Decode JSFuck: Recover the Original JavaScript Without Running It
Paste a bracket-only ([]()!+) payload into a JSFuck decoder and get readable JavaScript back without executing it, covering alert(), XSS payloads, and hybrid JSFireTruck stubs.
Static analysis for stage 1 interdiction
Fully automatic multi-layer malware analysis. Finally something fast enough for a live incident. Not a sandbox. No detonation, no queue.
Attackers stack Base64, XOR, compression, and string tricks to burn your time.
KlaroSkope peels back every layer automatically. Paste a sample, get the payload and detection rules. In seconds, not hours.
One free analysis. No signup needed.
Sample handling
Your sample, handled like evidence.
Parsed, not executed
Analysis method
Algorithmic analysis. Not AI guesswork.
Same input, same output
Capability index
Decodes techniques including Base64, XOR, RC4, GZIP, PowerShell EncodedCommand, JSFuck, obfuscator.io, VBA and XLM macros, and LSB steganography.
Scripts, PDFs, Office documents, images, SVG, extensions, emails, archives. Every analysis delivers actionable intelligence
130+ decoding techniques handle Base64, XOR, GZIP, PowerShell, esoteric JavaScript (JSFuck, JJEncode, AAEncode), and more. Recursive decoding through 20+ layers.
12 techniques: LSB encoding, EXIF injection, PNG chunk abuse, IDAT payloads, polyglot files, EOF appended data, alpha channel encoding. Extracted payloads auto-fed to deobfuscation.
Chrome (.crx) and Firefox (.xpi) analysis. V3 manifest parsing, permission risk scoring, JS deobfuscation, and stego extraction from extension assets.
Structure analysis, JavaScript extraction, embedded file detection, form field inspection, phishing kit attribution, and risk verdicts. Embedded images auto-scanned for steganography.
VBA macro extraction, OLE2 and OOXML parsing, embedded object detection, and payload analysis. Supports macro-enabled formats (.docm, .xlsm, .pptm), templates, and add-ins.
Phishing triage for .eml and .msg files. SPF, DKIM, and DMARC authentication checks, received-chain inspection, and recursive attachment analysis through the decoder pipeline.
ZIP, RAR, 7z, TAR, and CAB extraction with common-password attempts and zip-bomb safeguards. Every extracted file is routed to its matching analysis vector.
SVG is XML markup, not a picture. Inline scripts, external script references inside foreignObject, navigation attributes, data URIs, and base64 payloads are extracted from .svg and .svgz and routed to the decoder pipeline.
URLs, IPs, domains, file paths, registry keys, hashes. Pulled automatically from decoded output across all analysis vectors.
Your time goes to the threat, not its wrapper.
Paste scripts, upload images with hidden payloads, drop browser extensions, or submit Office documents, PDFs, SVG files, emails, and archives.
Script deobfuscation, steganography extraction, PDF threat analysis, Office macro analysis, SVG smuggling extraction, extension forensics, email and archive unpacking, IOC extraction, MITRE mapping. All automatic.
Export rules, grab IOCs, file the report. Back to threat hunting.
LLMs are powerful, but multi-layer deobfuscation breaks their accuracy model
Even 95% per-layer accuracy sounds great until you stack 21 layers. Deflate, Base64, char codes, XOR with rolling key. The more layers, the worse it gets.
Stacked LLM callsCompounding errors, compounding costs
KlaroSkopeConsistent results, first layer to last
Errors compound exponentially for LLMs. Deterministic execution stays consistent regardless of depth. Your report is reproducible evidence, not a model's best guess.
Read the full analysisDeep dives into script obfuscation techniques and how to defeat them
No signup. No credit card. Paste something ugly and watch it decode.
Try It FreeBuilt by a CISSP threat-detection engineer. Read why