{"adoption": {"forks": 227, "observed_at": "2026-08-28T04:04:13.159081+00:00", "stars": 1276}, "canonical_url": "https://ross.abutalabs.com/products/offensivevba", "card": {"archived": false, "artifact_type": "learning-resource", "description": "This repo covers some code execution and AV Evasion methods for Macros in Office documents", "domain": ["penetration-testing", "security", "windows"], "enriched": true, "function": ["penetration-testing", "security", "developer-tools"], "health_score": 20, "homepage": null, "language": "VBA", "license": "BSD-2-Clause", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["S3cur3Th1sSh1t/OffensiveVBA"], "name": "S3cur3Th1sSh1t/OffensiveVBA", "platform": ["windows", "cross-platform"], "pushed_at": "2022-01-27T20:42:21+00:00", "repo": "S3cur3Th1sSh1t/OffensiveVBA", "stars": 1276, "tags": ["vba", "office-macros", "av-evasion", "red-team", "offensive-security", "shellcode", "amsi-bypass", "code-execution"], "topics": [], "urls": [], "use_cases": ["find VBA macro templates for code execution in Office documents", "learn antivirus evasion techniques for Office macros", "run shellcode from a Word or Excel macro", "bypass AMSI from VBA", "study red team tradecraft for phishing payloads", "collect offensive VBA snippets in one place"], "what_it_is": "A curated collection of offensive VBA macro templates for code execution and antivirus evasion in Microsoft Office documents. It aggregates techniques like shellcode injection, AMSI bypasses, PPID spoofing, and process creation via Win32/WMI from various public sources into one reference repository.", "when_to_avoid": ["you need a maintained tool or library rather than copy-paste templates", "you want defensive macro detection or Office hardening guidance", "your target environment is not Windows/Office"], "when_to_choose": ["you are a red teamer or pentester building Office macro payloads", "you want a reference collection of public VBA evasion techniques", "you are learning how macros achieve code execution and evade AV"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/offensivevba", "repo": "S3cur3Th1sSh1t/OffensiveVBA", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:13.159081+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T05:02:54.328505+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1ced1d0037481f85304ad67e82833a4f216cd9757f0e038913a7365003b084ae", "fetched_at": "2026-08-28T04:04:13.159081+00:00", "kind": "readme", "missing": false, "url": "https://github.com/S3cur3Th1sSh1t/OffensiveVBA"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1788, "days_push": 1679, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}