• Stars
    star
    364
  • Rank 112,857 (Top 3 %)
  • Language VBA
  • License
    GNU Affero Genera...
  • Created about 5 years ago
  • Updated about 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

🐟 PoC of a VBA macro spawning a process with a spoofed parent and command line.

This repository contains an example of a VBA macro spawning a process with a spoofed parent and command line. Companion blog post: Building an Office macro to spoof parent processes and command line arguments

Demo

Click for full size.

Demo

Notes

  • The 32-bit initial PoC was written and tested by myself, on Windows 10 with Office Professional Plus 2016, version 1902.

  • The 64-bit version is a contribution brought by @py7hagoras.

  • The size of the original command line stored in originalCli needs to be greater than the size of the real one stored in cmdStr

Acknowledgments & inspiration

Disclaimer

You are solely responsible for the use you make of this PoC. I assume no liability for any misuse or damage caused by this program.

More Repositories

1

CloudFlair

πŸ”Ž Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
Python
1,880
star
2

log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
Java
1,055
star
3

censys-subdomain-finder

⚑ Perform subdomain enumeration using the certificate transparency logs from Censys.
Python
579
star
4

Adaz

πŸ”§ Deploy customizable Active Directory labs in Azure - automatically.
HCL
368
star
5

duplicacy-autobackup

πŸ’Ύ Painless automated backups to multiple storage providers with Docker and duplicacy.
Shell
246
star
6

mindmaps

πŸ” Mindmaps for threat hunting - work in progress.
148
star
7

IPv6teal

πŸ‘‹ Stealthy data exfiltration via IPv6 covert channel
Python
91
star
8

firepwned

πŸ™ Checks Firefox saved passwords against known data leaks using the Have I Been Pwned API.
Python
81
star
9

nextcloud-docker-compose

☁️ Spin up a Nextcloud instance with automatied backups and SSL certificate issuance.
74
star
10

docker-python-sandbox

A Docker-powered NodeJS sandbox to execute untrusted python code.
JavaScript
62
star
11

nmap-nse-info

Browse and search through nmap's NSE scripts.
Lua
58
star
12

code-execution-api-demo

JavaScript
17
star
13

aws-sso-device-code-authentication

Python
16
star
14

fun-with-vpc-endpoints

HCL
14
star
15

geolocate-ips

Batch IP geolocation script.
Python
12
star
16

abusing-cloudflare-workers

Abusing Cloudflare Workers to establish persistence and exfiltrate sensitive data at the edge.
JavaScript
10
star
17

telegram-downbot

A Telegram bot to monitor websites
CoffeeScript
6
star
18

polybot

CoffeeScript
5
star
19

unix-commands

Some useful UNIX commands
4
star
20

powercoders-docker

Repository for Powercoders Docker presentation and workshop
Python
2
star
21

falias

Shell
2
star
22

filezilla-passwords-revealer

JavaScript
1
star
23

hackathon

JavaScript
1
star
24

flame-maker

Java
1
star
25

fos2015.github.io

Website for the Foundations of Software course at EPFL in the Fall 2015 semester
CSS
1
star
26

Rails-app

Ruby
1
star