DECRYPT2

Splunk Community

DECRYPT2

DECRYPT2
DECRYPT2 is a fork of DECRYPT by Michael Zalewski DECRYPT is a set of Splunk commands which provide Base32, Base64, XOR, ROTX, RC4, ROL/ROR, hex, ascii, substr, decode (python codec), escape, unescape, htmlescape, htmlunescape, tr, rev, find, substr, slice, zlib_inflate, Base32 reverse endian, Base64 reverse endian, Base58 routines which are commonly used for obfuscating malware communications and data exfiltration. These commands can be leveraged in Splunk queries by users or automation to decipher previously indexed communications.
2 topics and 0 replies mentioned DECRYPT2 in
Latest Topics
Latest Replies
No posts to display.
Top Topics
My Topics
No posts to display.