Skip to content

Instantly share code, notes, and snippets.

@michaelder
Last active May 14, 2022 04:50
Show Gist options
  • Star 2 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save michaelder/066a5259145947f9d138f1f2a607aaae to your computer and use it in GitHub Desktop.
Save michaelder/066a5259145947f9d138f1f2a607aaae to your computer and use it in GitHub Desktop.
Cyberchef Recipe for Cobalt Strike Reflective Loader(beacon) v4
Regular_expression('User defined','FromBase64String\\("([^"]+)',true,true,false,false,false,false,'List capture groups')
From_Base64('A-Za-z0-9+/=',true)
Gunzip()
Register('([\\s\\S]*)',true,false,false)
Regular_expression('User defined','FromBase64String\\(\'([^\']+)',true,true,false,false,false,false,'List capture groups')
Register('([\\s\\S]*)',true,false,false)
Find_/_Replace({'option':'Regex','string':'.+'},'$R0',true,false,true,true)
Regular_expression('User defined','-bxor (.+)',true,true,false,false,false,false,'List capture groups')
Register('([\\s\\S]*)',true,false,false)
Find_/_Replace({'option':'Regex','string':'.+'},'$R1',true,false,true,true)
From_Base64('A-Za-z0-9+/=',true)
XOR({'option':'Decimal','string':'$R2'},'Standard',false)
To_Hex('Space',0)
Remove_whitespace(true,true,true,true,true,false)
Register('([\\s\\S]*)',true,false,true)
Regular_expression('User defined','33C080B0([a-f0-9]{2}[a-f0-9]{2}[a-f0-9]{2}[a-f0-9]{2})([a-f0-9]{2})403D([a-f0-9]{2}[a-f0-9]{2}[a-f0-9]{2}[a-f0-9]{2})',true,true,true,false,false,true,'List matches with capture groups')
Remove_whitespace(true,true,true,true,true,false)
Register('Group1:([\\s\\S]*)Group2:([\\s\\S]*)Group3:([\\s\\S]*)',true,true,false)
Find_/_Replace({'option':'Regex','string':'.+'},'$R6',true,false,true,true)
Swap_endianness('Hex',4,true)
From_Base(16)
Register('([\\s\\S]*)',true,false,false)
Find_/_Replace({'option':'Regex','string':'.+'},'$R7,2',true,false,true,true)
Multiply('Comma')
Register('([\\s\\S]*)',true,false,false)
Find_/_Replace({'option':'Regex','string':'.+'},'$R3',true,false,true,true)
Regular_expression('User defined','FFFFFFFFFFFFFFFFFF($R5[a-f0-9]{$R8})',true,true,false,false,false,false,'List capture groups')
From_Hex('Auto')
XOR({'option':'Hex','string':'$R5'},'Standard',false)
To_Hexdump(16,false,false,false)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment