Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
hedgehog-tools — Collection of scripts for malware analysis, deobfuscation, and configuration extraction. Supports static analysis, unpacking, shellcode conversion, and C2 extraction for malware families like AgentTesla, Qakbot, and CobaltStrike. | Kitploit
Tools/GitHubGitHub/struppigel/hedgehog-tools
Static AnalysisDynamic Analysis (Sandboxing)Reverse EngineeringShellcodeForensicsMalware AnalysisBinary Analysis
GitHubstruppigel/hedgehog-tools

hedgehog-tools

Collection of scripts for malware analysis, deobfuscation, and configuration extraction. Supports static analysis, unpacking, shellcode conversion, and C2 extraction for malware families like AgentTesla, Qakbot, and CobaltStrike.

View Repository
1421322 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

hedgehog-tools

Repo of smaller scripts for malware analysis, deobfuscation and configuration extraction.

See README.md files within the folders for more details.

Overview of generic tools

FolderScriptDependsStaticPurpose
ECMAScript helpersextract_called_functions.jsNodeJS✅JavaScript deobfuscation. Recursively extracts all called functions based on a given start function
ECMAScript helpersrename_identifiers.jsNodeJS✅JavaScript deobfuscation. Renames all identifiers to ren_<number>
Ghidra scriptsPropagateExternalParametersX64.javaJava✅x64 variant of Ghidra-provided 32-bit PropagateExternalParameters script
Ghidra scriptsmove_callers_to_malware_namespace.pyJython✅Moves all caller functions into malware:: namespace
ktracektrace/ktrace.pyPython✅kernel mode driver emulator and tracer
Nuitkanuitka_extractor.pyPython✅Extracts Nuitka onefile executables
PKGpkg_vfs_extract.pyPython✅Extracts and inspects embedded Virtual Filesystems from vercel/pkg binaries
Python helper scriptsextract_export_symbols.pyPython✅Obtains a list of symbols for all exported functions of a DLL
Python helper scriptsmonitor_and_dump_changed_files.pyPython⛔Monitors changes within a given folder and dumps the changed files
PyInstaller modpyinstaller-mod-extractor-ng.pyPython✅Extracts PyInstaller files that use a custom stub and custom encryption
Quick Batch File Compilerqbfc_extract.pyPython✅Extracts Quick Batch File Compiler files
RenPyrpa_extractor.pyPython✅Extracts RenPy archives (.rpa, .rpi)
Shellcode2PEshellcode_to_pe.pyPython✅Converts raw shellcode into a PE file with shellcode as entry point

Overview of family based deobfuscators

TargetDependsStaticConfig extractionC2 extractionDeobfuscationUnpackingHandles packed sample
AgentTesla (OriginLogger)Python, dnlib✅✅✅⛔⛔⛔
AllComePython✅✅✅⛔⛔⛔
BadSpaceIDAPython (IDA 8), HexRays decompiler✅⛔⛔✅⛔⛔
BeamNG Mod MalwareGhidra, Jython✅⛔⛔✅⛔⛔
BrowserFixer.NET C#⛔⛔⛔✅⛔⛔
CobaltStrikePython, Ghidra, Jython✅⛔⛔✅⛔⛔
DaveIDAPython (IDA 9)✅⛔⛔✅⛔⛔
EvilConwiPython✅✅⛔⛔⛔⛔
GootLoaderJavaScript, NodeJS✅✅✅✅✅✅
HijackLoaderPython✅✅⛔✅✅✅
LimeRATPython, dnlib✅✅✅⛔⛔⛔
LummaStealerGhidra, Jython✅⛔⛔✅⛔⛔
NightHawkIDAPython (IDA 8)✅⛔⛔✅⛔✅
PEUnionPython, Speakeasy✅⛔⛔⛔✅✅
PrivateLoaderIDAPython (IDA 8)✅⛔⛔✅⛔⛔
QakbotPython✅✅✅

Licensing

Unless stated otherwise, tools in this repository are licensed under the MIT License (see LICENSE).

Some tools are derived from GPLv3 projects and therefore remain licensed under GPLv3+. These tools contain their own LICENSE files and headers.

Download Tool
✅
⛔
⛔
RokRATPython, Ghidra, Jython✅⛔⛔✅⛔✅
VirutPython, Ghidra, Jython✅⛔⛔✅⛔✅
XWormRATPython, dnlib✅✅✅⛔⛔⛔