Agent skill

Extracting Config From Agent Tesla Rat

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis.

Apache-2.0Auto-check passedSecurity

Install Extracting Config From Agent Tesla Rat

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-config-from-agent-tesla-rat -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills extracting-config-from-agent-tesla-rat --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/extracting-config-from-agent-tesla-rat .claude/skills/extracting-config-from-agent-tesla-rat && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
extracting-config-from-agent-tesla-rat
GitHub stars
34k
Token cost
~1.8k tokens
SKILL.md length
254 words
Files
7 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis.

  • Analyzing a suspected
  • SKILL.md covers Overview, When to Use, Prerequisites and Workflow, plus 2 more sections
  • Runs Python scripts from its folder
  • Confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence

What it does

Extracting Config From Agent Tesla Rat is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. Use when analyzing a suspected or confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence or incident response.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Transactional email, OSINT and Incident response. It works with Telegram and .NET. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Analyzing a suspected
  • Confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence
  • Incident response

Example prompts

  • “Use the extracting-config-from-agent-tesla-rat skill to extract embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram…”
  • “/extracting-config-from-agent-tesla-rat”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • splunk.com
    • blog.qualys.com
    • any.run
    • trustwave.com
    • malpedia.caad.fkie.fraunhofer.de

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Extracting Config From Agent Tesla Rat loads about 1.8k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 254 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 254 words, ~1,814 tokens.

Download SKILL.mdSave it as .claude/skills/extracting-config-from-agent-tesla-rat/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
extracting-config-from-agent-tesla-rat
description
Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. Use when analyzing a suspected or confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence or incident response.
domain
cybersecurity
subdomain
malware-analysis
tags
agent-tesla, rat, config-extraction, dotnet, malware-analysis, keylogger, credential-theft
version
1.0
author
mahipal
license
Apache-2.0
atlas_techniques
AML.T0024, AML.T0056, AML.T0086
nist_ai_rmf
GOVERN-1.1, MEASURE-2.7, MANAGE-3.1
nist_csf
DE.AE-02, RS.AN-03, ID.RA-01, DE.CM-01
mitre_attack
T1027, T1055, T1140, T1497, T1003

Extracting Config from Agent Tesla RAT

Overview

Agent Tesla is a .NET-based Remote Access Trojan (RAT) and keylogger that ranked among the top 10 malware variants in 2024, impacting 6.3% of corporate networks globally. It exfiltrates stolen credentials via SMTP email, FTP upload, Telegram bot API, or Discord webhooks. The malware configuration is embedded in the .NET assembly, typically obfuscated using string encryption, resource encryption, or custom loaders that decrypt and execute Agent Tesla in memory via .NET Reflection (fileless). Configuration extraction involves decompiling the .NET assembly with dnSpy or ILSpy, identifying the decryption routine for configuration strings, and extracting SMTP server addresses, credentials, FTP endpoints, Telegram bot tokens, and targeted applications.

When to Use

  • When performing authorized security testing that involves extracting config from agent tesla rat
  • When analyzing malware samples or attack artifacts in a controlled environment
  • When conducting red team exercises or penetration testing engagements
  • When building detection capabilities based on offensive technique understanding

Prerequisites

  • dnSpy or ILSpy for .NET decompilation
  • Python 3.9+ with dnlib or pythonnet for automated extraction
  • de4dot for .NET deobfuscation
  • Understanding of .NET IL code and Reflection
  • Sandbox for dynamic analysis (ANY.RUN, CAPE)

Workflow

Step 1: Deobfuscate and Extract Configuration
python
#!/usr/bin/env python3
"""Extract Agent Tesla RAT configuration from .NET assemblies."""
import re
import sys
import json
import base64
import hashlib
from pathlib import Path


def extract_strings_from_dotnet(filepath):
    """Extract readable strings from .NET binary for config analysis."""
    with open(filepath, 'rb') as f:
        data = f.read()

