Logo white

Peter M. Groen / oletools

Sign in
  • Sign in
  • Project
  • Files
  • Commits
  • Network
  • Graphs
  • Milestones
  • Issues 0
  • Merge Requests 0
  • Labels
  • Wiki
  • Commits 1,521
  • Compare
  • Branches 1
  • Tags 0
  • oletools
08 Feb, 2015
2 commits
  • olevba: improved Base64 decoding, fixed triage mode not to scan attrib lines
    b984e77a
    Philippe Lagadec authored
    2015-02-08 16:27:53 +0100  
    Browse Code »
  • oleid: added comments
    aca4787e
    Philippe Lagadec authored
    2015-02-08 16:23:51 +0100  
    Browse Code »

07 Feb, 2015
4 commits
  • olevba: improved Base64 detection and decoding
    67f0725b
    Philippe Lagadec authored
    2015-02-07 15:16:38 +0100  
    Browse Code »
  • olevba: added several suspicious keywords
    8f37786d
    Philippe Lagadec authored
    2015-02-07 14:45:10 +0100  
    Browse Code »
  • olevba: display exceptions with stack trace
    f854f4df
    Philippe Lagadec authored
    2015-02-07 14:41:13 +0100  
    Browse Code »
  • olevba: renamed option --hex to --decode, fixed display
    e011de51
    Philippe Lagadec authored
    2015-02-07 14:17:52 +0100  
    Browse Code »

05 Feb, 2015
1 commit
  • updated readme for v0.08
    0bc2449b
    Philippe Lagadec authored
    2015-02-05 16:00:39 +0100  
    Browse Code »

03 Feb, 2015
1 commit
  • olevba: triage now uses VBA_Scanner results, shows Base64 and Dridex strings, ex… ...
    9a505c80
    …ception handling in detect_base64_strings
    Philippe Lagadec authored
    2015-02-03 22:28:07 +0100  
    Browse Code »

01 Feb, 2015
2 commits
  • olevba: added Base64 obfuscation decoding (contribution from @JamesHabben)
    5dfb7b56
    Philippe Lagadec authored
    2015-02-01 21:37:35 +0100  
    Browse Code »
  • olevba: fixed issue #4: regex for URL, e-mail and exe filename
    89272589
    Philippe Lagadec authored
    2015-02-01 20:55:42 +0100  
    Browse Code »

29 Jan, 2015
2 commits
  • olevba: added DridexUrlDecoder from James Habben
    b56f9ef7
    Philippe Lagadec authored
    2015-01-29 22:49:30 +0100  
    Browse Code »
  • olevba: added Dridex obfuscation decoding, improved display, shows obfuscation name
    732e9a0a
    Philippe Lagadec authored
    2015-01-29 22:48:08 +0100  
    Browse Code »

26 Jan, 2015
2 commits
  • olevba: added option --hex to show all hex strings decoded
    bcbb6086
    Philippe Lagadec authored
    2015-01-26 06:43:45 +0100  
    Browse Code »
  • updated olefile to v0.42
    5d3718da
    Philippe Lagadec authored
    2015-01-26 06:19:34 +0100  
    Browse Code »

24 Jan, 2015
3 commits
  • olevba: improved the detection of IOCs obfuscated with hex strings and StrReverse
    4c98aa7a
    Philippe Lagadec authored
    2015-01-24 22:04:02 +0100  
    Browse Code »
  • olefile: fixed a bug in _list when a storage is empty
    6b3088fe
    Philippe Lagadec authored
    2015-01-24 21:51:02 +0100  
    Browse Code »
  • improved olefile to specify the encoding for path names, changed default to UTF-… ...
    7a9cb922
    …8 on python 2.x to support non-Latin1 code pages
    Philippe Lagadec authored
    2015-01-24 21:41:22 +0100  
    Browse Code »

23 Jan, 2015
1 commit
  • olevba: fixed issue #3, case-insensitive search in code_modules
    1d05bbab
    Philippe Lagadec authored
    2015-01-23 18:06:18 +0100  
    Browse Code »

