Logo white

Peter M. Groen / oletools

Sign in
  • Sign in
  • Project
  • Files
  • Commits
  • Network
  • Graphs
  • Milestones
  • Issues 0
  • Merge Requests 0
  • Labels
  • Wiki
  • Commits 1,521
  • Compare
  • Branches 1
  • Tags 0
  • oletools
26 May, 2015
3 commits
  • olevba: added is_mso_file function
    4795c8b9
    Philippe Lagadec authored
    2015-05-26 21:53:04 +0200  
    Browse Code »
  • updated olefile to v0.43 (slight changes in _OleDirectoryEntry)
    77842b93
    Philippe Lagadec authored
    2015-05-26 21:52:36 +0200  
    Browse Code »
  • updated doc and setup.py
    15a9744c
    Philippe Lagadec authored
    2015-05-26 21:50:43 +0200  
    Browse Code »

24 May, 2015
1 commit
  • improved support for MHTML files with modified header: fixed issue #11
    bdad8c14
    Philippe Lagadec authored
    2015-05-24 22:26:04 +0200  
    Browse Code »

06 May, 2015
5 commits
  • updated readme with link to issue #10
    fad632c5
    Philippe Lagadec authored
    2015-05-06 15:13:31 +0200  
    Browse Code »
  • updated setup.py for v0.10
    eb29007c
    Philippe Lagadec authored
    2015-05-06 15:03:12 +0200  
    Browse Code »
  • updated doc home for v0.10
    7336f730
    Philippe Lagadec authored
    2015-05-06 14:56:52 +0200  
    Browse Code »
  • updated readme and doc
    f2ead51c
    Philippe Lagadec authored
    2015-05-06 14:55:45 +0200  
    Browse Code »
  • added support for Word MHTML files with macros (Single File Web Page), fixed issue #10
    0762f5bb
    Philippe Lagadec authored
    2015-05-06 14:49:39 +0200  
    Browse Code »

23 Mar, 2015
3 commits
  • updated readme and doc
    dc628fab
    Philippe Lagadec authored
    2015-03-23 21:43:36 +0100  
    Browse Code »
  • setup.py: added shebang line, chmod +x
    d1f62d20
    Philippe Lagadec authored
    2015-03-23 19:41:57 +0100  
    Browse Code »
  • updated setup.py
    b4b61695
    Philippe Lagadec authored
    2015-03-23 16:56:38 +0100  
    Browse Code »

22 Mar, 2015
1 commit
  • olevba: added suspicious keywords for sandboxing and virtualisation detection
    75e413f5
    Philippe Lagadec authored
    2015-03-22 17:35:25 +0100  
    Browse Code »

19 Mar, 2015
3 commits
  • set all scripts as executable on Linux/Unix
    91642895
    Philippe Lagadec authored
    2015-03-19 09:14:07 +0100  
    Browse Code »
  • changed line endings from CRLF to LF in all scripts to improve Linux/Unix compatibility
    cda79757
    Philippe Lagadec authored
    2015-03-19 08:49:56 +0100  
    Browse Code »
  • olevba: changed line endings from CRLF to LF
    a4ffb743
    Philippe Lagadec authored
    2015-03-19 08:20:13 +0100  
    Browse Code »

04 Mar, 2015
3 commits
  • olevba: added banner with version
    41896bcf
    Philippe Lagadec authored
    2015-03-04 22:31:14 +0100  
    Browse Code »
  • olevba: updated description
    74cd7ccb
    Philippe Lagadec authored
    2015-03-04 22:28:47 +0100  
    Browse Code »
  • olevba: added support for Word 2003 XML
    70b7bfb6
    Philippe Lagadec authored
    2015-03-04 22:27:31 +0100  
    Browse Code »

