About the lab

Turn a nasty file into readable evidence.

KittyVex is a static malware inspection workspace. Samples are treated as hostile data: unpacked when supported, string-scanned, scored, and never launched. Discord and Telegram bot tokens are extracted for identification only.

What she peels first

Discord webhooks, bot tokens, Telegram C2, wallets, tunnels, browser credential paths, PE imports, packer hints (PyInstaller, Nuitka, cx_Freeze, py2exe, AutoIt, .NET), and named families from stealers and RATs.

Identity lookups

Webhook and bot checks are read-only. KittyVex does not post to Discord or Telegram. Hash reputation is skipped on the live scan path so the report returns quickly.

Know the boundary

This is triage, not a courtroom. Use a sandbox before you call something clean. Optional lock: KITTYVEX_ACCESS_KEY. Rate limit: 10 scans / 15 minutes / IP.