Security & Data Transparency

Privacy Policy

At LOLPulse, we believe cybersecurity research tools must honor the operational sensitivity of threat hunting data. This policy outlines how we treat information when you browse our catalog or triage command lines.

Effective Date: January 1, 2026Last Updated: September 20, 2026

Zero Command Telemetry Harvesting

Analyst Confidentiality by Architecture

When you paste command lines, scripts, or parameter flags into the LOLPulse Live Interactive Triage Analyzer, processing is executed in-memory within your client browser using pure TypeScript heuristics. We do not save, store, log, harvest, or transmit your analyzed commands to any database or external third party. Internal IP addresses, usernames, paths, and proprietary strings present in your triage queries remain confidential to your local session.

1. Information We Collect

LOLPulse collects minimal technical data necessary to deliver high-availability access and understand aggregate usage trends:

  • Aggregated Web Analytics: We use Google Analytics 4 (GA4) with IP anonymization enabled to collect anonymized usage metrics such as pages viewed, general geographic region (country-level), browser type, referring domains, and duration on site.
  • Standard Server Logs: Edge hosting infrastructure (such as Vercel) automatically logs standard HTTP request headers, response codes, timestamp, and anonymized client IP addresses to maintain security, mitigate DDoS attacks, and diagnose infrastructure health.
  • Voluntary Communications: If you contact our research team or lead curator via email or LinkedIn, we receive the information you provide (such as your name, email address, and inquiry details) solely to respond to your request.

2. Cookies & Local Client Storage

We do not use intrusive tracking cookies, advertising identifiers, or cross-site fingerprinting technologies. The small data items stored on your device include:

UI Theme Preference

Stored via localStorage under the key theme to remember your Dark / Light mode preference across visits without transmitting data to any server.

Analytics Cookies

First-party GA4 performance cookies (e.g. _ga) that record aggregated visitor counts to help us allocate bandwidth and prioritize new LOLBin documentation.

3. How We Use Collected Information

Collected technical information is used exclusively to:

  • Ensure the stability, availability, and performance of the LOLPulse static catalog and dynamic rule rendering.
  • Detect, prevent, and mitigate malicious bot traffic, automated scraping, or denial-of-service attempts.
  • Analyze aggregate usage patterns (such as popular operating systems or SIEM formats) to prioritize new detection engineering templates (e.g., KQL, Sigma, Splunk SPL).

We will never sell, rent, monetize, or broker your personal information or telemetry to third parties, advertisers, or data aggregators.

4. Third-Party Links & Upstream References

LOLPulse contains contextual outbound links to external cybersecurity repositories, standards bodies, and research papers, including:

  • The MITRE ATT&CK® knowledge base (attack.mitre.org)
  • Upstream community projects: LOLBAS, GTFOBins, LOOBins, and SigmaHQ
  • Check Point Research publications and academic archives
  • Professional profile links (LinkedIn, GitHub)

We have no control over the privacy practices or content of external third-party websites. We encourage you to review their respective privacy policies when visiting external destinations.

5. Your Rights Under GDPR & CCPA

Depending on your jurisdiction (such as the European Economic Area under GDPR or California under the CCPA/CPRA), you may have statutory rights regarding your personal data:

  • The right to know what personal data is processed or collected.
  • The right to request deletion of personal information you have provided to us.
  • The right to opt-out of cookie tracking via your browser's “Do Not Track” (DNT) header or Global Privacy Control (GPC).

Because we do not maintain persistent user profiles, accounts, or command histories, we generally retain no personally identifiable user records that can be linked to an individual analyst.

6. Data Controller & Contact Channels

LOLPulse is curated by Sharon Ben Moshe (Cybersecurity Researcher & Detection Engineer). For any privacy inquiries, questions regarding our telemetry handling, or compliance requests, please reach out via:

LOLPulse Research & Detection Engineering Lab
Curator: Sharon Ben Moshe
Support & Compliance Email: support@lolpulse.dev
LOLPulse Privacy Governance