About the Researcher & LOLPulse Lab
LOLPulse is an independent, practitioner-driven detection engineering research initiative dedicated to demystifying Living-off-the-Land Binaries, scripts, and libraries (LOLBins/LOLBAS) and arming SOC teams with verified, high-fidelity detection logic.

Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Founder & Lead Researcher • Check Point
Cybersecurity researcher, detection engineer, and Check Point malware analyst specializing in Living-off-the-Land Binaries (LOLBins) tradecraft, OS telemetry analysis (Windows Event Logs, Sysmon, auditd), LLM threat intelligence, and automated SIEM detection rules (KQL, Sigma, Splunk).
As a cybersecurity researcher and Check Point malware analyst, Sharon has investigated adversary tactics ranging from weaponized document exploits to generative AI threat modeling. Sharon built LOLPulse to bridge the gap between static adversary reference repos and modern automated SOC workflows. Every command line breakdown, telemetry signature, and mitigation rule on this site is curated and reviewed to ensure zero false-positive fatigue and immediate operational utility.
Published Cybersecurity Research & Industry Contributions
Check Point ResearchAlongside ongoing security research at Check Point, Sharon has authored and co-authored landmark threat research investigations at Check Point Research, exposing emerging adversary tactics in artificial intelligence weaponization and malicious document exploitation.
OpwnAI: AI That Can Save the Day or HACK it Away
One of the industry's earliest and most influential research publications exploring the dual-use cyber implications of OpenAI's ChatGPT. The study systematically demonstrated how LLMs lower the barrier to entry for adversaries across the entire cyber kill chain—generating targeted spear-phishing lures, weaponized VBA scripts, and polymorphic malware payloads—while also pioneering defensive applications for threat hunting and code auditing.
The Weaponization of PDFs: 68% of Cyber attacks begin in your inbox, with 22% of these hiding in PDFs
An authoritative investigation analyzing real-world threat telemetry to dissect why PDF files remain the primary delivery vector for stealthy cyber intrusions. The research deconstructs sophisticated evasion techniques—including malicious JavaScript obfuscation, embedded multi-stream payloads, font format parsing exploits, and reader-specific quirks—designed to bypass secure email gateways.
Telemetry & Rule Verification Methodology
How LOLPulse tests, verifies, and publishes LOLBin attack patterns and SIEM detection rules.
1. Multi-OS Lab Execution
Commands are safely detonated inside isolated virtual lab environments across modern operating systems: Windows 11 Enterprise (23H2/24H2), Windows Server 2025, Ubuntu/Debian Linux, and macOS Sequoia.
2. Deep Telemetry Extraction
We extract event logs from Sysmon (Event ID 1, 3, 7, 8, 11), Windows Security Event 4688 with full command-line auditing, PowerShell ScriptBlock (4104), Linux auditd EXECVE, and macOS Endpoint Security Framework.
3. Tri-Format Rule Authoring
Every identified attack vector is translated into verified Microsoft Defender/Sentinel KQL, vendor-neutral Sigma YAML (v2 spec), and Splunk SPL queries, formatted for instant copy-paste deployment.
Community Attribution & Upstream Alignment
LOLPulse honors and builds upon pioneering open-source community knowledge bases:
- LOLBAS Project: Windows binary tradecraft reference
- GTFOBins: Unix/Linux binaries with SUID/sudo capabilities
- LOOBins: macOS living-off-the-orchard research
- MITRE ATT&CK®: Global adversary tactics & technique taxonomy
When using the LOLPulse interactive command line analyzer, all parsing, deobfuscation, and query generation logic executes 100% locally within your browser. No alert strings, sensitive hostnames, usernames, or telemetry data are ever transmitted to external servers. All information published on LOLPulse is strictly intended for defensive detection engineering, threat hunting, and educational triage.
Explore the Verified Knowledge Base
Browse 259 weaponized binaries or triage command lines in real time.