> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/cyberchef.md).

# CyberChef

When reverse engineering, perhaps you've used CyberChef, GCHQ's "Cyber Swiss Army Knife". This standalone, offline web page provides hundreds of data transformation operations that you can drag into a recipe, feed in some data, and watch the output update in real time. You don't have to install any software, sensitive data isn't sent to any remote server, and the interface encourages experimentation.

For example, when you suspect data is XOR-encoded, you can try keys and immediately see if the output looks like plaintext. Or if you hit AES-encrypted data and can't remember whether it's CBC or CTR, just try both.

However, during reverse engineering, you often bounce data between IDA and CyberChef. You find an encrypted region in a binary, copy the bytes out, load them into CyberChef in a browser tab, figure out the right transformation, then copy the result back into IDA. It's tedious and easy to make a silly mistake.

The Malware Analysis add-on eliminates the round-trip. It embeds CyberChef's data transformation engine directly into IDA Pro, with a Qt interface that sits alongside your disassembly as a side panel. Data flows top to bottom through three panels for input, recipe, and output.

![CyberChef panel with input, recipe, and output](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-3e8350a92a85eddbf6d45893ab98f413707563c5%2Fcyberchef-interface.png?alt=media)

{% hint style="info" %}
CyberChef comes from the open source [ida-cyberchef](https://plugins.hex-rays.com/hexrayssa/ida-cyberchef/ida-cyberchef) plugin, which is available for free in the IDA plugin repository. The add-on includes it for convenience and discoverability. CyberChef is not available on some Linux systems, and some offline bundles may not include it. CyberChef does not load on Python 3.13.0 to 3.13.12 or on Python 3.14.0.
{% endhint %}

## Input

The plugin works with data directly from your IDB. It can follow your cursor, transforming and previewing a slice of data from that address. As you move through the disassembly, it reads bytes at the current position and applies the recipe in real time. This is useful for validating a hypothesis. Say you've recovered an XOR key and want to see how it decodes a region of data: you can scroll around and apply the transformation and preview how it would look.

You can also operate on the mouse's selection or specify an explicit range by hand. You can always paste or type data directly, just like the CyberChef web interface, with a format selector for string, hex, or base64 interpretations. Finally, you can select a region and use **CyberChef > Send to CyberChef-A** in the context menu, which is pretty handy:

![Send to CyberChef context menu action](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-292ff02155e674bab397e028e02453e2bd13b955%2Fcyberchef-send-to-cyberchef.png?alt=media)

## Recipe

To construct your recipe, a search bar with fuzzy matching helps you find the operation you want, against the \~440 supported operations. For malware analysis, the heavy hitters are probably variants of XOR, including brute forcing the key, byte-wise operations like shift and invert, AES and RC4 encryption, and a collection of hashing algorithms. But the full CyberChef catalog is available, including protobuf decoding, to/from charcode, and even CitrixCTX1 Decode. As you hover over a candidate, the plugin shows documentation about how to use the operation.

![Operation search with documentation](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-faf2c48335161a648ebd4ba28f020a05a2709b4c%2Fcyberchef-operation-search.png?alt=media)

You can chain multiple operations into a recipe, and results update as you tweak parameters. The same interactive experimentation you're used to from the web interface works here, except your data never leaves IDA.

![Recipe with Rotate left and XOR operations](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-6a307959f0ab1dc19f9054e38511ef6bed5c34bb%2Fcyberchef-recipe.png?alt=media)

## Output destinations

Once you've figured out the right transformation, there are several destinations for the output. The simplest options are copying to clipboard or saving to a file. When copying, you choose the format (hex dump, hex string, C-style array, raw bytes, or plain string), which is convenient for pasting into reports or other tools.

![Output panel with destination buttons](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-524348d6f0e82f9c24dd1a08f7501c0a44059762%2Fcyberchef-output.png?alt=media)

Two options are specific to IDA. First, you can attach the decoded data as a comment at the source address. Use this when you want to annotate encrypted strings without modifying the database. The comment serves as a reminder of what the data decodes to, visible in the IDB:

![Decoded data as a comment at the source address](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-9680adceb1fa08d16a7f40ce139dc0dc2c49ce97%2Fcyberchef-comment.png?alt=media)

Or you can patch the transformed bytes directly back into the IDB. This is particularly useful when you've decoded an embedded configuration file and want to xref to specific fields within IDA. As you apply specific types to the decoded bytes, like a custom structure layout, IDA can render the data more clearly:

![Decoded configuration patched into the IDB with a structure applied](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-76806a9c1291ead5cc4d771c70695040ca5d0340%2Fcyberchef-patched-structure.png?alt=media)

## Under the hood

The plugin doesn't port the 440 operations from JavaScript into Python or C++. Instead, it runs the actual CyberChef JavaScript code inside a JavaScript engine embedded in IDA. This is a small amount of code, and it lets the plugin rely on (and contribute back to) the CyberChef community.

The few operations that the plugin can't support are due to browser-specific dependencies. Yara scanning, for example, requires linking against the Yara library in a way that doesn't translate to an embedded engine.

The CyberChef engine is also accessible as a Python library. You can pass in data and recipe definitions as Python data structures and get results back programmatically:

```python
from ida_cyberchef import bake

bake(b"\x29\x24\x2d\x2d\x2e", [{"op": "XOR", "args": {"key": {"option": "Hex", "string": "41"}}}])
```

For the background, see the blog post [IDA Pro, Meet CyberChef](https://hex-rays.com/blog/ida-pro-meet-cyberchef).

## Configuration

To open a CyberChef panel, select **Malware Analysis > CyberChef** or **View > Open subviews > CyberChef**, or press `Shift-C`. You can open up to 26 panels, named `CyberChef-A` to `CyberChef-Z`.

CyberChef has no settings. You select these options in each panel:

| Option             | Values                                                    | Default                                  | Description                                                                                                                                                                                                                                 |
| ------------------ | --------------------------------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Input source       | Manual Input, From Cursor, From Selection, From Location  | Manual Input                             | From Cursor reads 256 bytes at the cursor and follows it. From Selection follows the selection in the disassembly and hex views. From Location reads a fixed address and length, and does not follow the cursor.                            |
| Input format       | Text (UTF-8), Hex String, Base64                          | Text (UTF-8)                             | How to interpret manual input. Not available for the other input sources.                                                                                                                                                                   |
| Address and length | hexadecimal address, decimal length or end address        | length 256                               | The range to read in From Location mode.                                                                                                                                                                                                    |
| Output format      | Depends on the result type                                | Hex Dump for bytes, Pretty JSON for JSON | Bytes can show as Hex Dump, Text, Hex String (spaced or unspaced), String Literal, C Array (hex or decimal), or C Variable.                                                                                                                 |
| Output destination | Copy to clipboard, Save to file, Copy to IDB, Set comment | none                                     | Copy to IDB patches the bytes into the database, and is available only for bytes output from the From Selection or From Location input sources. Set comment adds the output as a comment at the start of the input range, or at the cursor. |

The input area shows only the first 256 bytes of the input, but the recipe gets all the data. An asynchronous operation stops after 10 seconds. CyberChef does not save the recipe, input, or input source. When IDA restores a desktop layout, CyberChef panels open empty.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/cyberchef.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
