0xm4v3rick / Extract-MacroLinks
This PS script will extract macro from Excel and Word files. Also checks the macro for suspecious code patterns Includes temporary DDE check for word documents
☆34Updated last year
Alternatives and similar repositories for Extract-Macro
Users that are interested in Extract-Macro are comparing it to the libraries listed below
Sorting:
- A sample of proof of concept scripts that run Calc.exe with full source code.☆96Updated 11 months ago
- DLL Password Filter Implant with Exfiltration Capabilities☆138Updated 5 years ago
- ☆62Updated 5 years ago
- A tool for detecting VBA stomping.☆100Updated 3 years ago
- A simple python implementation of a BITS server.☆105Updated 3 years ago
- WMI Shell project : proof-of-concept of remote access to a Windows machine using only the WMI service.☆44Updated 6 years ago
- ☆93Updated 3 years ago
- DPAPI offline decryption utility☆70Updated 2 years ago
- A simple XLL, showing how to create an XLL from scratch.☆48Updated 9 years ago
- ☆58Updated 4 years ago
- SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and …☆76Updated 2 years ago
- A repository of example VBA stomped documents☆28Updated 6 years ago
- Dumping credentials through windbg and pykd☆41Updated last year
- InsecurePowerShell is PowerShell with some security features removed.☆105Updated 7 years ago
- Presentation material presented by Outflank team members at public events.☆190Updated 8 months ago
- Labs setup for tests & experimentations☆26Updated 3 years ago
- SettingContent-MS File Execution vulnerability in Windows 10☆25Updated 6 months ago
- ReVBShell - Reverse VBS Shell☆82Updated 5 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆157Updated 3 years ago
- SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers☆123Updated last year
- A repository of some of my Windows 10 Device Guard Bypasses☆138Updated 8 years ago
- Inject Encrypted Commands Into EMF Shapes for C2 In VBA / Office Malware☆38Updated 5 years ago
- AdHoc solutions☆48Updated last year
- Windows Shortcut file (LNK) parser☆135Updated 2 years ago
- A set of commands to bypass Defender (and some other AVs)☆20Updated 6 years ago
- ☆67Updated 2 years ago
- 64bit Windows 10 shellcode that injects all processes with Meterpreter reverse shells.☆130Updated 2 years ago
- Windows link file (shortcuts) examiner☆68Updated last year