Finding Property Values in Office Documents, (Sat, Feb 16th)

In diary entry “Maldoc Analysis of the Weekend”, I use the strings method explained in diary entry “Quickie: String Analysis is Still Useful” to quickly locate the PowerShell command hidden in a malicious Word document.

Article Link: https://isc.sans.edu/diary/rss/24652