
netwatch
Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

A monthly Windows PE baseline dataset for Cyber security researchers

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general…

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Config extractor for AgentTesla - Discord/Telegram Variant

Config Extractor for Asyncrat/Dcrat/VenomRat

Scans a list of raccoon servers from Tria.ge and extracts the config

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

Code developed to steal certain browser config files (history, preferences, etc)