Logo white

Peter M. Groen / oletools

Sign in
  • Sign in
  • Project
  • Files
  • Commits
  • Network
  • Graphs
  • Milestones
  • Issues 0
  • Merge Requests 0
  • Labels
  • Wiki
  • Commits 1,521
  • Compare
  • Branches 1
  • Tags 0
  • oletools
17 Sep, 2015
1 commit
  • updated readme for v0.40
    f1cefbd4
    Philippe Lagadec authored
    2015-09-17 20:52:08 +0200  
    Browse Code »

16 Sep, 2015
2 commits
  • setup.py: sync oletools version number with olevba (0.40)
    57ec6e29
    Philippe Lagadec authored
    2015-09-16 21:52:42 +0200  
    Browse Code »
  • olevba: join long VBA lines ending with underscore before scan, disabled unused option --each
    63ec91ed
    Philippe Lagadec authored
    2015-09-16 21:35:37 +0200  
    Browse Code »

15 Sep, 2015
1 commit
  • olevba: remove duplicate IOCs from results
    6569631d
    Philippe Lagadec authored
    2015-09-15 22:39:40 +0200  
    Browse Code »

13 Sep, 2015
1 commit
  • olevba: moved main functions to a class VBA_Parser_CLI, fixed issue when analysis was done twice
    e6d5614b
    Philippe Lagadec authored
    2015-09-13 21:47:01 +0200  
    Browse Code »

06 Sep, 2015
1 commit
  • olevba: improved VBA_Parser, refactored the main CLI functions
    e6148632
    Philippe Lagadec authored
    2015-09-06 16:16:55 +0200  
    Browse Code »

28 Jul, 2015
1 commit
  • doc: fixed olevba.html (removed malicious code to avoid AV warnings)
    7c2a7d81
    Philippe Lagadec authored
    2015-07-28 15:36:12 +0200  
    Browse Code »

13 Jul, 2015
1 commit
  • olevba: added Base64 function decoding to VBA Parser
    4991f1ae
    Philippe Lagadec authored
    2015-07-13 16:06:42 +0200  
    Browse Code »

12 Jul, 2015
3 commits
  • olevba: removed malicious code from documentation to avoid triggering antivirus
    41d98ad5
    Philippe Lagadec authored
    2015-07-12 15:26:57 +0200  
    Browse Code »
  • olevba: added Hex function decoding to VBA Parser
    aaa7c73f
    Philippe Lagadec authored
    2015-07-12 15:21:50 +0200  
    Browse Code »
  • olevba: removed usage of sys.stderr which causes issues (fixed issue #23)
    cbbb5d20
    Philippe Lagadec authored
    2015-07-12 15:18:40 +0200  
    Browse Code »

21 Jun, 2015
1 commit
  • olevba: display decoded strings which are printable by default, fixed VBA_Scanne… ...
    bf3fd0ac
    …r.scan to return raw strings instead of repr(strings)
    Philippe Lagadec authored
    2015-06-21 22:50:40 +0200  
    Browse Code »

19 Jun, 2015
4 commits
  • fixed readme and doc
    e6c4676f
    Philippe Lagadec authored
    2015-06-19 22:13:41 +0200  
    Browse Code »
  • updated readme and doc for oletools 0.12
    6e4e7d5f
    Philippe Lagadec authored
    2015-06-19 22:08:31 +0200  
    Browse Code »
  • olevba: improved display during long analysis
    bd53eff6
    Philippe Lagadec authored
    2015-06-19 21:48:42 +0200  
    Browse Code »
  • olevba: added options -a, -c, --each, --attr
    2fa4c06c
    Philippe Lagadec authored
    2015-06-19 20:31:40 +0200  
    Browse Code »

16 Jun, 2015
4 commits
  • olevba: display VBA obfuscation flag in triage mode
    ac8bddb7
    Philippe Lagadec authored
    2015-06-16 22:44:56 +0200  
    Browse Code »
  • olevba: added pyparsing into thirdparty folder
    ab1ba65e
    Philippe Lagadec authored
    2015-06-16 21:57:53 +0200  
    Browse Code »
  • olevba: added pyparsing into thirdparty folder
    b9b82e25
    Philippe Lagadec authored
    2015-06-16 21:57:17 +0200  
    Browse Code »
  • olevba: added generic VBA expression deobfuscation (chr,asc,etc) using pyparsing
    f1944c35
    Philippe Lagadec authored
    2015-06-16 19:20:54 +0200  
    Browse Code »

