Ross ROSS = Recommend OSS · open-source software intelligence for agents

kevthehermit/RATDecoders

Python Decoders for Common Remote Access Trojans observed · 2026-08-28

github.com/kevthehermit/RATDecoders · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4540
  • days_rel: n/a
  • days_push: 778
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1120 stars · 306 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Python library and CLI tool (malconf) that statically analyzes malware samples from common Remote Access Trojan (RAT) families and extracts their embedded configuration data. It supports dozens of RAT families like DarkComet, njRat, and NanoCore, and can be embedded in automated malware analysis pipelines.

Use cases

  • extract configuration from a malware sample
  • identify which RAT family a binary belongs to
  • parse C2 server addresses from malware configs
  • integrate malware config extraction into an analysis pipeline
  • bulk analyze a directory of malware samples
  • support incident response with malware configuration data

When to choose

  • you need to statically extract configs from known RAT families
  • you are an incident responder or malware analyst handling common RATs
  • you want a pip-installable library for automated malware triage

When to avoid

  • you need dynamic malware analysis or sandboxing
  • the malware family is not in the supported RAT list
  • you need general-purpose reverse engineering rather than config extraction

Facets

library · maturity maintenance

parser security developer-tools cli security reverse-engineering developer-tools python cli cross-platform malware-analysis malware-configuration-extraction remote-access-trojans incident-response yara threat-intelligence

1 source

Member repositories

RepositoryRoleHealth v2
kevthehermit/RATDecodersmain32

For agents

markdown · JSON · MCP: product_card(name="kevthehermit/RATDecoders")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem