HIMANSHUSHARMA20/CipherLens

Privacy-first, local browser-based analyzer that detects and ranks likely data transformations for cybersecurity analysis.

TypeScript

0

1 commits

updated Sep 28, 2026

See the code

See what people are saying

SourceMessageScoreDate

I built CipherLens — a local-first tool that tries to identify what operation could explain unknown data (r/SideProject)

Hey everyone, I’ve been working on a cybersecurity tool called CipherLens. The idea came from a simple problem I kept running into with tools like CyberChef: You have some unknown data, but you don’t know which operation you should try first. Instead of manually guessing between Base64, Hex, URL…

1

Sep 29, 2026

README

CipherLens

"Don't guess the operation. Find it."

License: MIT Privacy: 100% Client-Side TypeScript Local Executable Operations

CipherLens is an open-source, local-first data transformation discovery and analysis tool designed for cybersecurity professionals, forensic analysts, CTF players, and developers.

Unlike traditional tools where users must manually guess and test operations one by one, CipherLens automates the discovery process. It analyzes unknown payloads, fingerprints input features, evaluates candidate transformations, validates outputs, scores results using content-type-aware heuristics, and presents ranked, evidence-backed candidate operations alongside a search-first Transformation Workbench.


Core Features

  • Automated Transformation Discovery: Input raw, obfuscated, or encrypted data streams and receive candidate operations ranked by confidence.
  • Content-Type-Aware Scoring Engine: Content validators evaluate Plain English, JSON, XML, URLs, JWT, Programming Syntax, Multilingual UTF-8, and File Magic Bytes without false-positive vocabulary penalties.
  • Search-First Transformation Workbench: Integrated operation selector with live search filtering, recent operations quick bar, technical specifications, and mathematical formulas for 497 operations.
  • Top 10 Candidate Ranking: Displays top meaningful candidates with evidence breakdowns detailing structural, language, entropy, and pattern signals.
  • Output Deduplication: Groups identical or near-duplicate candidate outputs to preserve candidate diversity.
  • 100% Client-Side & Privacy-First: All core operations run 100% locally inside your browser memory. Zero backend, zero database, zero tracking, zero telemetry, and zero hidden network calls.
  • Non-Blocking Web Worker Architecture: Offloads CPU-intensive analysis to a Web Worker for a smooth 60fps UI experience.
  • Strict Theme System: Supported in clean Light mode (default) and red-accented Dark mode.

Authoritative Operation Inventory

CipherLens implements the authoritative CyberChef-derived reference baseline:

  • 535 raw reference category entries
  • 501 unique canonical operations
  • 497 local executable operations (100% implemented)
    • 187 AUTO operations (Auto-detected, executed, scored)
    • 82 PARAMETER_REQUIRED operations (Keyed ciphers & parameterized transformations)
    • 228 MANUAL operations (Workbench transformations & parsers: 21 VERIFIED PASS, 206 EXECUTION VERIFIED, 1 BLOCKED pgp-encrypt-and-sign)
  • 3 explicit external operations (HTTP Request, DNS over HTTPS, Show on Map)
  • 1 reference-only concept (Magic)

Run the CLI audit tool to inspect runtime coverage:

npm run operations:audit

Architecture Overview

   USER INPUT
       │
   INPUT PREPROCESSOR & FINGERPRINTING
   (Entropy, Character Ratios, Hex/B64/Morse/JWT/Magic Signatures)
       │
   OPERATION REGISTRY & CANDIDATE SELECTOR
   (497 Executable Local Operations)
       │
   AUTOMATED EXECUTION & SIGNAL SCORING
   (Language, JSON, XML, URL, Code, Magic Bytes, Evidence Weights)
       │
   RESULT DEDUPLICATION & TOP 10 RANKING
       │
   USER INTERFACE (React + Tailwind CSS)

Security & Privacy Model

CipherLens is designed around a strict client-side threat model:

  1. Local Execution: All data analysis occurs entirely in local browser memory.
  2. XSS Protection: Untrusted output strings are rendered strictly as native React text nodes (<code>{output}</code>), eliminating DOM XSS vectors.
  3. Prototype Pollution Defense: Input property mergers sanitize dangerous keys (__proto__, constructor, prototype).
  4. Input Size Limits: Enforces a 5MB analyzer input cap and 10MB workbench input cap to prevent browser memory exhaustion.
  5. URL Security: External link navigation validates protocol schemes, restricting execution strictly to http: and https: while blocking dangerous protocols (javascript:, data:).
  6. Private Network Boundaries: HTTP request validation classifies and flags private/loopback host targets (127.0.0.1, localhost, 10.x.x.x, 192.168.x.x, 169.254.169.254).
  7. Storage Isolation: localStorage persists strictly non-sensitive user options (theme selection and recentOpIds). Zero payload data or credentials are persisted.

Development & Build

Requirements

  • Node.js: v18.0.0 or higher
  • npm: v9.0.0 or higher

Local Setup

# Clone repository
git clone https://github.com/HIMANSHUSHARMA20/CipherLens.git
cd cipherlens

# Install dependencies
npm install

# Start development server
npm run dev

# Run Vitest test suite
npm run test

# Run Operation Audit report
npm run operations:audit

# Production build
npm run build

Browser Compatibility & Verification Scope

  • Verified Environment: Chromium-based browsers (Chrome, Edge, Brave, Opera) verified via automated and product-level release validation suite.
  • Other Browsers: Firefox, Safari, and other modern WebKit/Gecko-based browsers are expected to work where standard Web APIs (Web Workers, WebCrypto, ESM) are supported, but have not been independently validated in this release check.

Vercel Deployment

CipherLens is configured for zero-config direct deployment from GitHub to Vercel or any static web host (Netlify, Cloudflare Pages, GitHub Pages):

  1. Push your repository to GitHub.
  2. Import the repository into Vercel.
  3. Set Build Command: npm run build
  4. Set Output Directory: dist
  5. Deploy.

Pre-configured headers in public/_headers and vercel.json enforce Content Security Policy (CSP), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and Referrer-Policy: strict-origin-when-cross-origin.


License

MIT License. See LICENSE for details.

HIMANSHUSHARMA20/CipherLens

Privacy-first, local browser-based analyzer that detects and ranks likely data transformations for cybersecurity analysis.

TypeScript

0

1 commits

updated Sep 28, 2026

See the code

See what people are saying

SourceMessageScoreDate

I built CipherLens — a local-first tool that tries to identify what operation could explain unknown data (r/SideProject)

Hey everyone, I’ve been working on a cybersecurity tool called CipherLens. The idea came from a simple problem I kept running into with tools like CyberChef: You have some unknown data, but you don’t know which operation you should try first. Instead of manually guessing between Base64, Hex, URL…

1

Sep 29, 2026

README

CipherLens

"Don't guess the operation. Find it."

License: MIT Privacy: 100% Client-Side TypeScript Local Executable Operations

CipherLens is an open-source, local-first data transformation discovery and analysis tool designed for cybersecurity professionals, forensic analysts, CTF players, and developers.

Unlike traditional tools where users must manually guess and test operations one by one, CipherLens automates the discovery process. It analyzes unknown payloads, fingerprints input features, evaluates candidate transformations, validates outputs, scores results using content-type-aware heuristics, and presents ranked, evidence-backed candidate operations alongside a search-first Transformation Workbench.


Core Features

  • Automated Transformation Discovery: Input raw, obfuscated, or encrypted data streams and receive candidate operations ranked by confidence.
  • Content-Type-Aware Scoring Engine: Content validators evaluate Plain English, JSON, XML, URLs, JWT, Programming Syntax, Multilingual UTF-8, and File Magic Bytes without false-positive vocabulary penalties.
  • Search-First Transformation Workbench: Integrated operation selector with live search filtering, recent operations quick bar, technical specifications, and mathematical formulas for 497 operations.
  • Top 10 Candidate Ranking: Displays top meaningful candidates with evidence breakdowns detailing structural, language, entropy, and pattern signals.
  • Output Deduplication: Groups identical or near-duplicate candidate outputs to preserve candidate diversity.
  • 100% Client-Side & Privacy-First: All core operations run 100% locally inside your browser memory. Zero backend, zero database, zero tracking, zero telemetry, and zero hidden network calls.
  • Non-Blocking Web Worker Architecture: Offloads CPU-intensive analysis to a Web Worker for a smooth 60fps UI experience.
  • Strict Theme System: Supported in clean Light mode (default) and red-accented Dark mode.

