
YARA_for_config_extraction
Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Scans a list of raccoon servers from Tria.ge and extracts the config

Config Extractor for Asyncrat/Dcrat/VenomRat

Config extractor for AgentTesla - Discord/Telegram Variant

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Contains a simple yara rule to hunt for possible compromised KeePass config files

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Code developed to steal certain browser config files (history, preferences, etc)

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general…

A monthly Windows PE baseline dataset for Cyber security researchers