CyberChef: The Cyber Swiss Army Knife for Encoding, Decoding, and Data Analysis

CyberChef: The Cyber Swiss Army Knife for Encoding, Decoding, and Data Analysis

CyberChef is a web app for transforming data. You drag operations into a recipe, such as “From Base64”, then “Gunzip”, then “Extract URLs”, and it applies them to your input as you type. It was built and open sourced by GCHQ, the UK signals intelligence agency, and is a staple of security analysts, CTF players, and developers.

Features

  • Hundreds of operations: encoding (Base64, hex, URL), encryption and decryption (AES, DES, XOR), hashing, compression, character sets, date and time parsing, regular expressions, networking and data formats
  • Magic: automatic detection of likely encodings, for when you do not know what you are looking at
  • Breakpoints and step-through, to debug a recipe
  • Recipes in the URL, so you can share or bookmark a whole workflow
  • Files up to around 2 GB
  • Runs entirely in the browser: data is never sent to a server

Why self-host it

The public instance at gchq.github.io works fine, and it processes data client-side. Self-hosting still makes sense in environments that block external sites, for offline and air-gapped machines, or simply to guarantee the code you run has not changed under you.

Deployment

It is a static site, so any web server works. The official container is the quickest route:

docker run -d -p 127.0.0.1:8080:8080 ghcr.io/gchq/cyberchef:latest

Or build it and serve the output directory:

git clone https://github.com/gchq/CyberChef && cd CyberChef
npm install && npm run build
# serve build/prod with nginx, Caddy, or any static host

IT Tools is a friendlier collection of developer utilities (UUID generators, converters, formatters) that overlaps with CyberChef for simpler tasks. For command-line equivalents, base64, xxd, openssl, and jq cover much of the same ground.

License

Apache License 2.0.