
A list of cyber-chef recipes and curated links

CyberChef is the self-purported 'Cyber Swiss-Army Knife' created by GCHQ. It's a fantastic tool for data transformation, extraction & manipulation in your web-browser.
Full credit to @GCHQ for producing the tool. See: https://gchq.github.io/CyberChef/
Mastering regular expressions are key to making the most of data manipulation in CyberChef (or any DFIR work). Below are some regexs that I keep coming back to.
Extract Base64: [a-zA-Z0-9+/=]{30,}

Extract Hexadecimal: [a-fA-F0-9]{10,}

Extract Character Codes: [\d]{2,3}(,|’)

(?<=foo)(.*)
^.*(?=bar)
(?<=')(.*?)(?=')

CyberChef provides an operation HTTP Request (see Recipe 22) which allows HTTP requests to external resources. Due to Same Origin Policy (SOP) or lack of Cross-Origin Resource Sharing configuration many do not work. SOP is a security measure in modern browsers which prevents you from reading cross-site responses from servers which don't explicitly allow it via CORS. Check out @GlassSec's talk on CyberChef which includes tips to boot Chrome without web-security to enable HTTP requests to otherwise restricted APIs (like Virus Total)
Some example CyberChef recipes:
Recipe 1: Extract base64, raw inflate & beautify
Recipe 4: Group Policy Preference Password Decryption
Recipe 5: Using Loops and Labels
Recipe 6: Google ei Timestamps
Recipe 7: Multi-stage COM scriptlet to x86 assembly
Recipe 8: Extract hexadecimal, convert to hexdump for embedded PE file
Recipe 9: Reverse strings, character substitution, from base64
Recipe 10: Extract object from Squid proxy cache
Recipe 11: Extract GPS Coordinates to Google Maps URLs
Recipe 12: Big Number Processing
Recipe 13: Parsing DNS PTR records with Registers
Recipe 14: Decoding POSHC2 executables
Recipe 15: Parsing $MFT $SI Timestamps
Recipe 16: Decoding PHP gzinflate and base64 webshells
Recipe 17: Extracting shellcode from a Powershell Meterpreter Reverse TCP Script
Recipe 18: Recycle Bin Parser with Subsections and Merges
Recipe 19: Identify Obfuscated Base64 with Regular Expression Highlighting
Recipe 20: Using Yara rules with deobfuscated malicious scripts
Recipe 21: Inline deobfuscation of hex encoded VBE script attached to a malicious LNK file
Recipe 22: JA3 API search with HTTP Request and Registers
Recipe 24: Picking a random letter from a six-byte string
Recipe 25: Creating a Wifi QR code
Recipe 26: Extracting and Decoding a Multistage PHP Webshell
Recipe 27: Decoding an Auto Visitor PHP script
Recipe 28: De-obfuscation of Cobalt Strike Beacon using Conditional Jumps to obtain shellcode
Recipe 29: Log File Timestamp Manipulation with Subsections and Registers
Recipe 30: CharCode obfuscated PowerShell Loader for a Cobalt Strike beacon
Recipe 31: Deobfuscate encoded strings in .NET binary
Recipe 32: Extract malicious Gootkit DLL from obfuscated registry data
Recipe 33: Identify embedded URLs in Emotet PowerShell script
Recipe 34: Analysing OOXML Files for URLs
Recipe 35: Decrypting REvil PowerShell ransomware sample
Recipe 36: Create a CyberChef Password Generator
Recipe 37: From Sandbox zipped email to malicious URL
Recipe 38: Planes, Skulls and Envelopes - Live and Let PowerShell
Recipe 39: Decrypt GoldMax aka Sunshutte encrypted configuration files