惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
腾讯CDC
D
Docker
G
Google Developers Blog
D
DataBreaches.Net
雷峰网
雷峰网
Blog — PlanetScale
Blog — PlanetScale
S
SegmentFault 最新的问题
The Cloudflare Blog
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
量子位
美团技术团队
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Engineering at Meta
Engineering at Meta
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Webcast: Uncovering Secrets and Simplifying Your Life wit...
BHIS · 2021-12-21 · via Black Hills Information Security, Inc.

, , ,





Information takes many forms. Some of these forms are easy to understand and others less so. Some are hardly even recognizable.

How do you know when you’ve found something interesting? When is that string of random-looking gibberish actually random gibberish and when is it something you can pick apart and make use of? What about that giant blob of text that may or may not have interesting parts inside it?

CyberChef – a free browser-based tool from GCHQ – is a great place to start. It knows about lots of different data formats and encoding rules and lets you string them together into recipes to help you pluck out just the parts you need. In this webcast, we’ll look at some of the ways CyberChef has helped make sense of confusing things, how it compares to other tools you may already know, and how you might make it part of your own adventures.

Recorded•2021-04-22

Join the BHIS Community Discord: https://discord.gg/bhis

00:00 – FEATURE PRESENTATION BEGINS: Uncovering Secrets and Simplifying your Life with CyberChef

02:03 – Secrets are Everywhere

06:45 – Landing on Mars

09:27 – CyberChef

10:59 – What is GCHQ?

12:31 – CyberChef is for 7-bit ASCII

14:06 – CyberChef is for Extracting Text from Screenshots

16:51 – CyberChef is for QR Codes

19:03 – CyberChef Recipes to Look For

19:51 – DEMO: Base64 Offsets

23:13 – DEMO: Process Several at Once (Fork)

24:57 – Code Tidy Has Its Own Section

25:43 – DEMO: Storing Recipes Locally

26:43 – DEMO: Extracting URLs

29:44 – DEMO: Extracting IP Addresses

31:18 – DEMO: Test Regular Expressions

33:21 – DEMO: Frequency Distribution

34:17 – DEMO: Converting Distance

36:51 – Followup Ideas

38:31 – DEMO: Using Break & Skip Buttons

39:56 – QnA

47:13 – LINK: https://www.antisyphontraining.com/modern-webapp-pentesting-w-bb-king/

48:31 – LINK: https://www.antisyphontraining.com/regular-expressions-your-new-lifestyle-w-joff-thyer/

We think BB is pretty cool …but we might be biased.

Why not find out for yourself and take a class with him?

Modern WebApp Pentesting

Available live/virtual and on-demand