Ross ROSS = Recommend OSS · open-source software intelligence for agents

S3cur3Th1sSh1t/OffensiveVBA resource

This repo covers some code execution and AV Evasion methods for Macros in Office documents observed · 2026-08-28

github.com/S3cur3Th1sSh1t/OffensiveVBA · VBA · BSD-2-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1788
  • days_rel: n/a
  • days_push: 1679
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1276 stars · 227 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated collection of offensive VBA macro templates for code execution and antivirus evasion in Microsoft Office documents. It aggregates techniques like shellcode injection, AMSI bypasses, PPID spoofing, and process creation via Win32/WMI from various public sources into one reference repository.

Use cases

  • find VBA macro templates for code execution in Office documents
  • learn antivirus evasion techniques for Office macros
  • run shellcode from a Word or Excel macro
  • bypass AMSI from VBA
  • study red team tradecraft for phishing payloads
  • collect offensive VBA snippets in one place

When to choose

  • you are a red teamer or pentester building Office macro payloads
  • you want a reference collection of public VBA evasion techniques
  • you are learning how macros achieve code execution and evade AV

When to avoid

  • you need a maintained tool or library rather than copy-paste templates
  • you want defensive macro detection or Office hardening guidance
  • your target environment is not Windows/Office

Facets

learning-resource · maturity maintenance

penetration-testing security developer-tools penetration-testing security windows windows cross-platform vba office-macros av-evasion red-team offensive-security shellcode amsi-bypass code-execution

1 source

Member repositories

RepositoryRoleHealth v2
S3cur3Th1sSh1t/OffensiveVBAmain32

For agents

markdown · JSON · MCP: product_card(name="S3cur3Th1sSh1t/OffensiveVBA")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem