆMON-authored techniques; a
per-technique NEW badge conveys authorship.
Impacket is a suite, not one tool, so its ~48 WADComs techniques are split back out by their
actual examples/<script>.py — one page per script (Impacket-secretsdump, Impacket-ntlmrelayx,
…). Case-duplicate WADComs families (e.g. Enum4Linux / enum4linux) are folded onto one canonical
page so the static router never silently drops a tool. Both normalisations live in
scripts/wadcoms-normalize.mjs and are applied by npm run data and the one-shot
scripts/split-impacket.mjs.
🩵 Develop
npm install
npm run data # regenerate the dataset from vendor/ + committed source snapshots
npm run dev # local dev server
npm run build # astro build + pagefind index → dist/
npm run preview # serve the production build
npm run build (what CI runs) only consumes the committed src/data/techniques.json; it never
re-runs ingestion, so there is no cross-repo dependency at deploy time.
💛 Regenerating the dataset
npm run data reads the vendored upstreams, the committed authored snapshots in
src/data/sources/, and src/data/catalog-additions.json. It normalizes everything to the unified Technique model,
validates every record with Zod (failing on any bad or duplicate record), and writes
src/data/{techniques,tools,facets}.json plus public/data/techniques.json. Commit the result.
npm run data:enrich reapplies the metadata pass without re-reading upstreams. It normalizes
access labels, execution contexts, environments, availability, evidence state, and compatibility
notes, then rebuilds the indexes. The catalog's bookmarks, saved views, density, font size, line
wrapping, and reduced-motion preference stay in the browser's local storage.
To refresh against the latest upstreams (submodule route):
git submodule update --remote vendor/gtfobins vendor/lolbas vendor/wadcoms
npm run data
💜 Deploy
The site is a static build hosted on Vercel at the domain root — no base
path. Import the GitHub repo as a Vercel project (framework preset: Astro) and it deploys on
every push to main; vercel.json pins the build:
{
"framework": "astro",
"buildCommand": "npm run build", // data:public + astro build + pagefind index
"installCommand": "npm ci",
"outputDirectory": "dist",
"cleanUrls": true,
"trailingSlash": false
}
npm run build runs Pagefind over dist/ and copies the index back into public/, so offline
search ships with the static output — no adapter, no serverless functions. Set the production origin
in one place — SITE in astro.config.mjs (used for the sitemap, canonical URLs and Open Graph) —
to the project's real Vercel domain (custom domain, or the default *.vercel.app URL).
Web Analytics / Speed Insights are wired in src/layouts/Base.astro (production only, cookieless,
zero-dependency) and light up once you enable them under the Vercel project's Analytics /
Speed Insights tabs.
Because there is no base path, src/lib/url.ts's url() helper is a passthrough (it only guarantees
a leading slash); if the site is ever moved back under a sub-path, set base in astro.config.mjs
and every internal link already routes through url().
❤️ Scope
For authorized testing, CTFs, detection engineering and education only. Know your scope; get permission first.
☧ DΛΣMӨП//SEC · built with Astro + Pagefind · themed with Rosé Pine · GPL-3.0 ❀