CYBERCHEF
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
CyberChef is a web app for encoding, decoding, and data analysis. Essential for SOC analysts and malware analysts.
ACCESS#
# Online: https://gchq.github.io/CyberChef # Offline: Download from GitHub
INTERFACE#
INPUT#
# Paste or upload data
RECIPE#
# Drag operations from left panel # Chain multiple operations
OUTPUT#
# View transformed result # Save or copy
ENCODING/DECODING#
BASE64#
To Base64 # Encode From Base64 # Decode
HEX#
To Hex # Convert to hex From Hex # Convert from hex To Hexdump # Formatted hex dump From Hexdump # Parse hex dump
URL#
URL Encode # Encode special chars URL Decode # Decode %XX
HTML#
HTML Entity Encode HTML Entity Decode Strip HTML Tags
ASCII/UNICODE#
To Charcode # To ASCII codes From Charcode # From ASCII codes Escape Unicode # \uXXXX format Unescape Unicode
BINARY#
To Binary # Convert to binary From Binary # Convert from binary
COMMON RECIPES#
DECODE OBFUSCATED POWERSHELL#
1. From Base64 2. Decode text (UTF-16LE) # For: powershell -enc BASE64
DECODE NESTED BASE64#
1. From Base64 2. From Base64 3. From Base64 # Use "Loop" operation for multiple iterations
EXTRACT URLs#
1. Extract URLs
# Regex: https?://[^\s<>"{}|\\^`\[\]]+
EXTRACT IPs#
1. Extract IP addresses
# Regex: \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
DECODE MALWARE STRINGS#
1. From Hex 2. XOR (with key) 3. To UTF-8
HASHING#
GENERATE HASHES#
MD5 SHA1 SHA256 SHA512 SSDEEP # Fuzzy hash
VERIFY HASH#
# Input: file content # Operation: MD5/SHA256 # Compare output with known hash
ENCRYPTION/DECRYPTION#
SYMMETRIC#
AES Encrypt/Decrypt DES Encrypt/Decrypt Triple DES Blowfish RC4
ASYMMETRIC#
RSA Encrypt/Decrypt
OPTIONS#
Mode: CBC, ECB, CTR, GCM Padding: PKCS7, None, Zero Key format: Hex, UTF8, Base64 IV: Initialization Vector
COMPRESSION#
Gunzip # Decompress gzip Gzip # Compress gzip Unzip # Extract ZIP Zip # Create ZIP Raw Inflate # Decompress deflate Raw Deflate # Compress deflate Bzip2 Decompress Bzip2 Compress
DATA FORMAT#
JSON#
JSON Beautify # Pretty print JSON Minify # Compact JPath Expression # Query JSON
XML#
XML Beautify XML Minify XPath Expression
PARSING#
Parse IP range Parse IPv6 address Parse URI Parse User Agent Parse X.509 certificate
TEXT OPERATIONS#
MANIPULATION#
Find / Replace Regular expression Split Merge Sort Unique Reverse Filter
EXTRACTION#
Extract URLs Extract Email addresses Extract IP addresses Extract domains Extract file paths
ANALYSIS#
Frequency distribution Entropy Index of Coincidence Chi-square
NETWORKING#
Parse IP range Parse URI Defang URL # Replace . with [.] Refang URL # Restore . from [.] Defang IP address Refang IP address
FORENSICS#
FILE ANALYSIS#
Detect File Type # Magic bytes Extract Files # Carve embedded files Scan for embedded files Parse EXIF data Parse QR Code Generate QR Code
TIMESTAMP#
Translate DateTime Format Windows Filetime to UNIX UNIX Timestamp to Date Parse DateTime
MALWARE ANALYSIS#
DEOBFUSCATION#
Generic Code Beautify JavaScript Beautify JavaScript Parser CSS Beautify
XOR OPERATIONS#
XOR # XOR with key XOR Brute Force # Try all single-byte keys
STRING ANALYSIS#
Strings # Extract strings Escape string # Add escape chars Unescape string # Remove escape chars
LANGUAGE#
From Morse Code To Morse Code ROT13 ROT47 Atbash Cipher Caesar Cipher Vigenere Decode Substitute
FLOW CONTROL#
Fork # Split processing Merge # Combine results Jump # Jump to label Label # Mark position Conditional Jump Register Comment
LOOP#
# Repeat operations Loop (10) # Run 10 times
REGULAR EXPRESSIONS#
Regular expression # Match: Extract matches # List: List all matches # Replace: Substitute
USEFUL REGEX#
Email: [a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}
IPv4: \d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
URL: https?://[^\s<>"{}|\\^`\[\]]+
Domain: [a-zA-Z0-9][-a-zA-Z0-9]*\.[a-zA-Z]{2,}
Base64: [A-Za-z0-9+/=]{4,}
MD5: [a-fA-F0-9]{32}
SHA256: [a-fA-F0-9]{64}
RECIPES FOR SOC#
ANALYZE PHISHING URL#
1. Defang URL (for sharing) 2. URL Decode 3. Extract domain 4. Parse URI
DECODE ENCODED COMMAND#
1. From Base64 2. Decode text (UTF-16LE) 3. Generic Code Beautify
EXTRACT IOCs#
1. Fork 2. Branch 1: Extract IP addresses 3. Branch 2: Extract URLs 4. Branch 3: Extract domains 5. Merge
ANALYZE MALICIOUS ATTACHMENT#
1. Unzip (if needed) 2. Detect File Type 3. Strings 4. Extract URLs
TIPS#
# Save recipes for reuse # Use "Magic" to auto-detect encoding # Chain operations in sequence # Use Fork/Merge for parallel processing # Drag to reorder operations
QUICK REFERENCE#
From Base64 # Decode base64 To Hex # Encode to hex URL Decode # Decode URL XOR # XOR decrypt Gunzip # Decompress Strings # Extract strings Extract URLs # Find URLs Defang URL # Safe sharing Regular expression # Pattern match JSON Beautify # Format JSON MD5/SHA256 # Generate hash