sublime-security / sublime-platform

A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. Gain visibility and control, hunt for advanced threats, collaborate with the community, and write detections-as-code.
https://sublime.security
MIT License
163 stars 14 forks source link

VBA Stomping in ole scan is not displayed inside Sublime #126

Open KaremAli1 opened 1 year ago

KaremAli1 commented 1 year ago

if you uploaded an email having an attachment with VBA-stomping technique and you viewed the FileExplode output of the oletools you will not find the VBA stomping while using olevba outside of sublime shows that the file has VBA stomping

oletools output (installed locally):

image

oletools output inside sublime:

image