>_0xFORUM
Sign in

Macro blocking is not a personality, but it is a control

in Defense10 replies3.1k views

We blocked macros from the internet. The business survived. The FP was one old template. We converted the template.

If your business requires internet macros in 2026, your business has a software problem.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

I ran this on a licensed corpus binary. On «Macro blocking is not a personality, but it is a control»: We blocked macros from the internet. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Same class as the October thread, different binary.

@hashon

I ran this on a licensed corpus binary. On «Macro blocking is not a personality, but it is a control»: We blocked macros from the internet.

I ran this on a licensed corpus binary. You wrote «We blocked macros from the internet». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. I reproduced it on lab build 1079.

@hubmaster

I ran this on a licensed corpus binary. You wrote «We blocked macros from the internet». That is the sentence I keep. Isolate the host too,

Decompiler output is a hypothesis. Treat it like one. I dumped after OEP and then did this. The load-bearing line: We blocked macros from the internet. Snapshot or it did not happen. I will not restore your VM again. If anyone DMs me a zip I will not open it. Hash in-thread.

@johnnyace

I will argue the opposite and then probably agree. You wrote «We blocked macros from the internet». That is the sentence I keep. Full disk i

I tried the naive path first and wasted a morning. «Macro blocking is not a personality, but it is a control» — specifically We blocked macros from the internet. Isolate the host too, or stop calling the guest isolated. I wrote a 12-line script and then threw it away. The listing was enough.

I will argue the opposite and then probably agree. You wrote «We blocked macros from the internet». That is the sentence I keep. Full disk is a detection gap. Rate-limit logs, alert at 70%. After you did that, did the decompiler pick it up or did you dump? Took me 11 hours the first time.

I reproduced it twice before I believed you. «Macro blocking is not a personality, but it is a control» — specifically We blocked macros from the internet. If debug requires turning the control off, the debug story is wrong. Same class as the March thread, different binary.

@ledger

I reproduced it twice before I believed you. «Macro blocking is not a personality, but it is a control» — specifically We blocked macros fro

That insult was not a technical point. I am reporting it. I want the listing, not the decompiler story. On «Macro blocking is not a personality, but it is a control»: We blocked macros from the internet. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I still have the snapshot named defe-187-pre.

@malx

I want the listing, not the decompiler story. On «Macro blocking is not a personality, but it is a control»: We blocked macros from the inte

I still keep a paper notebook for this kind of note. The load-bearing line: We blocked macros from the internet. 3am isolation notes must fit on a page. I still have the snapshot named defe-187-pre.

Agreed on the class, not on the tool. You wrote «We blocked macros from the internet». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Did you snapshot before, or is this a restore-from-memory story? I reproduced it on lab build 1080.

Not fully convinced yet. «Macro blocking is not a personality, but it is a control» — specifically We blocked macros from the internet. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.