Observed arrival · 2026-09-22
LOLPulse, a Decoder Ring for Suspicious Commands
A browser-based security engine that analyzes LOLBin command lines, maps them to MITRE ATT&CK, and generates KQL, Sigma, and Splunk detections.
- For
- SOC analysts and detection engineers
- Worth noticing
- The analyzer outputs KQL, Sigma, and Splunk formats and shows expected parent-to-child process lineage.
Field notes
The public interface combines a searchable LOLBin directory with an interactive command-line analyzer. Its example traces certutil.exe from a cmd.exe parent to a staged payload, identifies T1105, and breaks down suspicious switches such as -urlcache and -split. The page also organizes entries by attack objectives including Download, Execute, UAC Bypass, and Defense Evasion. It presents the heuristic engine as version 1.0 and states that parsing occurs client-side.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue