> For the complete documentation index, see [llms.txt](https://sandyzeng.gitbook.io/kql/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sandyzeng.gitbook.io/kql/kql-quick-guide/need-to-learn-later/decode.md).

# decode

This is example from WPNinja Summit 2022 session "Throwing KQL like a shuriken". Presented by Gianni Castaldi and Alex Verboon&#x20;

####

```
DeviceProcessEvents
| extend EncodedString = extract(@" -[eE][^xXrR]\S* ([a-zA-Z0-9]*={0,2})", 1, ProcessCommandLine)
| where isnotempty(EncodedString)

DeviceProcessEvents
| extend EncodedString = extract(@" -[eE][^xXrR]\S* ([a-zA-Z0-9]*={0,2})", 1, ProcessCommandLine)
| where isnotempty(EncodedString)
| where strlen(EncodedString) >= 4
| extend DecodedString = base64_decode_tostring(EncodedString)
| where isnotempty(DecodedString)
| extend DecodedString = replace_string(DecodedString, "\x00", "")
| project-reorder Timestamp, DecodedString
```
