# sevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.

Repository: https://github.com/sevagas/macro_pack
Canonical: https://ross.abutalabs.com/products/macro_pack
Homepage: https://blog.sevagas.com
Language: Python
License: Apache-2.0
License Family: permissive
Topics: pentest, social-engineering, vba, obfuscation, redteam, msoffice, macros, meterpreter
Archived: true
Last push: 2024-08-15T14:21:39+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3256, "days_push": 748, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2307, forks 412 (observed 2026-08-28T04:06:35.835338+00:00)

## What it is
macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other formats for red teaming, pentests, and social engineering assessments. It simplifies antimalware bypass by automating the pipeline from VBA source to final malicious document or payload format.

## Use cases
- generate obfuscated macro-enabled office documents for pentest engagements
- bypass antimalware detection of VBA payloads
- create social engineering attack documents for red team assessments
- automate VBA and VBS script obfuscation
- generate malicious shortcuts and script formats like lnk, hta, wsf
- integrate Metasploit or Empire payloads into office documents
- demo macro attack techniques for security training

## When to choose
- you need to automate generation of obfuscated Office/VBA payloads during authorized red team or pentest work
- you want a single-line CLI tool compatible with Metasploit and Empire payloads
- you need to generate many retro formats (docm, xlsm, lnk, hta, etc.) quickly

## When to avoid
- you need actively maintained tooling - the project has not been maintained since 2021
- you lack Windows with MS Office installed for automatic document generation or trojan features
- you need modern EDR bypass or initial access capabilities beyond legacy macro techniques
- you are looking for a defensive or detection tool rather than offensive

## Facets
- artifact type: cli-tool
- maturity: abandoned
- function: security, penetration-testing, cli, developer-tools
- domain: security, penetration-testing, developer-tools
- platform: python, windows, cli
- tags: redteam, social-engineering, vba, obfuscation, macro-generation, office-documents, antivirus-bypass, pentest, command-line, linux

## Member repositories
- sevagas/macro_pack (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:35.835338+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:39:39.907591+00:00, confidence not recorded.
  - readme: https://github.com/sevagas/macro_pack (fetched 2026-08-28T04:06:35.835338+00:00, sha d0fa9c1c183e)
  - homepage: https://blog.sevagas.com (fetched 2026-08-29T10:19:56.096927+00:00, sha fbe96f011e27)
  - site_page: https://blog.sevagas.com/?-About-us-=&lang=en (fetched 2026-08-29T10:19:56.105804+00:00, sha 78c601362256)
- Data as of 2026-08-30T08:39:29.467469+00:00.
