
pip3line
The Swiss army knife of byte manipulation

The Swiss army knife of byte manipulation

Decodes PlugX traffic and encrypted/compressed artifacts

Wireshark plugin for dissecting the Telegram protocol

Hive v5 file decryption algorithm

Extracts and decrypts malware configuration data from captured samples, automating C2 endpoint discovery, credential extraction, and indicator triage…

Simple decrypter for Java AdWind, jRAT, jBifrost trojan

Lightweight Go-based reverse shell management server with a web GUI for interactive shell sessions, session management, and multi-tab terminal…

phpstudy dll backdoor for v2016 and v2018

CVE-2026-43813: CloudAttestation enforceEnvironment bypass


Lua-based Wireshark postdissector that decrypts and parses Ubiquiti AirMAX/RouterBoard 802.11 vendor IEs into filterable fields.

IDA python scripts to decrypt strings from KPOT and set those as comments

CVE-2020-27688

Bypass for Symantec Endpoint Protection's Client User Interface Password

Generates unique polymorphic decryption code for encrypting data, using randomly selected instructions and keys, with junk opcode generation. Written…

HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.

Talos Decryptor POC for Remcos RAT version 2.0.5 and earlier