Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
donut-decryptor — Extracts and decrypts inner payloads from Donut obfuscator samples by detecting loader shellcode signatures, parsing the DONUT_INSTANCE structure, and dumping DONUT_MODULE data. | Kitploit
Tools/GitHubGitHub/volexity/donut-decryptor
Defensive ToolsStatic AnalysisEncryption/Decryption ToolsReverse EngineeringMalware AnalysisDigital ForensicsBinary Analysis
GitHubvolexity/donut-decryptor

donut-decryptor

Extracts and decrypts inner payloads from Donut obfuscator samples by detecting loader shellcode signatures, parsing the DONUT_INSTANCE structure, and dumping DONUT_MODULE data.

View Repository
1411042 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

donut_decryptor

A configuration and module extractor for the donut binary obfuscator

Description

donut-decryptor checks file(s) for known signatures of the donut obfuscator's loader shellcode. If located, it will parse the shellcode to locate, decrypt, and extract the DONUT_INSTANCE structure embedded in the binary, and report pertinent configuration data. If a DONUT_MODULE is present in the binary it is decrypted and dumped to disk.

Installation

You can install donut-decryptor for usage by navigating to the root directory of the project and using pip:

cd /path/to/donut-decryptor
python -m pip install .

Following installation, a command-line script is available. For usage instructions use:

donut-decryptor --help

Development

This project uses Hatch for project management, Ruff for linting and formatting, and mypy for type checking.

Setup

Install Hatch:

pip install hatch

Running Tests

hatch run test
hatch run test-cov  # with coverage

Linting and Formatting

hatch run lint:style   # check style
hatch run lint:fmt     # format code and fix issues
hatch run lint:typing  # run mypy type checking
hatch run lint:all     # run all checks

Examples

The files present in the samples directory are 7z files password protected using the password infected, all of which contain donuts which can be decoded using this script.

TODO list

  • Update detection rules and instance parsing for alternative output formats:
    • Hex
    • C-String/Ruby
    • Python
    • C#
    • Powershell
  • Consider moving loader/instance mapping to a YAML configuration file.
Download Tool