Securing Networks: Real-Time Base64 Keyword Detection
ID: 17151387-3263-59c6-b684-33c0248c5d64
STIX ID: report--17151387-3263-59c6-b684-33c0248c5d64
Feed Name: Fidelis Security
This report explains a method to detect base64-encoded data exfiltration without full decoding by identifying one of three characteristic base64 offsets for any target keyword. It demonstrates use of CyberChef’s “Show Base64 offsets” and YARA’s base64 string modifier to locate patterns such as “.exe\n,” highlights an example of encoded system profiling data hidden after a JPEG End-of-Image marker, and proposes practical heuristics (e.g., match frequency thresholds and file-size limits) to minimize false positives, enabling scalable network and file-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
