Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cyberchef-recipes — A list of cyber-chef recipes and curated links | Kitploit
Tools/GitHubGitHub/mattnotmax/cyberchef-recipes
Disk ForensicsEncryption/Decryption ToolsNetwork ForensicsPhishingMalware AnalysisDigital ForensicsThreat IntelligenceLearning & EducationIncident ResponseCurated ResourcesLog Analysis
2.2k280242 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
mattnotmax/cyberchef-recipes

cyberchef-recipes

A list of cyber-chef recipes and curated links

View Repository

cyberchef_banner_1500

CyberChef is the self-purported 'Cyber Swiss-Army Knife' created by GCHQ. It's a fantastic tool for data transformation, extraction & manipulation in your web-browser.

Full credit to @GCHQ for producing the tool. See: https://gchq.github.io/CyberChef/

General Tips

  • Download CyberChef and run it entirely client-side. It doesn't need an internet connection except for certain operations. That way all your data is safe.
  • Don't try and shoe-horn CyberChef into something that it can't do. It can do a lot but it's not a fully fledged programming language!

Useful Regular Expressions

Mastering regular expressions are key to making the most of data manipulation in CyberChef (or any DFIR work). Below are some regexs that I keep coming back to.

Extracting Encoded Data

  • Extract Base64: [a-zA-Z0-9+/=]{30,}

    • Here '30' is an arbitrary number that can be adjusted according to the script.
      base64
  • Extract Hexadecimal: [a-fA-F0-9]{10,}

    • This could also be adjusted to {32} (MD5), {40} (SHA1), {64}, SHA256 to extract various hashes hex
  • Extract Character Codes: [\d]{2,3}(,|’)

    • In this example it would extract character codes in the format ('30, 40, 50, 60') charcode

Lookaheads & Lookbehinds

  • Positive Lookbehind: (?<=foo)(.*)
    • Extract everything after 'foo' without including 'foo'
  • Positive Lookahead: ^.*(?=bar)
    • Extract everything before 'bar' without including 'bar'
  • Lookahead/behind Combo: (?<=')(.*?)(?=')
    • Extract everything between ' and ' combo

Working with APIs and CyberChef

CyberChef provides an operation HTTP Request (see Recipe 22) which allows HTTP requests to external resources. Due to Same Origin Policy (SOP) or lack of Cross-Origin Resource Sharing configuration many do not work. SOP is a security measure in modern browsers which prevents you from reading cross-site responses from servers which don't explicitly allow it via CORS. Check out @GlassSec's talk on CyberChef which includes tips to boot Chrome without web-security to enable HTTP requests to otherwise restricted APIs (like Virus Total)

CyberChef Recipes

Some example CyberChef recipes:

Recipe 1: Extract base64, raw inflate & beautify

Recipe 2: Invoke Obfuscation

Recipe 3: From CharCode

Recipe 4: Group Policy Preference Password Decryption

Recipe 5: Using Loops and Labels

Recipe 6: Google ei Timestamps

Recipe 7: Multi-stage COM scriptlet to x86 assembly

Recipe 8: Extract hexadecimal, convert to hexdump for embedded PE file

Recipe 9: Reverse strings, character substitution, from base64

Recipe 10: Extract object from Squid proxy cache

Recipe 11: Extract GPS Coordinates to Google Maps URLs

Recipe 12: Big Number Processing

Recipe 13: Parsing DNS PTR records with Registers

Recipe 14: Decoding POSHC2 executables

Recipe 15: Parsing $MFT $SI Timestamps

Recipe 16: Decoding PHP gzinflate and base64 webshells

Recipe 17: Extracting shellcode from a Powershell Meterpreter Reverse TCP Script

Recipe 18: Recycle Bin Parser with Subsections and Merges

Recipe 19: Identify Obfuscated Base64 with Regular Expression Highlighting

Recipe 20: Using Yara rules with deobfuscated malicious scripts

Recipe 21: Inline deobfuscation of hex encoded VBE script attached to a malicious LNK file

Recipe 22: JA3 API search with HTTP Request and Registers

Recipe 23: Defeating DOSfuscation embedded in a malicious DOC file with Regular Expression capture groups

Recipe 24: Picking a random letter from a six-byte string

Recipe 25: Creating a Wifi QR code

Recipe 26: Extracting and Decoding a Multistage PHP Webshell

Recipe 27: Decoding an Auto Visitor PHP script

Recipe 28: De-obfuscation of Cobalt Strike Beacon using Conditional Jumps to obtain shellcode

Recipe 29: Log File Timestamp Manipulation with Subsections and Registers

Recipe 30: CharCode obfuscated PowerShell Loader for a Cobalt Strike beacon

Recipe 31: Deobfuscate encoded strings in .NET binary

Recipe 32: Extract malicious Gootkit DLL from obfuscated registry data

Recipe 33: Identify embedded URLs in Emotet PowerShell script

Recipe 34: Analysing OOXML Files for URLs

Recipe 35: Decrypting REvil PowerShell ransomware sample

Recipe 36: Create a CyberChef Password Generator

Recipe 37: From Sandbox zipped email to malicious URL

Recipe 38: Planes, Skulls and Envelopes - Live and Let PowerShell

Recipe 39: Decrypt GoldMax aka Sunshutte encrypted configuration files

Recipe 40: Morse Code Madness

Recipe 41: PHP mixed hexadecimal and octal encoding

Recipe 42: PHP Webshell with layered obfuscation

Download Tool