PyChef documentation
PyChef is an unofficial, pure-Python data-transformation library inspired by CyberChef. It runs recipes and reusable pipelines inside normal Python scripts, tests, services, notebooks, and CTF tooling. The published package has no runtime dependency on Node.js or JavaScript.
The PyPI distribution is named cyberchef-py. The import is named pychef.
PyChef currently registers 502 operation names from the pinned CyberChef 11.3.0
inventory. Name coverage and exact option-level compatibility are deliberately
reported separately; read Compatibility and current status before relying on an uncommon
format or protocol variant.
Start here
Getting started installs the package and performs a first transformation.
Text, bytes, and structured data explains when PyChef uses
strand when it usesbytes.Recipes explains CyberChef-compatible recipe dictionaries.
Pipelines explains immutable, composable Python transformations.
Operation reference lists every operation, its arguments, status, and examples.
CTF and binary tools covers packing, endianness, XOR, hashes, cyclic patterns, and AES.
Packets, PCAP, and PCAPNG turns network packets, PCAP, and PCAPNG into Python dictionaries.
Learn
Reference
- Operation reference
- Python API reference
- Top-level package
- Recipes and execution
- Pipelines
- CTF helpers
aes_decrypt()aes_encrypt()aes_gcm_decrypt()aes_gcm_encrypt()chunks()cyclic()cyclic_find()decode_bytes()digest()digests()encode_bytes()flat()hexdump()md5()p8()p16()p16be()p16le()p32()p32be()p32le()p64()p64be()p64le()pack()rol()ror()sha1()sha256()sha512()swap_endian()u8()u16()u16be()u16le()u32()u32be()u32le()u64()u64be()u64le()unpack()xor_bytes()
- Packet and capture parsers
- Operation registry
- Compatibility report
- Public types
- Exceptions
- Compatibility and current status
- Attribution and licenses
Project
- Contributing to PyChef and its documentation
- Frequently asked questions
- Why do I install
cyberchef-pybut importpychef? - Does PyChef need Node.js or JavaScript?
- Why did an operation return
bytesinstead ofstr? - How do I pass operation options?
- How do I chain an operation with normal Python code?
- How do I see intermediate values?
- Does 100% operation-name coverage mean exact CyberChef parity?
- Can I use the AES implementation for production secrets?
- How do I update the documentation after changing an operation?
- Why do I install