Microsoft Office

Analyze Documents

SSView

Analyze OLE2 Structured Storage files.

Website: https://www.mitec.cz/ssv.htmlarrow-up-right Author: Michal Mutl License: Free to use for private, educational and non-commercial purposes. Notes: ssview State File: remnux.tools.ssviewarrow-up-right

msoffcrypto-tool

Decrypt a Microsoft Office file with password, intermediate key, or private key which generated its escrow key.

Website: https://github.com/nolze/msoffcrypto-toolarrow-up-right Author: nolze License: MIT License: https://github.com/nolze/msoffcrypto-tool/blob/master/LICENSE.txtarrow-up-right State File: remnux.python3-packages.msoffcrypto-toolarrow-up-right

pcodedmp

Disassemble VBA p-code.

Website: https://github.com/bontchev/pcodedmparrow-up-right Author: Vesselin Bontchev: https://twitter.com/bontchevarrow-up-right License: GNU General Public License (GPL) v3: https://github.com/bontchev/pcodedmp/blob/master/LICENSEarrow-up-right State File: remnux.python3-packages.pcodedmparrow-up-right

pcode2code

Decompile VBA macro p-code from Microsoft Office documents.

Website: https://github.com/Big5-sec/pcode2codearrow-up-right Author: Nicolas Zilio: https://twitter.com/Big5_secarrow-up-right License: GNU General Public License (GPL) v3: https://github.com/Big5-sec/pcode2code/blob/master/LICENSEarrow-up-right State File: remnux.python3-packages.pcode2codearrow-up-right

oletools

Microsoft Office OLE2 compound documents.

Website: http://www.decalage.info/python/oletoolsarrow-up-right Author: Philippe Lagadec: https://twitter.com/decalage2arrow-up-right License: Free, custom license: https://github.com/decalage2/oletools/blob/master/LICENSE.mdarrow-up-right Notes: mraptor, msodde, olebrowse, oledir, oleid, olemap, olemeta, oleobj, oletimes, olevba, pyxswf, rtfobj, ezhexviewer State File: remnux.python3-packages.oletoolsarrow-up-right

EvilClippy

Modify aspects of Microsoft Office documents.

Website: https://github.com/outflanknl/EvilClippyarrow-up-right Author: Stan Hegt: https://twitter.com/StanHackedarrow-up-right, with contributions from Carrie Roberts: https://twitter.com/OrOneEqualsOnearrow-up-right License: GNU General Public License (GPL) v3.0: https://github.com/outflanknl/EvilClippy/blob/master/LICENSE.mdarrow-up-right Notes: To remove VBA project password protection from the file, use the evilclippy -uu command. State File: remnux.packages.evilclippyarrow-up-right

XLMMacroDeobfuscator

Deobfuscate XLM macros (also known as Excel 4.0 macros) from Microsoft Office files.

Website: https://github.com/DissectMalware/XLMMacroDeobfuscatorarrow-up-right Author: https://twitter.com/DissectMalwarearrow-up-right License: Apache License 2.0: https://github.com/DissectMalware/XLMMacroDeobfuscator/blob/master/LICENSEarrow-up-right Notes: xlmdeobfuscator State File: remnux.python3-packages.xlmmacrodeobfuscatorarrow-up-right

ViperMonkey

A VBA parser and emulation engine to analyze malicious macros.

Website: https://www.decalage.info/en/vba_emulationarrow-up-right Author: Philippe Lagadec: https://twitter.com/decalage2arrow-up-right License: Free, custom license: https://github.com/decalage2/ViperMonkey#licensearrow-up-right Notes: Only available on older version of REMnux based on Ubuntu 20.04 (Focal). vmonkey State File: remnux.python3-packages.vipermonkeyarrow-up-right

msoffcrypto-crack.py

Recover the password of an encrypted Microsoft Office document.

Website: https://blog.didierstevens.com/2018/12/31/new-tool-msoffcrypto-crack-py/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.msoffcrypto-crackarrow-up-right

rtfdump

Analyze a suspicious RTF file.

Website: https://blog.didierstevens.com/2018/12/10/update-rtfdump-py-version-0-0-9/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain Notes: rtfdump.py State File: remnux.scripts.rtfdumparrow-up-right

zipdump.py

Analyze zip-compressed files.

Website: https://blog.didierstevens.com/2020/07/27/update-zipdump-py-version-0-0-20/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.zipdumparrow-up-right

xmldump.py

Extract contents of XML files, in particular OOXML-formatted Microsoft Office documents.

Website: https://blog.didierstevens.com/2017/12/18/new-tool-xmldump-py/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain State File: remnux.scripts.zipdumparrow-up-right

oledump

Analyze OLE2 Structured Storage files.

Website: https://blog.didierstevens.com/programs/oledump-py/arrow-up-right Author: Didier Stevens: https://twitter.com/DidierStevensarrow-up-right License: Public Domain Notes: oledump.py State File: remnux.packages.oledumparrow-up-right

libolecf

Microsoft Office OLE2 compound documents.

Website: https://github.com/libyal/libolecfarrow-up-right Author: Joachim Metz License: GNU Lesser General Public License (LGPL) v3+: https://github.com/libyal/libolecf/blob/master/COPYINGarrow-up-right Notes: olecfexport, olecfinfo, olecfmount, etc. State File: remnux.packages.libolecfarrow-up-right

msoffice-crypt

Encrypt and decrypt OOXML Microsoft Office documents.

Website: https://github.com/herumi/msofficearrow-up-right Author: Cybozu Labs Inc., Mitsunari Shigeo: https://twitter.com/herumiarrow-up-right License: Free, custom license: https://github.com/herumi/msoffice/blob/master/COPYRIGHTarrow-up-right State File: remnux.packages.msoffice-cryptarrow-up-right

Hachoir

View, edit, and carve contents of various binary file types.

Website: https://github.com/vstinner/hachoirarrow-up-right Author: https://hachoir.readthedocs.io/en/latest/authors.htmlarrow-up-right License: GNU General Public License (GPL) v2: https://github.com/vstinner/hachoir/blob/master/COPYINGarrow-up-right Notes: hachoir-grep, hachoir-metadata, hachoir-strip, hachoir-wx State File: remnux.python3-packages.hachoirarrow-up-right

olefile

Python package to parse, read and write MS OLE2 files.

Website: https://github.com/decalage2/olefilearrow-up-right Author: Philippe Lagadec License: All Rights Reserved (https://github.com/decalage2/olefile/blob/master/LICENSE.txt)arrow-up-right) State File: remnux.python3-packages.olefilearrow-up-right

Last updated