I wrote a small Python library to extract metadata and embedded files in a #OneNote documents (.one). The OneNote file format is not really documented but it seems to work on the files I tested.
It is published on the @volexity GitHub repository: https://github.com/volexity/threat-intel/tree/main/tools/one-extract
It can be used in #standalone or included easily on any #pipeline.
#CTI #threathunting #maldoc #maliciousdocuments
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves - By Warren Mercer, Paul Rascagneres and Vitor Ventura.
The Azerbaijan public sector and other import... http://feedproxy.google.com/~r/feedburner/Talos/~3/HJ1mqTAdQDQ/poetrat-update.html #maliciousdocuments #azerbajian #poetrat #python #lua