decalage2 / oletools

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
http://www.decalage.info/python/oletools
Other
2.88k stars 564 forks source link

olevba+mraptor - add more VBA triggers #228

Open decalage2 opened 6 years ago

decalage2 commented 6 years ago

See https://github.com/BrunoMCBraga/VBA-Macros-Events-Cheat-Sheet/ which mentions additional triggers. And also:

decalage2 commented 6 years ago

Here is a sample using app_WindowSelectionChange: https://twitter.com/JohnLaTwC/status/957700127166119936