About the lab
Turn a nasty file into readable evidence.
KittyVex is a static malware inspection workspace. Samples are treated as hostile data: unpacked when supported, string-scanned, scored, and never launched. Discord and Telegram bot tokens are extracted for identification only.
What she peels first
Discord webhooks, bot tokens, Telegram C2, wallets, tunnels, browser credential paths, PE imports, packer hints (PyInstaller, Nuitka, cx_Freeze, py2exe, AutoIt, .NET), and named families from stealers and RATs.
Identity lookups
Webhook and bot checks are read-only. KittyVex does not post to Discord or Telegram. Hash reputation is skipped on the live scan path so the report returns quickly.
Know the boundary
This is triage, not a courtroom. Use a sandbox before you call something clean. Optional lock: KITTYVEX_ACCESS_KEY. Rate limit: 10 scans / 15 minutes / IP.