kevthehermit/RATDecoders
Python Decoders for Common Remote Access Trojans observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4540
- days_rel: n/a
- days_push: 778
- n_releases_24m: 0
Adoption not part of the score
1120 stars · 306 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Python library and CLI tool (malconf) that statically analyzes malware samples from common Remote Access Trojan (RAT) families and extracts their embedded configuration data. It supports dozens of RAT families like DarkComet, njRat, and NanoCore, and can be embedded in automated malware analysis pipelines.
Use cases
- extract configuration from a malware sample
- identify which RAT family a binary belongs to
- parse C2 server addresses from malware configs
- integrate malware config extraction into an analysis pipeline
- bulk analyze a directory of malware samples
- support incident response with malware configuration data
When to choose
- you need to statically extract configs from known RAT families
- you are an incident responder or malware analyst handling common RATs
- you want a pip-installable library for automated malware triage
When to avoid
- you need dynamic malware analysis or sandboxing
- the malware family is not in the supported RAT list
- you need general-purpose reverse engineering rather than config extraction
Facets
library · maturity maintenance
parser security developer-tools cli security reverse-engineering developer-tools python cli cross-platform malware-analysis malware-configuration-extraction remote-access-trojans incident-response yara threat-intelligence
1 source
- readme: https://github.com/kevthehermit/RATDecoders · fetched 2026-08-28 · 92df300f2b54
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| kevthehermit/RATDecoders | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="kevthehermit/RATDecoders")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem