# S3cur3Th1sSh1t/OffensiveVBA

This repo covers some code execution and AV Evasion methods for Macros in Office documents

Repository: https://github.com/S3cur3Th1sSh1t/OffensiveVBA
Canonical: https://ross.abutalabs.com/products/offensivevba
Language: VBA
License: BSD-2-Clause
License Family: permissive
Last push: 2022-01-27T20:42:21+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1788, "days_push": 1679, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1276, forks 227 (observed 2026-08-28T04:04:13.159081+00:00)

## What it is
A curated collection of offensive VBA macro templates for code execution and antivirus evasion in Microsoft Office documents. It aggregates techniques like shellcode injection, AMSI bypasses, PPID spoofing, and process creation via Win32/WMI from various public sources into one reference repository.

## Use cases
- find VBA macro templates for code execution in Office documents
- learn antivirus evasion techniques for Office macros
- run shellcode from a Word or Excel macro
- bypass AMSI from VBA
- study red team tradecraft for phishing payloads
- collect offensive VBA snippets in one place

## When to choose
- you are a red teamer or pentester building Office macro payloads
- you want a reference collection of public VBA evasion techniques
- you are learning how macros achieve code execution and evade AV

## When to avoid
- you need a maintained tool or library rather than copy-paste templates
- you want defensive macro detection or Office hardening guidance
- your target environment is not Windows/Office

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: penetration-testing, security, developer-tools
- domain: penetration-testing, security, windows
- platform: windows, cross-platform
- tags: vba, office-macros, av-evasion, red-team, offensive-security, shellcode, amsi-bypass, code-execution

## Member repositories
- S3cur3Th1sSh1t/OffensiveVBA (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:13.159081+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T05:02:54.328505+00:00, confidence not recorded.
  - readme: https://github.com/S3cur3Th1sSh1t/OffensiveVBA (fetched 2026-08-28T04:04:13.159081+00:00, sha 1ced1d003748)
- Data as of 2026-08-30T08:39:29.467469+00:00.
