sevagas/macro_pack
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research. observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3256
- days_rel: n/a
- days_push: 748
- n_releases_24m: 0
Adoption not part of the score
2307 stars · 412 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other formats for red teaming, pentests, and social engineering assessments. It simplifies antimalware bypass by automating the pipeline from VBA source to final malicious document or payload format.
Use cases
- generate obfuscated macro-enabled office documents for pentest engagements
- bypass antimalware detection of VBA payloads
- create social engineering attack documents for red team assessments
- automate VBA and VBS script obfuscation
- generate malicious shortcuts and script formats like lnk, hta, wsf
- integrate Metasploit or Empire payloads into office documents
- demo macro attack techniques for security training
When to choose
- you need to automate generation of obfuscated Office/VBA payloads during authorized red team or pentest work
- you want a single-line CLI tool compatible with Metasploit and Empire payloads
- you need to generate many retro formats (docm, xlsm, lnk, hta, etc.) quickly
When to avoid
- you need actively maintained tooling - the project has not been maintained since 2021
- you lack Windows with MS Office installed for automatic document generation or trojan features
- you need modern EDR bypass or initial access capabilities beyond legacy macro techniques
- you are looking for a defensive or detection tool rather than offensive
Facets
cli-tool · maturity abandoned
security penetration-testing cli developer-tools security penetration-testing developer-tools python windows cli redteam social-engineering vba obfuscation macro-generation office-documents antivirus-bypass pentest command-line linux
3 sources
- readme: https://github.com/sevagas/macro_pack · fetched 2026-08-28 · d0fa9c1c183e
- homepage: https://blog.sevagas.com · fetched 2026-08-29 · fbe96f011e27
- site_page: https://blog.sevagas.com/?-About-us-=&lang=en · fetched 2026-08-29 · 78c601362256
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| sevagas/macro_pack | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="sevagas/macro_pack")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem