
ThreatResearch
Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Python config extractors for malware families including PlugX, Remcos, templateX, and RedLine Stealer, supporting C2 configuration extraction for…

Static config extractor for SmokeLoader samples that deobfuscates, unpacks, and emulates protected routines to recover final-stage C2 settings.

Config extractor for AgentTesla - Discord/Telegram Variant

Config Extractor for Asyncrat/Dcrat/VenomRat

An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general…

Contains a simple yara rule to hunt for possible compromised KeePass config files

Python parser for extracting CobaltStrike Beacon configurations from PE files, memory dumps, and C2 URLs using heuristic XOR decryption and…

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

A monthly Windows PE baseline dataset for Cyber security researchers

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

Code developed to steal certain browser config files (history, preferences, etc)

Scans a list of raccoon servers from Tria.ge and extracts the config

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…