- http://www.decalage.info/python/oletools
- http://reconstructer.org/code/OfficeMalScanner.zip
- https://blog.didierstevens.com/my-software/#oledump
- http://decalage.info/vba_emulation
- https://github.com/bontchev/pcodedmp
- https://github.com/decalage2/oletools/blob/master/oletools/msodde.py
- https://bitbucket.org/cse-assemblyline/alsvc_cleaver
- https://bitbucket.org/cse-assemblyline/alsvc_oletools/src
- oledump get stream hashes
- oledump -p plugin_http_heuristics.py
- use oledump to extract embedded files