GCHQ's 'Cyber Swiss Army Knife': 300+ drag-and-drop operations โ decode, decrypt, decompress, extract. CTF players keep it pinned; incident responders cook artifacts in it daily.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Magic auto-guesses chains โ spooky-good first move.
Recipes chain left-to-right; output feeds next op.
OSINT/IR triage in one click.
Malware droppers unravel beautifully here.
Recipes are shareable โ build a personal toolkit.
| Magic | auto-detect chains |
| From Base64/Hex | decode staples |
| XOR | bruteforce keys |
| Extract * | IPs/URLs/emails |
| Gunzip/Inflate | compressed streams |
| JWT Decode | token inspection |
Offline desktop build available โ no internet required mid-IR.
If Magic fails, think backwards: what would an attacker do LAST?
JWT, URL, HTML entities, punycode โ web CTF categories melt here.
Security Onion even embeds CyberChef for analysts.
Use CyberChef only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.