DECRYPT is a set of Splunk commands which provide Base32, Base64, XOR, ROTX, RC4 and ROL/ROR routines which are commonly used for obfuscating malware communications and data exfiltration.
These commands can be leveraged in Splunk queries by users or automation to decipher previously indexed communications.