28 Feb, 2015
2 commits
  • olevba: updated description in code
    ec719fa9
    Philippe Lagadec authored
    2015-02-28 19:01:04 +0100  
    Browse Code »
  • olevba: fixed issue #5 in doc, --hex option renamed to --decode
    13a71c47
    Philippe Lagadec authored
    2015-02-28 19:00:09 +0100  
    Browse Code »

08 Feb, 2015
6 commits
  • updated setup.py for v0.08
    6c64d5d1
    Philippe Lagadec authored
    2015-02-08 22:46:16 +0100  
    Browse Code »
  • updated doc and readme
    430c7b98
    Philippe Lagadec authored
    2015-02-08 22:42:15 +0100  
    Browse Code »
  • olevba: improved VBA_Scanner and scan_vba API
    cdbcd101
    Philippe Lagadec authored
    2015-02-08 17:16:15 +0100  
    Browse Code »
  • olevba: updated VBA_Parser docstring
    7d530ddb
    Philippe Lagadec authored
    2015-02-08 16:45:56 +0100  
    Browse Code »
  • olevba: improved Base64 decoding, fixed triage mode not to scan attrib lines
    b984e77a
    Philippe Lagadec authored
    2015-02-08 16:27:53 +0100  
    Browse Code »
  • oleid: added comments
    aca4787e
    Philippe Lagadec authored
    2015-02-08 16:23:51 +0100  
    Browse Code »

07 Feb, 2015
4 commits
  • olevba: improved Base64 detection and decoding
    67f0725b
    Philippe Lagadec authored
    2015-02-07 15:16:38 +0100  
    Browse Code »
  • olevba: added several suspicious keywords
    8f37786d
    Philippe Lagadec authored
    2015-02-07 14:45:10 +0100  
    Browse Code »
  • olevba: display exceptions with stack trace
    f854f4df
    Philippe Lagadec authored
    2015-02-07 14:41:13 +0100  
    Browse Code »
  • olevba: renamed option --hex to --decode, fixed display
    e011de51
    Philippe Lagadec authored
    2015-02-07 14:17:52 +0100  
    Browse Code »

05 Feb, 2015
1 commit
  • updated readme for v0.08
    0bc2449b
    Philippe Lagadec authored
    2015-02-05 16:00:39 +0100  
    Browse Code »

03 Feb, 2015
1 commit
  • olevba: triage now uses VBA_Scanner results, shows Base64 and Dridex strings, ex… ...
    9a505c80
    …ception handling in detect_base64_strings
    Philippe Lagadec authored
    2015-02-03 22:28:07 +0100  
    Browse Code »

01 Feb, 2015
2 commits
  • olevba: added Base64 obfuscation decoding (contribution from @JamesHabben)
    5dfb7b56
    Philippe Lagadec authored
    2015-02-01 21:37:35 +0100  
    Browse Code »
  • olevba: fixed issue #4: regex for URL, e-mail and exe filename
    89272589
    Philippe Lagadec authored
    2015-02-01 20:55:42 +0100  
    Browse Code »

29 Jan, 2015
2 commits
  • olevba: added DridexUrlDecoder from James Habben
    b56f9ef7
    Philippe Lagadec authored
    2015-01-29 22:49:30 +0100  
    Browse Code »
  • olevba: added Dridex obfuscation decoding, improved display, shows obfuscation name
    732e9a0a
    Philippe Lagadec authored
    2015-01-29 22:48:08 +0100  
    Browse Code »

26 Jan, 2015
2 commits
  • olevba: added option --hex to show all hex strings decoded
    bcbb6086
    Philippe Lagadec authored
    2015-01-26 06:43:45 +0100  
    Browse Code »
  • updated olefile to v0.42
    5d3718da
    Philippe Lagadec authored
    2015-01-26 06:19:34 +0100  
    Browse Code »

24 Jan, 2015
1 commit
  • olevba: improved the detection of IOCs obfuscated with hex strings and StrReverse
    4c98aa7a
    Philippe Lagadec authored
    2015-01-24 22:04:02 +0100  
    Browse Code »