There are quite a few tools that allow analysts to look inside original Microsoft Office formats:
- oletools: A unique set of several powerful tools that allow an analyst to analyze all common documents associated with Microsoft Office products, for example:
- olebrowse: A pretty basic GUI tool that allows you to browse CFB documents
- oledir: Displays directory entries within CFB files
- olemap: Shows all sectors present in the document, including the header
-
-
- oleobj: Allows you to extract embedded objects from CFB files
- rtfobj: Pretty much the same functionality, but this time for RTF documents
-
Figure 11: Example of the olemap output
- oledump: This powerful tool gives a valuable insight into streams that are present in the document and features dumping and decompression options as well
- rtldump: Another tool from the same author, this time aiming to facilitate the analysis of RTF documents
- OfficeMalScanner: Features several heuristics to search for and analyze shellcode...