NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1375 most downloaded on PyPI
Python tools to analyze security characteristics of MS Office and OLE files (also called Structured Storage, Compound File Binary Format or Compound Document File Format), for Malware Analysis and Incident Response #DFIR
Last release 2 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 2.1 years
Most releases are documented
notes for 28 of 42 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
43 releases · first in 2012
fixed a bug in open_slk (issue #797, PR #769)
added simple detection of CVE-2021-40444 initial stage
2022-05-09 v0.60.1:
More details about fixed issues and improvements in 0.60: https://github.com/decalage2/oletools/milestone/10?closed=1
One column per quarter.
ftguess: new tool to identify file formats and containers (issue #680)
More details about fixed issues and improvements in 0.60: https://github.com/decalage2/oletools/milestone/10?closed=1
added several CLSIDs related to MS Office click-to-run issue CVE-2021-27058
More details about fixed issues and improvements in 0.56: https://github.com/decalage2/oletools/milestone/9?closed=1
fixed bug when parsing some malformed files (issue #629)
More details about fixed issues and improvements in 0.56: https://github.com/decalage2/oletools/milestone/9?closed=1
added detection of trigger _OnConnecting
How to install with pip: https://github.com/decalage2/oletools/wiki/Install
Nothing published for this version
rtfobj: added URL carver for CVE-2017-0199
Main changes in oletools v0.55:
How to install with pip: https://github.com/decalage2/oletools/wiki/Install
This is a bugfix release for oletools 0.54 .
This is a bugfix release for oletools 0.54.
Changes:
How to install/update with pip: https://github.com/decalage2/oletools/wiki/Install
olevba: decompress_stream now accepts both bytes and bytearray (fixes #422)
olevba: decompress_stream now accepts both bytes and bytearray (fixes #422)
olevba, msodde: added support for encrypted MS Office files
Main changes in oletools 0.54:
How to install with pip: https://github.com/decalage2/oletools/wiki/Install
2018-06-13 v0.53.1: Bugfix release
2018-06-13 v0.53.1: Bugfix release - rtfobj: fixed issue #316, whitespace after \bin on Python 3 - olevba3: fixed #320, chr instead of unichr on python 3 - olevba3: fixed #322, import reduce from functools
common.clsid contains the list of known CLSIDs, and their links to CVE vulnerabilities when relevant.
2018-05-30 v0.53: - olevba and mraptor can now parse Word/PowerPoint 2007+ pure XML files (aka Flat OPC format) - improved support for VBA forms in olevba (oleform) - rtfobj now displays the CLSID of OLE objects, which is the best way to identify them. Known-bad CLSIDs such as MS Equation Editor are highlighted in red. - Updated rtfobj to handle obfuscated RTF samples. - rtfobj now handles the "\'" obfuscation trick seen in recent samples such as https://twitter.com/buffaloverflow/status/989798880295444480, by emulating the MS Word bug described in https://securelist.com/disappearing-bytes/84017/ - msodde: improved detection of DDE formulas in CSV files - oledir now displays the tree of storage/streams, along with CLSIDs and their meaning. - common.clsid contains the list of known CLSIDs, and their links to CVE vulnerabilities when relevant. - oleid now detects encrypted OpenXML files - fixed bugs in oleobj, rtfobj, oleid, olevba
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixed issue #265 (error when installing on Python 3)
Fixed issue #265 (error when installing on Python 3)
Nothing published for this version
New tool msodde to detect and extract DDE links from MS Office files, RTF and CSV;
improved rtfobj to handle malformed RTF files, detect vulnerability CVE-2017-0199
all oletools now support python 2 and 3.
olevba: added PPT97 macros support, improved handling of malformed/incomplete documents, improved error handling and JSON output, now returns an exit
improved handling of malformed/incomplete documents, improved error handling and JSON output, now returns an exit code based on analysis results, new --relaxed option. rtfobj : improved parsing to handle obfuscated RTF documents, added -d option to set output dir. Moved repository and documentation to GitHub.
2016-04-19 v0.46: olevba does not deobfuscate VBA expressions by default (much faster), new option --deobf to enable it. Fixed color display bug on Windows for several tools.
2016-04-12 v0.45: improved rtfobj to handle several anti-analysis tricks , improved olevba to export results in JSON format.
2016-03-11 v0.44: improved olevba to extract and analyse strings from VBA Forms.
olevba does not deobfuscate VBA expressions by default (much faster), new option --deobf to enable it. Fixed color display bug on Windows for several
olevba does not deobfuscate VBA expressions by default (much faster), new option --deobf to enable it. Fixed color display bug on Windows for several tools. oletools-0.46.tar.gz oletools-0.46.zip
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
to show the macro code with VBA strings deobfuscated.
to show the macro code with VBA strings deobfuscated.
to decode Hex and Base64 within VBA expressions. Display printable deobfuscated strings by default. Improved the VBA_Parser API. Improved performance.
to decode Hex and Base64 within VBA expressions. Display printable deobfuscated strings by default. Improved the VBA_Parser API. Improved performance. Fixed issue #23 with sys.stderr.
expressions with any combination of Chr, Asc, Val, StrReverse, Environ, +, &, using a VBA parser built with pyparsing . New options to display only th
expressions with any combination of Chr, Asc, Val, StrReverse, Environ, +, &, using a VBA parser built with pyparsing . New options to display only the analysis results or only the macros source code. The analysis is now done on all the VBA modules at once.
2015-05-29 v0.11: Improved parsing of MHTML and ActiveMime/MSO files in olevba , added several suspicious keywords to VBA scanner (thanks to @ozhermit and Davy Douhine for the suggestions)
Nothing published for this version
Nothing published for this version
with macros, aka "Single File Web Page" (.mht) - see issue #10 for more info
with macros, aka "Single File Web Page" (.mht) - see issue #10 for more info
added anti-sandboxing/VM detection
added anti-sandboxing/VM detection
obfuscated with Hex/StrReverse/Base64/Dridex and extract IOCs. Added new triage mode, support for non-western codepages with olefile 0.42, improved AP
obfuscated with Hex/StrReverse/Base64/Dridex and extract IOCs. Added new triage mode, support for non-western codepages with olefile 0.42, improved API and display, several bugfixes.
Nothing published for this version
keywords and IOCs in VBA macros, can now scan several files and open password-protected zip archives, added a Python API, upgraded OleFileIO_PL to ole
keywords and IOCs in VBA macros, can now scan several files and open password-protected zip archives, added a Python API, upgraded OleFileIO_PL to olefile v0.41
2014-08-28 v0.06: added olevba , a new tool to extract VBA Macro source code from MS Office documents (97-2003 and 2007+). Improved documentation
Nothing published for this version
- 2013-04-18 v0.04: fixed bug in rtfobj, added documentation for rtfobj
2013-04-18 v0.04: fixed bug in rtfobj, added documentation for rtfobj
2012-11-09 v0.03: Improved pyxswf to extract Flash objects from RTF
Nothing published for this version
Nothing published for this version
-
See also the changelog in each source file for more details.
See also the changelog in each source file for more details.
You can’t perform that action at this time.
Your coding agent can read these notes before it upgrades. Set up the MCP server →