Open decalage2 opened 7 years ago
olevba: done in commit b9b9af8.
Potentially more keywords to detect techniques for macros that create other VBA macros by launching a new Word/Excel application via COM:
isVBOMEnabled
: checks if VBOM access is allowed
Add several keywords to detect macros that attempt to disable protection to run self-modifying VBA code, as described in those articles:
As listed in the Trend Micro article, this includes:
TODO: