name: char_conversion_matrix id: 0177cf7b-8cf9-412a-9919-d1919b8d59dc version: 3 creation_date: '2024-01-10' modification_date: '2026-05-13' author: Splunk Threat Research Team lookup_type: csv description: A simple conversion matrix for converting to and from UTF8/16 base64/hex/decimal encoding. Created mosty from https://community.splunk.com/t5/Splunk-Search/base64-decoding-in-search/m-p/27572#M177741, with small modifications for UTF16LE parsing for powershell encoding. match_type: - WILDCARD(data) min_matches: 1 case_sensitive_match: true