17 Jan, 2015
2 commits
  • olevba: removed .application from the list of executable extensions, scan reversed hex strings
    be1d4830
    Philippe Lagadec authored
    2015-01-17 23:40:26 +0100  
    Browse Code »
  • olevba: removed .com from the list of executable extensions, added scan_vba to r… ...
    782a5267
    …un all detection algorithms, decoded hex strings are now also scanned
    Philippe Lagadec authored
    2015-01-17 23:20:57 +0100  
    Browse Code »

16 Jan, 2015
3 commits
  • olevba: added option -i to analyze VBA source code directly
    249db149
    Philippe Lagadec authored
    2015-01-16 23:13:32 +0100  
    Browse Code »
  • olevba: added several suspicious keywords
    1586b7e9
    Philippe Lagadec authored
    2015-01-16 22:53:39 +0100  
    Browse Code »
  • olevba: fix for issue #3 (exception when module name="text")
    518dae05
    Philippe Lagadec authored
    2015-01-16 14:27:18 +0100  
    Browse Code »

11 Jan, 2015
1 commit
  • olevba: added new triage mode, options -t and -d
    ebdb4e2d
    Philippe Lagadec authored
    2015-01-11 17:00:49 +0100  
    Browse Code »

08 Jan, 2015
2 commits
  • olevba: fixed issue #2, decoding VBA stream names using specified codepage and e… ...
    56759d61
    …nabling unicode stream names in olefile
    Philippe Lagadec authored
    2015-01-08 23:13:01 +0100  
    Browse Code »
  • olevba: added hex strings detection and decoding
    9f45875a
    Philippe Lagadec authored
    2015-01-08 17:07:38 +0100  
    Browse Code »

05 Jan, 2015
8 commits
  • updated readme and doc
    85f94f92
    Philippe Lagadec authored
    2015-01-05 22:54:51 +0100  
    Browse Code »
  • olevba: fixed small bug in suspicious keywords
    caa1e066
    Philippe Lagadec authored
    2015-01-05 22:48:15 +0100  
    Browse Code »
  • updated readme
    c6db08ab
    Philippe Lagadec authored
    2015-01-05 21:47:41 +0100  
    Browse Code »
  • updated license
    0e57ddbe
    Philippe Lagadec authored
    2015-01-05 21:38:52 +0100  
    Browse Code »
  • updated readme
    ec7f6a7f
    Philippe Lagadec authored
    2015-01-05 21:38:02 +0100  
    Browse Code »
  • updated setup.py for v0.07, including xglob and prettytable
    7a54e113
    Philippe Lagadec authored
    2015-01-05 21:32:52 +0100  
    Browse Code »
  • xglob: added license.txt
    8aa2e9bc
    Philippe Lagadec authored
    2015-01-05 21:29:12 +0100  
    Browse Code »
  • Merged in jkothamb/oletools-1/jkothamb/missed-dependency-1420410202661 (pull request #2) ...
    058a8e09
    missed dependency
    Philippe Lagadec authored
    2015-01-05 08:15:21 +0100  
    Browse Code »

04 Jan, 2015
2 commits
  • missed dependency
    89c7c2ea
    Juzar Kothambawala authored
    2015-01-04 22:22:32 +0000  
    Browse Code »
  • olevba: added several suspicious keywords, improved display
    8e04c154
    Philippe Lagadec authored
    2015-01-04 17:19:34 +0100  
    Browse Code »

03 Jan, 2015
4 commits
  • updated readme
    2939f491
    Philippe Lagadec authored
    2015-01-03 14:59:17 +0100  
    Browse Code »
  • olevba: added comments about executable filenames regex
    2575a66f
    Philippe Lagadec authored
    2015-01-03 14:50:20 +0100  
    Browse Code »
  • olevba: improved display
    1f318944
    Philippe Lagadec authored
    2015-01-03 14:32:16 +0100  
    Browse Code »
  • olevba: improved display, shows container file
    23169cd9
    Philippe Lagadec authored
    2015-01-03 13:48:26 +0100  
    Browse Code »