← All cheat sheets

CYBERCHEF

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

CyberChef is a web app for encoding, decoding, and data analysis.
Essential for SOC analysts and malware analysts.

ACCESS#

# Online: https://gchq.github.io/CyberChef
# Offline: Download from GitHub

INTERFACE#


    

INPUT#

# Paste or upload data

RECIPE#

# Drag operations from left panel
# Chain multiple operations

OUTPUT#

# View transformed result
# Save or copy

ENCODING/DECODING#


    

BASE64#

To Base64              # Encode
From Base64            # Decode

HEX#

To Hex                 # Convert to hex
From Hex               # Convert from hex
To Hexdump             # Formatted hex dump
From Hexdump           # Parse hex dump

URL#

URL Encode             # Encode special chars
URL Decode             # Decode %XX

HTML#

HTML Entity Encode
HTML Entity Decode
Strip HTML Tags

ASCII/UNICODE#

To Charcode            # To ASCII codes
From Charcode          # From ASCII codes
Escape Unicode         # \uXXXX format
Unescape Unicode

BINARY#

To Binary              # Convert to binary
From Binary            # Convert from binary

COMMON RECIPES#


    

DECODE OBFUSCATED POWERSHELL#

1. From Base64
2. Decode text (UTF-16LE)
# For: powershell -enc BASE64

DECODE NESTED BASE64#

1. From Base64
2. From Base64
3. From Base64
# Use "Loop" operation for multiple iterations

EXTRACT URLs#

1. Extract URLs
# Regex: https?://[^\s<>"{}|\\^`\[\]]+

EXTRACT IPs#

1. Extract IP addresses
# Regex: \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}

DECODE MALWARE STRINGS#

1. From Hex
2. XOR (with key)
3. To UTF-8

HASHING#


    

GENERATE HASHES#

MD5
SHA1
SHA256
SHA512
SSDEEP                 # Fuzzy hash

VERIFY HASH#

# Input: file content
# Operation: MD5/SHA256
# Compare output with known hash

ENCRYPTION/DECRYPTION#


    

SYMMETRIC#

AES Encrypt/Decrypt
DES Encrypt/Decrypt
Triple DES
Blowfish
RC4

ASYMMETRIC#

RSA Encrypt/Decrypt

OPTIONS#

Mode: CBC, ECB, CTR, GCM
Padding: PKCS7, None, Zero
Key format: Hex, UTF8, Base64
IV: Initialization Vector

COMPRESSION#

Gunzip                 # Decompress gzip
Gzip                   # Compress gzip
Unzip                  # Extract ZIP
Zip                    # Create ZIP
Raw Inflate            # Decompress deflate
Raw Deflate            # Compress deflate
Bzip2 Decompress
Bzip2 Compress

DATA FORMAT#


    

JSON#

JSON Beautify          # Pretty print
JSON Minify            # Compact
JPath Expression       # Query JSON

XML#

XML Beautify
XML Minify
XPath Expression

PARSING#

Parse IP range
Parse IPv6 address
Parse URI
Parse User Agent
Parse X.509 certificate

TEXT OPERATIONS#


    

MANIPULATION#

Find / Replace
Regular expression
Split
Merge
Sort
Unique
Reverse
Filter

EXTRACTION#

Extract URLs
Extract Email addresses
Extract IP addresses
Extract domains
Extract file paths

ANALYSIS#

Frequency distribution
Entropy
Index of Coincidence
Chi-square

NETWORKING#

Parse IP range
Parse URI
Defang URL             # Replace . with [.]
Refang URL             # Restore . from [.]
Defang IP address
Refang IP address

FORENSICS#


    

FILE ANALYSIS#

Detect File Type       # Magic bytes
Extract Files          # Carve embedded files
Scan for embedded files
Parse EXIF data
Parse QR Code
Generate QR Code

TIMESTAMP#

Translate DateTime Format
Windows Filetime to UNIX
UNIX Timestamp to Date
Parse DateTime

MALWARE ANALYSIS#


    

DEOBFUSCATION#

Generic Code Beautify
JavaScript Beautify
JavaScript Parser
CSS Beautify

XOR OPERATIONS#

XOR                    # XOR with key
XOR Brute Force        # Try all single-byte keys

STRING ANALYSIS#

Strings                # Extract strings
Escape string          # Add escape chars
Unescape string        # Remove escape chars

LANGUAGE#

From Morse Code
To Morse Code
ROT13
ROT47
Atbash Cipher
Caesar Cipher
Vigenere Decode
Substitute

FLOW CONTROL#

Fork                   # Split processing
Merge                  # Combine results
Jump                   # Jump to label
Label                  # Mark position
Conditional Jump
Register
Comment

LOOP#

# Repeat operations
Loop (10)              # Run 10 times

REGULAR EXPRESSIONS#

Regular expression
# Match: Extract matches
# List: List all matches
# Replace: Substitute

USEFUL REGEX#

Email:    [a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}
IPv4:     \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
URL:      https?://[^\s<>"{}|\\^`\[\]]+
Domain:   [a-zA-Z0-9][-a-zA-Z0-9]*\.[a-zA-Z]{2,}
Base64:   [A-Za-z0-9+/=]{4,}
MD5:      [a-fA-F0-9]{32}
SHA256:   [a-fA-F0-9]{64}

RECIPES FOR SOC#


    

ANALYZE PHISHING URL#

1. Defang URL (for sharing)
2. URL Decode
3. Extract domain
4. Parse URI

DECODE ENCODED COMMAND#

1. From Base64
2. Decode text (UTF-16LE)
3. Generic Code Beautify

EXTRACT IOCs#

1. Fork
2. Branch 1: Extract IP addresses
3. Branch 2: Extract URLs
4. Branch 3: Extract domains
5. Merge

ANALYZE MALICIOUS ATTACHMENT#

1. Unzip (if needed)
2. Detect File Type
3. Strings
4. Extract URLs

TIPS#

# Save recipes for reuse
# Use "Magic" to auto-detect encoding
# Chain operations in sequence
# Use Fork/Merge for parallel processing
# Drag to reorder operations

QUICK REFERENCE#

From Base64            # Decode base64
To Hex                 # Encode to hex
URL Decode             # Decode URL
XOR                    # XOR decrypt
Gunzip                 # Decompress
Strings                # Extract strings
Extract URLs           # Find URLs
Defang URL             # Safe sharing
Regular expression     # Pattern match
JSON Beautify          # Format JSON
MD5/SHA256            # Generate hash