extracting-config-from-agent-tesla-rat

mukul975/extracting-config-from-agent-tesla-rat · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.

SKILL.md

Files

This skill is a package of 7 files. Install with the command above, or download the folder.

Related

  1. malware-analysis · zhaoxuya520 bundle
    Analyze suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior detection.
    12.8k
    repo stars
  2. implementing-diamond-model-analysis · mukul975 bundle
    Provides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
    24.6k
    repo stars
  3. extracting-memory-artifacts-with-rekall · mukul975 bundle
    Analyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
    24.6k
    repo stars
  4. performing-malware-ioc-extraction · mukul975 bundle
    Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
    24.6k
    repo stars
  5. reverse-engineering-dotnet-malware-with-dnspy · mukul975 bundle
    Analyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.
    24.6k
    repo stars
  6. analyzing-malicious-pdf-with-peepdf · mukul975 bundle
    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
    24.6k
    repo stars

Frequently asked questions

How do I install the extracting-config-from-agent-tesla-rat skill?

Run npx skillmds add mukul975/extracting-config-from-agent-tesla-rat in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the extracting-config-from-agent-tesla-rat skill do?

Extract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis. It is listed under Security, AI & ML, Data & Analytics, Incident Response, Penetration Testing on SkillMD.

Is extracting-config-from-agent-tesla-rat safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with extracting-config-from-agent-tesla-rat?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is extracting-config-from-agent-tesla-rat free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published extracting-config-from-agent-tesla-rat?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.