{"adoption": {"forks": 604, "observed_at": "2026-08-28T04:08:02.914163+00:00", "stars": 3404}, "canonical_url": "https://ross.abutalabs.com/products/oletools", "card": {"archived": false, "artifact_type": "library", "description": "oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.", "domain": ["security", "developer-tools", "files", "parsers"], "enriched": true, "function": ["parser", "security", "developer-tools", "cli"], "health_score": 67, "homepage": "http://www.decalage.info/python/oletools", "language": "Python", "license": "NOASSERTION", "license_family": "other", "maturity": "active", "member_repos": ["decalage2/oletools"], "name": "decalage2/oletools", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2026-02-14T19:42:44+00:00", "repo": "decalage2/oletools", "stars": 3404, "tags": ["malware-analysis", "dfir", "forensics", "vba-macros", "ole-files", "ms-office", "rtf", "openxml"], "topics": ["python", "python-library", "olefile", "malware-analysis", "ms-office-documents", "compound", "rtf", "forensics", "ole-files", "security", "parser", "pyparsing", "vba", "macros"], "urls": [], "use_cases": ["extract vba macros from office documents", "analyze malicious office files for malware", "parse ole2 compound file binary format", "detect suspicious macros in docx and xls files", "forensic analysis of outlook messages and msi files", "incident response triage of office attachments", "extract embedded ole objects from rtf files"], "what_it_is": "oletools is a Python package of tools for analyzing Microsoft OLE2 (Structured Storage/Compound File Binary Format) files and MS Office documents, including RTF and OpenXML formats. It can detect, extract, and analyze VBA macros, Excel 4/XLM macros, OLE objects, and DDE links, primarily for malware analysis, forensics, and debugging.", "when_to_avoid": ["you need to create or edit Office documents rather than analyze them", "you only need modern OOXML parsing without security analysis", "you need a GUI-based analysis tool"], "when_to_choose": ["you need to inspect or deobfuscate VBA or Excel 4/XLM macros in Office documents", "you are doing malware analysis, DFIR, or forensics on OLE/OOXML files", "you want a Python library plus CLI tools for parsing legacy Office formats"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/oletools", "repo": "decalage2/oletools", "role": "main", "score": 53}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:08:02.914163+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:38:37.188550+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b634db7caffd018eacfdd41e667d4672d4c08939dd4978c7bbeb19088fc9475d", "fetched_at": "2026-08-28T04:08:02.914163+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/oletools"}, {"content_hash": "9180e9aa94f435e314bffe2450e3c0e6b176762dfc196005dd5d3ae5ac9710a5", "fetched_at": "2026-08-29T09:32:50.625723+00:00", "kind": "homepage", "missing": false, "url": "http://www.decalage.info/python/oletools"}, {"content_hash": "7bfc9436c75d076d52fb3a37c937605d479e74730261a1aef06392785ed40278", "fetched_at": "2026-08-29T09:32:50.635363+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/oletools/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 67, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3756, "days_push": 200, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 53, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}