Authoritative Operation Inventory

CipherLens implements the authoritative CyberChef-derived reference baseline:

  • 535 raw reference category entries
  • 501 unique canonical operations
  • 497 local executable operations (100% implemented)
    • 187 AUTO operations (Auto-detected, executed, scored)
    • 82 PARAMETER_REQUIRED operations (Keyed ciphers & parameterized transformations)
    • 228 MANUAL operations (Workbench transformations & parsers: 21 VERIFIED PASS, 206 EXECUTION VERIFIED, 1 BLOCKED pgp-encrypt-and-sign)
  • 3 explicit external operations (HTTP Request, DNS over HTTPS, Show on Map)
  • 1 reference-only concept (Magic)

Run the CLI audit tool to inspect runtime coverage:

npm run operations:audit

Architecture Overview

   USER INPUT
       │
   INPUT PREPROCESSOR & FINGERPRINTING
   (Entropy, Character Ratios, Hex/B64/Morse/JWT/Magic Signatures)
       │
   OPERATION REGISTRY & CANDIDATE SELECTOR
   (497 Executable Local Operations)
       │
   AUTOMATED EXECUTION & SIGNAL SCORING
   (Language, JSON, XML, URL, Code, Magic Bytes, Evidence Weights)
       │
   RESULT DEDUPLICATION & TOP 10 RANKING
       │
   USER INTERFACE (React + Tailwind CSS)

Security & Privacy Model

CipherLens is designed around a strict client-side threat model:

  1. Local Execution: All data analysis occurs entirely in local browser memory.
  2. XSS Protection: Untrusted output strings are rendered strictly as native React text nodes (<code>{output}</code>), eliminating DOM XSS vectors.
  3. Prototype Pollution Defense: Input property mergers sanitize dangerous keys (__proto__, constructor, prototype).
  4. Input Size Limits: Enforces a 5MB analyzer input cap and 10MB workbench input cap to prevent browser memory exhaustion.
  5. URL Security: External link navigation validates protocol schemes, restricting execution strictly to http: and https: while blocking dangerous protocols (javascript:, data:).
  6. Private Network Boundaries: HTTP request validation classifies and flags private/loopback host targets (127.0.0.1, localhost, 10.x.x.x, 192.168.x.x, 169.254.169.254).
  7. Storage Isolation: localStorage persists strictly non-sensitive user options (theme selection and recentOpIds). Zero payload data or credentials are persisted.

Development & Build

Requirements

  • Node.js: v18.0.0 or higher
  • npm: v9.0.0 or higher

Local Setup

# Clone repository
git clone https://github.com/HIMANSHUSHARMA20/CipherLens.git
cd cipherlens

# Install dependencies
npm install

# Start development server
npm run dev

# Run Vitest test suite
npm run test

# Run Operation Audit report
npm run operations:audit

# Production build
npm run build

Browser Compatibility & Verification Scope

  • Verified Environment: Chromium-based browsers (Chrome, Edge, Brave, Opera) verified via automated and product-level release validation suite.
  • Other Browsers: Firefox, Safari, and other modern WebKit/Gecko-based browsers are expected to work where standard Web APIs (Web Workers, WebCrypto, ESM) are supported, but have not been independently validated in this release check.

Vercel Deployment

CipherLens is configured for zero-config direct deployment from GitHub to Vercel or any static web host (Netlify, Cloudflare Pages, GitHub Pages):

  1. Push your repository to GitHub.
  2. Import the repository into Vercel.
  3. Set Build Command: npm run build
  4. Set Output Directory: dist
  5. Deploy.

Pre-configured headers in public/_headers and vercel.json enforce Content Security Policy (CSP), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and Referrer-Policy: strict-origin-when-cross-origin.


License

MIT License. See LICENSE for details.

Languages

TypeScript

99.6%