{"adoption": {"forks": 188, "observed_at": "2026-08-28T04:03:40.836328+00:00", "stars": 1124}, "canonical_url": "https://ross.abutalabs.com/products/vipermonkey", "card": {"archived": false, "artifact_type": "library", "description": "A VBA parser and emulation engine to analyze malicious macros.", "domain": ["security", "developer-tools", "files"], "enriched": true, "function": ["parser", "security", "reverse-engineering", "interpreter"], "health_score": 20, "homepage": null, "language": "Python", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["decalage2/ViperMonkey"], "name": "decalage2/ViperMonkey", "platform": ["python", "windows", "cli"], "pushed_at": "2024-07-10T06:28:56+00:00", "repo": "decalage2/ViperMonkey", "stars": 1124, "tags": ["vba", "macro-analysis", "malware-analysis", "emulation", "maldoc", "office-files", "deobfuscation", "linux", "macos", "docker"], "topics": ["vba", "emulation", "malware-analysis", "python", "security", "macros", "parser", "pyparsing"], "urls": [], "use_cases": ["analyze malicious VBA macros in Word documents", "deobfuscate obfuscated Office macros", "extract URLs and payloads from maldocs", "emulate VBA code safely without running Office", "triage suspicious email attachments", "automate macro malware analysis in a sandbox"], "what_it_is": "ViperMonkey is a VBA parser and emulation engine written in Python for analyzing and deobfuscating malicious macros in Microsoft Office documents. It emulates VBA code execution to reveal the behavior of maldocs without running them in a live Office environment.", "when_to_avoid": ["you need fast, real-time scanning of large document volumes", "the macro relies on complex Office application features or DLL/ActiveX calls that emulation does not support", "you need a production-grade, commercially supported analysis tool"], "when_to_choose": ["you need to understand what a malicious Office macro does without executing it", "you want automated, scriptable VBA emulation for malware triage pipelines", "you need to deobfuscate heavily obfuscated VBA strings and logic"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/vipermonkey", "repo": "decalage2/ViperMonkey", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:40.836328+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:39:38.408855+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "a67db518e9e7cee7e7f42a320767baf6392ab3f6bc92ca574fd2fddc8f68818d", "fetched_at": "2026-08-28T04:03:40.836328+00:00", "kind": "readme", "missing": false, "url": "https://github.com/decalage2/ViperMonkey"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3629, "days_push": 784, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}