0% found this document useful (0 votes)
56 views

CyberChef Introduction

Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
56 views

CyberChef Introduction

Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 25

CyberChef. Simplify.

Uncover secrets.
Decode data.
Look for things.
Find things.
Secrets In Local Storage.
Secrets on Paper
…on your bank statement
On your driver’s license
CyberChef. Finally!
Extract Text from Screenshots
Confidence: 84%

cal@ubuntu:~/git$ ifconfig
ens33: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.44.3 netmask 255.255.255.0 broadcast 192.168.44.255
inet6 fe80::2092:ddae:337f:9e50 prefixlen 64 scopeid 0x20<link>
ether 00:0c:29:ef:ba:le txqueuelen 1000 (Ethernet)
RX packets 598 bytes 853437 (853.4 KB)
RX errors @ dropped 0 overruns @ frame 0
TX packets 133 bytes 13841 (13.8 KB)
TX errors © dropped @ overruns @ carrier 0 collisions @
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10<host>
loop txqueuelen 1000 (Local Loopback:
RX packets 136 bytes 11256 (11.2 KB)
RX errors @ dropped 0 overruns @ frame 0
TX packets 136 bytes 11256 (11.2 KB)
TX errors © dropped @ overruns @ carrier 0 collisions @
cal@ubuntu:~/git$ ip addr
1: lo: <LOOPBACK,UP,LOWER UP> mtu 65536 qdisc noqueue state UNKNOWN group
default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.6.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens33: <BROADCAST,MULTICAST,UP,LOWER UP> mtu 1560 qdisc fq codel state
UP group default qlen 1060
link/ether 00:0c:29:ef:ba:1le brd ff:ff:ff:ff:ff:ff
inet 192.168.44.3/24 brd 192.168.44.255 scope global dynamic noprefixroute
ens33
valid_1ft 85482sec preferred 1ft 85482sec
inet6 fe80::2092:ddae:337f:9e50/64 scope link noprefixroute
valid_1ft forever preferred_lft forever
Extract Text from Screenshots
QR Codes
QR Codes: EICAR
QR Codes: OWASP XSS Polyglot
Recipes To Look For
• Base64 Offsets
• Generate All Hashes
• Analyze Hash
• Code tidy / minify
• Extractors
• URLs
• IP addresses (regex. Goto Joff’s Class)
• Frequency Distributions
• Convert Distance
• because why not?
Base64 Offsets
Generate All Hashes
Analyze Hash
Process Several At Once (Fork)
Code Tidy Has Own Section
Extract URLs
Extract URLs PLUS MAGIC
Magic Exhausted
Extract IP Addresses

You might also like