29 May, 2015
4 commits
  • updated setup and doc for oletools 0.11
    58773840
    Philippe Lagadec authored
    2015-05-29 22:48:12 +0200  
    Browse Code »
  • olevba: added suspicious keywords - fixed issue #13
    46b4b11d
    Philippe Lagadec authored
    2015-05-29 22:36:35 +0200  
    Browse Code »
  • olevba: added suspicious keywords suggested by Davy Douhine - fixed issue #9
    cf11d960
    Philippe Lagadec authored
    2015-05-29 22:33:40 +0200  
    Browse Code »
  • olevba: added suspicious keyword suggested by @ozhermit
    9f16427f
    Philippe Lagadec authored
    2015-05-29 22:27:59 +0200  
    Browse Code »

26 May, 2015
4 commits
  • olevba: improved MSO files parsing, taking into account ...
    75259a45
    various data offsets (fixed issue #12) - improved detection of MSO files, avoiding incorrect parsing errors (fixed issue #7)
    Philippe Lagadec authored
    2015-05-26 23:25:17 +0200  
    Browse Code »
  • olevba: added is_mso_file function
    4795c8b9
    Philippe Lagadec authored
    2015-05-26 21:53:04 +0200  
    Browse Code »
  • updated olefile to v0.43 (slight changes in _OleDirectoryEntry)
    77842b93
    Philippe Lagadec authored
    2015-05-26 21:52:36 +0200  
    Browse Code »
  • updated doc and setup.py
    15a9744c
    Philippe Lagadec authored
    2015-05-26 21:50:43 +0200  
    Browse Code »

24 May, 2015
1 commit
  • improved support for MHTML files with modified header: fixed issue #11
    bdad8c14
    Philippe Lagadec authored
    2015-05-24 22:26:04 +0200  
    Browse Code »

06 May, 2015
5 commits
  • updated readme with link to issue #10
    fad632c5
    Philippe Lagadec authored
    2015-05-06 15:13:31 +0200  
    Browse Code »
  • updated setup.py for v0.10
    eb29007c
    Philippe Lagadec authored
    2015-05-06 15:03:12 +0200  
    Browse Code »
  • updated doc home for v0.10
    7336f730
    Philippe Lagadec authored
    2015-05-06 14:56:52 +0200  
    Browse Code »
  • updated readme and doc
    f2ead51c
    Philippe Lagadec authored
    2015-05-06 14:55:45 +0200  
    Browse Code »
  • added support for Word MHTML files with macros (Single File Web Page), fixed issue #10
    0762f5bb
    Philippe Lagadec authored
    2015-05-06 14:49:39 +0200  
    Browse Code »

23 Mar, 2015
3 commits
  • updated readme and doc
    dc628fab
    Philippe Lagadec authored
    2015-03-23 21:43:36 +0100  
    Browse Code »
  • setup.py: added shebang line, chmod +x
    d1f62d20
    Philippe Lagadec authored
    2015-03-23 19:41:57 +0100  
    Browse Code »
  • updated setup.py
    b4b61695
    Philippe Lagadec authored
    2015-03-23 16:56:38 +0100  
    Browse Code »

22 Mar, 2015
1 commit
  • olevba: added suspicious keywords for sandboxing and virtualisation detection
    75e413f5
    Philippe Lagadec authored
    2015-03-22 17:35:25 +0100  
    Browse Code »

19 Mar, 2015
2 commits
  • set all scripts as executable on Linux/Unix
    91642895
    Philippe Lagadec authored
    2015-03-19 09:14:07 +0100  
    Browse Code »
  • changed line endings from CRLF to LF in all scripts to improve Linux/Unix compatibility
    cda79757
    Philippe Lagadec authored
    2015-03-19 08:49:56 +0100  
    Browse Code »