Paul Rascagneres · @r00tbsd
1199 followers · 249 posts · Server infosec.exchange

I wrote a small Python library to extract metadata and embedded files in a documents (.one). The OneNote file format is not really documented but it seems to work on the files I tested.

It is published on the @volexity GitHub repository: github.com/volexity/threat-int
It can be used in or included easily on any .

#onenote #standalone #pipeline #cti #threathunting #maldoc #maliciousdocuments

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

PoetRAT: Malware targeting public and private sector in Azerbaijan evolves - By Warren Mercer, Paul Rascagneres and Vitor Ventura.

The Azerbaijan public sector and other import... feedproxy.google.com/~r/feedbu

#lua #python #poetrat #azerbajian #maliciousdocuments

Last updated 4 years ago