killchain-compendium/Forensics/OLEtools.md

576 B

oletools & Vmonkey

Usage

OLEtools

  • Check content of a stream
oledump.py file.doc  -Ss <No. of stream>
oledump.py file.doc  -Ss <No. of stream> -v
oledump.py -i file.doc
olevba file.doc

Vipermonkey

  • For the lazy ones
vmonkey file.doc

scdbg

Outlook

  • Outlook files like .msg can be read and changed to by perl-email-outlook-message via
msgconvert *.msg