E-E-A-T Research & Engineering Standards

About the Researcher & LOLPulse Lab

LOLPulse is an independent, practitioner-driven detection engineering research initiative dedicated to demystifying Living-off-the-Land Binaries, scripts, and libraries (LOLBins/LOLBAS) and arming SOC teams with verified, high-fidelity detection logic.

Sharon Ben Moshe

Sharon Ben Moshe

Cybersecurity Researcher & Detection Engineer • Founder & Lead Researcher • Check Point

Connect on LinkedIn

Cybersecurity researcher, detection engineer, and Check Point malware analyst specializing in Living-off-the-Land Binaries (LOLBins) tradecraft, OS telemetry analysis (Windows Event Logs, Sysmon, auditd), LLM threat intelligence, and automated SIEM detection rules (KQL, Sigma, Splunk).

As a cybersecurity researcher and Check Point malware analyst, Sharon has investigated adversary tactics ranging from weaponized document exploits to generative AI threat modeling. Sharon built LOLPulse to bridge the gap between static adversary reference repos and modern automated SOC workflows. Every command line breakdown, telemetry signature, and mitigation rule on this site is curated and reviewed to ensure zero false-positive fatigue and immediate operational utility.

Living-off-the-Land (LOLBAS)Malware AnalysisLLM Threat IntelligenceMITRE ATT&CK MatrixSysmon TelemetryYara RulesThreat Hunting & Triage

Published Cybersecurity Research & Industry Contributions

Check Point Research

Alongside ongoing security research at Check Point, Sharon has authored and co-authored landmark threat research investigations at Check Point Research, exposing emerging adversary tactics in artificial intelligence weaponization and malicious document exploitation.

AI Threat IntelligenceDecember 2022

OpwnAI: AI That Can Save the Day or HACK it Away

Check Point Research • Sharon Ben-Moshe, Gil Gekker, Golan Cohen

One of the industry's earliest and most influential research publications exploring the dual-use cyber implications of OpenAI's ChatGPT. The study systematically demonstrated how LLMs lower the barrier to entry for adversaries across the entire cyber kill chain—generating targeted spear-phishing lures, weaponized VBA scripts, and polymorphic malware payloads—while also pioneering defensive applications for threat hunting and code auditing.

Demonstrated end-to-end execution of automated cyber attacks using LLMs
Reverse engineered evasive code samples created through natural language
Identified dual-use defensive security automation paradigms
LLM WeaponizationCyber Kill ChainChatGPT SecurityDefensive AI
Read Full Research on Check Point
Malware AnalysisApril 2025

The Weaponization of PDFs: 68% of Cyber attacks begin in your inbox, with 22% of these hiding in PDFs

Check Point Research • Elad Paz (Team Leader, R&D) & Sharon Ben Moshe (Malware Analyst)

An authoritative investigation analyzing real-world threat telemetry to dissect why PDF files remain the primary delivery vector for stealthy cyber intrusions. The research deconstructs sophisticated evasion techniques—including malicious JavaScript obfuscation, embedded multi-stream payloads, font format parsing exploits, and reader-specific quirks—designed to bypass secure email gateways.

Telemetry breakdown of over 400 billion opened PDFs and inbox threat delivery
Deconstructed malicious PDF streams, JavaScript actions, and evasion mechanics
Established telemetry models informing behavioral endpoint detection
Malware AnalysisDocument WeaponizationPDF ExploitsInbox Threat Vectors
Read Full Research on Check Point

Telemetry & Rule Verification Methodology

How LOLPulse tests, verifies, and publishes LOLBin attack patterns and SIEM detection rules.

1. Multi-OS Lab Execution

Commands are safely detonated inside isolated virtual lab environments across modern operating systems: Windows 11 Enterprise (23H2/24H2), Windows Server 2025, Ubuntu/Debian Linux, and macOS Sequoia.

2. Deep Telemetry Extraction

We extract event logs from Sysmon (Event ID 1, 3, 7, 8, 11), Windows Security Event 4688 with full command-line auditing, PowerShell ScriptBlock (4104), Linux auditd EXECVE, and macOS Endpoint Security Framework.

3. Tri-Format Rule Authoring

Every identified attack vector is translated into verified Microsoft Defender/Sentinel KQL, vendor-neutral Sigma YAML (v2 spec), and Splunk SPL queries, formatted for instant copy-paste deployment.

Community Attribution & Upstream Alignment

LOLPulse honors and builds upon pioneering open-source community knowledge bases:

  • LOLBAS Project: Windows binary tradecraft reference
  • GTFOBins: Unix/Linux binaries with SUID/sudo capabilities
  • LOOBins: macOS living-off-the-orchard research
  • MITRE ATT&CK®: Global adversary tactics & technique taxonomy
Client Privacy & Ethical Commitment

When using the LOLPulse interactive command line analyzer, all parsing, deobfuscation, and query generation logic executes 100% locally within your browser. No alert strings, sensitive hostnames, usernames, or telemetry data are ever transmitted to external servers. All information published on LOLPulse is strictly intended for defensive detection engineering, threat hunting, and educational triage.

Explore the Verified Knowledge Base

Browse 259 weaponized binaries or triage command lines in real time.