Hide Payload in MS Office Document Properties
ID: fe072a42-de67-522c-918a-f01f8c5bc57b
STIX ID: report--fe072a42-de67-522c-918a-f01f8c5bc57b
Feed Name: Black Hills Infosec Blog
This blog post demonstrates a PowerShell script that bypasses MS Office application limits to insert very long text into the BuiltInDocumentProperties "Comments" field, provides VBA macros to read the comment value in Word/Excel/PowerPoint, and includes an option to sanitize author metadata; it is an instructional how-to rather than an incident report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
