h?ckers a[r]e gl*bbing

h?ckers a[r]e gl*bbing

🎙 John Hammond 👥 2.2M 📅 February 27, 2026 ⏱ 16 min 👁 32K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

wildcardobfuscationLOLGlobsPowerShellEDR evasion

Summary

In this video, John Hammond showcases a new open-source project called LOLGlobs, which catalogs wildcard-based command obfuscation techniques for various operating systems and shells. He explains the concept of living off the land (LOL) and how attackers use native tools to evade detection. The video demonstrates how to use wildcards like asterisks and question marks to obfuscate commands, breaking literal string-based detection. Hammond walks through examples for Windows CMD and PowerShell, showing how to hide the execution of commands like Invoke-WebRequest and Invoke-Expression. He also introduces PolyUploader, a tool for uploading files to multiple hosting sites, and URL shorteners like is.gd to obscure payload URLs. The video includes a sponsored segment for Exaforce, an AI-powered security operations center. Hammond emphasizes the value of such resources for both defenders and attackers, and encourages community contribution to the project.

137 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, actionable information for cybersecurity professionals, especially those interested in red teaming and detection evasion. The demonstration of LOLGlobs is clear and practical, showing real-world applications. The argumentation is solid, backed by references to established projects like LOLBAS and GTFOBins. Hammond also highlights the potential for AI to leverage such catalogs for improved detection, adding a forward-looking perspective. The inclusion of PolyUploader and URL shorteners adds practical value for staging attacks. However, the video does not deeply analyze the effectiveness of these techniques against modern EDRs, and the sponsor segment, while clearly marked, interrupts the flow.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous in its presentation of the LOLGlobs project, with direct links to the GitHub repository and related resources in the description. The title is cleverly aligned with the content, using wildcard characters to reflect the theme. The sources cited are credible and well-known within the cybersecurity community. The video does not provide independent verification of the tool’s claims, but it is transparent about the project’s open-source nature and encourages community review. The sponsor segment is clearly identified and does not compromise the technical content.

202 words

Title / Content Match

The title is a playful obfuscation itself, using wildcards and character substitution, which perfectly matches the video's focus on wildcard-based obfuscation.

Quality & Reliability

8/10

The video is a practical demonstration of a new open-source tool (LOLGlobs) for command obfuscation, presented by a well-known cybersecurity educator. The content is technically accurate, with clear explanations and live demonstrations. The tool is documented and available on GitHub, and the video references established resources like LOLBAS and GTFOBins. The main limitation is the lack of independent verification of the tool's effectiveness against modern EDRs, and the promotional segment for the sponsor.

Key Moments

Cited Sources

  • LOLGlobs GitHub Repository — The main project showcased in the video, a catalog of wildcard-based obfuscation techniques.
  • LOLGlobs Website — The web interface for the LOLGlobs project.
  • Argfuscator — A related tool for obfuscating command-line arguments, mentioned as an inspiration.
  • LOLBAS Project — Living Off The Land Binaries and Scripts, a key reference for LOL techniques.
  • GTFOBins — A curated list of Unix binaries that can be used to bypass local security restrictions.
  • LOLRMM — Living Off The Land Remote Monitoring and Management tools.
  • LOLDrivers — A project documenting vulnerable drivers that can be exploited.
  • LOLOL.Farm — A resource aggregating various LOL projects.
  • LOTS Project — Living Off Trusted Sites, a list of trusted domains that can be abused.
  • PolyUploader — A tool for uploading files to multiple hosting sites, mentioned for staging payloads.
  • John Hammond's Video on Argfuscator — A previous video by the same creator on a related obfuscation tool.

Concurring Sources

  • LOLBAS Project — Supports the concept of living off the land binaries, which LOLGlobs extends.
  • GTFOBins — Similar resource for Unix binaries, aligning with the LOL philosophy.

External References

Contribution & Novelties

The video introduces LOLGlobs, a novel open-source resource that systematically catalogs wildcard-based obfuscation techniques for command execution across multiple platforms. This fills a gap in the existing LOL ecosystem, which focuses on binaries and scripts but not specifically on wildcard patterns. The demonstration provides practical examples of how these techniques can evade string-based detection, and the integration with tools like PolyUploader and URL shorteners shows a complete attack chain. The video also suggests potential applications for AI in leveraging such catalogs for improved detection.

Pour aller plus loin :

120 words

Radar Profile

The radar profile shows high scores in quality and reliability, with moderate scores in quantity and technical depth. This indicates a well-produced, informative video that is accessible to a broad audience but may not delve into the most advanced technical details. The balance suggests a strong educational resource for those new to command obfuscation.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être dégagée.