    # Extract US (User Strings) heap from .NET metadata
    strings = []

    # Look for common Agent Tesla config patterns
    patterns = {
        "smtp_server": re.compile(rb'smtp[\.\-][\w\.\-]+\.\w{2,}', re.I),
        "email": re.compile(rb'[\w\.\-]+@[\w\.\-]+\.\w{2,}'),
        "ftp_url": re.compile(rb'ftp://[\w\.\-:/]+', re.I),
        "telegram_token": re.compile(rb'\d{8,10}:[A-Za-z0-9_-]{35}'),
        "telegram_chat": re.compile(rb'(?:chat_id=|chatid[=:])[\-]?\d{5,15}', re.I),
        "discord_webhook": re.compile(rb'https://discord\.com/api/webhooks/\d+/[\w-]+'),
        "password": re.compile(rb'(?:pass(?:word)?|pwd)[=:]\s*[\w!@#$%^&*]{4,}', re.I),
        "port": re.compile(rb'(?:port|smtp_port)[=:]\s*\d{2,5}', re.I),
    }

    results = {}
    for name, pattern in patterns.items():
        matches = pattern.findall(data)
        if matches:
            results[name] = [m.decode('utf-8', errors='replace') for m in matches]

    # Extract Base64-encoded strings (common obfuscation)
    b64_pattern = re.compile(rb'[A-Za-z0-9+/]{20,}={0,2}')
    b64_decoded = []
    for match in b64_pattern.finditer(data):
        try:
            decoded = base64.b64decode(match.group())
            text = decoded.decode('utf-8', errors='strict')
            if text.isprintable() and len(text) > 5:
                b64_decoded.append(text)
        except Exception:
            pass

    if b64_decoded:
        results["base64_decoded_strings"] = b64_decoded[:30]

    return results


def decrypt_agenttesla_strings(data, key_hex):
    """Decrypt Agent Tesla encrypted configuration strings."""
    key = bytes.fromhex(key_hex)
    # Agent Tesla V1: Simple XOR with key
    decrypted_strings = []

    # Find encrypted blobs (high-entropy byte sequences)
    blob_pattern = re.compile(rb'[\x80-\xff]{16,256}')
    for match in blob_pattern.finditer(data):
        blob = match.group()
        # Try XOR decryption
        decrypted = bytes(b ^ key[i % len(key)] for i, b in enumerate(blob))
        try:
            text = decrypted.decode('utf-8', errors='strict')
            if text.isprintable() and len(text.strip()) > 3:
                decrypted_strings.append(text.strip())
        except UnicodeDecodeError:
            pass

    # V2: SHA256-based key derivation then AES
    sha256_key = hashlib.sha256(key).digest()

    return decrypted_strings


def analyze_exfiltration_config(config):
    """Analyze extracted configuration for exfiltration methods."""
    methods = []

    if config.get("smtp_server"):
        methods.append({
            "type": "SMTP",
            "servers": config["smtp_server"],
            "emails": config.get("email", []),
        })

    if config.get("ftp_url"):
        methods.append({
            "type": "FTP",
            "urls": config["ftp_url"],
        })

    if config.get("telegram_token"):
        methods.append({
            "type": "Telegram",
            "tokens": config["telegram_token"],
            "chat_ids": config.get("telegram_chat", []),
        })

    if config.get("discord_webhook"):
        methods.append({
            "type": "Discord",
            "webhooks": config["discord_webhook"],
        })

    return methods


if __name__ == "__main__":
    if len(sys.argv) < 2:
        print(f"Usage: {sys.argv[0]} <agent_tesla_sample>")
        sys.exit(1)

    config = extract_strings_from_dotnet(sys.argv[1])
    methods = analyze_exfiltration_config(config)

    report = {"raw_config": config, "exfiltration_methods": methods}
    print(json.dumps(report, indent=2))

Validation Criteria

  • Exfiltration method identified (SMTP/FTP/Telegram/Discord)
  • Server addresses and credentials extracted from config
  • Targeted applications list recovered
  • Keylogger and screenshot capture settings documented
  • Persistence mechanism identified
  • IOCs suitable for network blocking extracted

