# olevba > Extract and analyze VBA macros from Office documents with deobfuscation **Category:** [[categories/analyze-documents-microsoft-office|Analyze Documents > Microsoft Office]] | **Tier:** Rich (FOR610) **Docs:** [https://docs.remnux.org/discover-the-tools/analyze+documents/microsoft+office](https://docs.remnux.org/discover-the-tools/analyze+documents/microsoft+office) ## Usage ```bash olevba document.docm olevba --deobf document.docm ``` ## Workflows - [[workflows/document-analysis-workflow|Malicious Document Analysis]] — Step 4: Macro/Script Extraction ## Related Tools - [[tools/evilclippy|evilclippy]] — Remove VBA project password protection and manipulate Office - [[tools/libolecf|libolecf]] — Microsoft Office OLE2 compound documents. - [[tools/msoffcrypto-crack|msoffcrypto-crack.py]] — Recover the password of an encrypted Microsoft Office docume - [[tools/msoffcrypto-tool|msoffcrypto-tool]] — Decrypt password-protected Microsoft Office documents (OLE a - [[tools/msoffice-crypt|msoffice-crypt]] — Encrypt and decrypt OOXML Microsoft Office documents. ## FOR610 **Sections:** 3 #office #vba #macro #deobfuscation