decalage2 / olefile
olefile is a Python package to parse, read and write Microsoft OLE2 files (also called Structured Storage, Compound File Binary Format or Compound Document File Format), such as Microsoft Office 97-2003 documents, vbaProject.bin in MS Office 2007+ files, Image Composer and FlashPix files, Outlook messages, StickyNotes, several Microscopy file fo…
☆239Updated 3 months ago
Alternatives and similar repositories for olefile:
Users that are interested in olefile are comparing it to the libraries listed below
- A VBA p-code disassembler☆461Updated 3 years ago
- Extract embedded files and macros from office documents.☆178Updated last year
- Library and tools to access the OLE 2 Compound File (OLECF) format☆69Updated 6 months ago
- ETW Python Library☆276Updated last year
- Python script to parse the NTFS USN Journal☆108Updated 2 years ago
- Windows registry file format specification☆337Updated 6 years ago
- Static analysis tools for Microsoft Office Open XML files and documents☆68Updated 7 years ago
- a vba pcode decompiler based on pcodedmp☆108Updated 3 years ago
- Yet another library library (and tools)☆205Updated last month
- Tool suite for inspecting NTFS artifacts.☆218Updated last year
- python eml parser module☆221Updated 3 months ago
- Pure Python parser for Windows Registry hives.☆427Updated 3 weeks ago
- Python bindings for The Sleuth Kit (libtsk)☆94Updated 2 months ago
- Trigram database written in C++, suited for malware indexing☆125Updated 4 months ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.☆276Updated 3 years ago
- Sample staging & detonation utility to be used in combination with Cuckoo Sandbox.☆82Updated last year
- VBA Dynamic Hook dynamically analyzes VBA macros inside Office documents by hooking function calls☆146Updated 8 years ago
- A tool for detecting VBA stomping.☆98Updated 2 years ago
- Parser for $LogFile on NTFS☆191Updated last year
- Windows Registry Knowledge Base☆171Updated 4 months ago
- EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.☆192Updated 4 years ago
- File and libmagic for Windows☆109Updated 4 years ago
- Python bindings for https://github.com/omerbenamram/evtx/☆50Updated 2 months ago
- Parser for $UsnJrnl on NTFS☆109Updated 2 years ago
- Regipy is an os independent python library for parsing offline registry hives☆252Updated 2 months ago
- Compressed Rich Text Format (RTF) compression and decompression in Python☆23Updated 10 months ago
- Windows Event Interactions in Python☆67Updated 3 months ago
- Smart DLL execution for malware analysis in sandbox systems☆143Updated 10 years ago
- Library and tools to access the Windows Shortcut File (LNK) format☆203Updated 4 months ago