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references, assets) in skills/extracting-config-from-agent-tesla-rat of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Extracting Config From Agent Tesla Rat next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Extracting Config From Agent Tesla Rat compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Extracting Config From Agent Tesla Rat this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Osintsmixs/osint-skill141—~5.5kAutomated safety check: PassMIT
Malware Analystaiskillstore/marketplace4336 repos~1.7kAutomated safety check: PassNone
Deliverability Incident Responsegrowthenginenowoslawski/coldoutboundskills753—~3.5kAutomated safety check: PassMIT
Better Notifybetter-notify/better-notify313—~783Automated safety check: PassMIT
Migrate Dotnet9 To Dotnet10dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMIT

Similar skills

  • Osint

    smixs/osint-skill

    Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.

    141 GitHub stars~5.5k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Malware Analyst

    aiskillstore/marketplace

    Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response.

    433 GitHub starsUsed in 6 repos~1.7k tokens
    SecurityAuto-check passed
  • Deliverability Incident Response

    growthenginenowoslawski/coldoutboundskills

    Triage playbook for when cold email deliverability breaks. An agent skill from growthenginenowoslawski/coldoutboundskills.

    753 GitHub stars~3.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Better Notify

    better-notify/better-notify

    End-to-end typed notification infrastructure for Node.js — typed catalog of email, SMS, push, web push, WhatsApp, Slack, Discord, Telegram, and GitHub notifications with provider-agnostic transports.

    313 GitHub stars~783 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed
  • Exposed Secret Rotation

    avelikiy/great_cto

    Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

    103 GitHub stars~884 tokensUpdated today
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Extracting Config From Agent Tesla Rat

What does Extracting Config From Agent Tesla Rat do?

Extracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. Extracting Config From Agent Tesla Rat is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.NET decompilation and memory analysis.

When should I use Extracting Config From Agent Tesla Rat?

Extracting Config From Agent Tesla Rat fits situations like: analyzing a suspected; confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence; incident response.

How do I install Extracting Config From Agent Tesla Rat in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-config-from-agent-tesla-rat -a claude-code`. Or copy the skill folder (skills/extracting-config-from-agent-tesla-rat in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/extracting-config-from-agent-tesla-rat in your project. Claude Code loads it when a task matches its description.

How do I install Extracting Config From Agent Tesla Rat in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-config-from-agent-tesla-rat -a codex`. Or copy the skill folder (skills/extracting-config-from-agent-tesla-rat in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/extracting-config-from-agent-tesla-rat in your project. Codex loads it when a task matches its description.

Can I use Extracting Config From Agent Tesla Rat in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill extracting-config-from-agent-tesla-rat -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extracting-config-from-agent-tesla-rat, .gemini/skills/extracting-config-from-agent-tesla-rat, .github/skills/extracting-config-from-agent-tesla-rat and .opencode/skills/extracting-config-from-agent-tesla-rat in your project.

What does Extracting Config From Agent Tesla Rat need to run?

Going by SKILL.md and its folder, Extracting Config From Agent Tesla Rat needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Extracting Config From Agent Tesla Rat access the network?

SKILL.md names 5 domains. As links in the text: splunk.com, blog.qualys.com, any.run, trustwave.com and malpedia.caad.fkie.fraunhofer.de. This is read from the text; nothing was executed.

Is Extracting Config From Agent Tesla Rat safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Extracting Config From Agent Tesla Rat use?

Extracting Config From Agent Tesla Rat is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Extracting Config From Agent Tesla Rat use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 767 tokens, read only when the agent opens those files.

What are the alternatives to Extracting Config From Agent Tesla Rat?

Skills that share tags, products or a category with Extracting Config From Agent Tesla Rat: Osint (smixs/osint-skill, 141 stars), Malware Analyst (aiskillstore/marketplace, 433 stars), Deliverability Incident Response (growthenginenowoslawski/coldoutboundskills, 753 stars) and Better Notify (better-notify/better-notify, 313 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Extracting Config From Agent Tesla Rat?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.