Firstly, you need some Powershell Base64 commands, you could search your security logs or Sysmon logs for these, or simply generate some yourself!


Next, we head over to Cyber Chef!

Now we copy the base64 component to the INPUT window:

We add the “From Base64” operation into our RECIPE!We now need to decode the text!

The format of the encoding is UTF-16LE (1200)

With this recipe BAKED we can see the clear text output! Simples!

