Skip to content
Aback Tools Logo

VBA P-Code/Compressed Macro Extractor

Extract and decompress VBA macros from Office documents (DOCX, XLSX, PPTX). Parse ZIP-based OOXML archives, decompress PERFORMED/DEFLATE compressed vbaProject.bin streams, and recover macro source code from the VBA project modules. Auto-execute macros are flagged with their trigger events for security analysis. Free, private, and no signup required.

VBA P-Code / Compressed Macro Extractor

Upload Office documents (DOCX, XLSX, PPTX) to extract and decompress embedded VBA macros. Recovers macro source code from compressed vbaProject.bin streams, detects auto-execute macros, and provides hex dump views for forensic analysis. All processing runs locally in your browser.

Drop a document here or click to browse

Supports DOCX, XLSX, and PPTX files

How to Use the VBA P-Code/Compressed Macro Extractor

Upload any Office Open XML document (DOCX, XLSX, PPTX) to extract embedded VBA macro source code. The tool parses the ZIP-based OOXML structure, finds vbaProject.bin entries, decompresses DEFLATE-compressed PERFORMED data streams, and recovers VBA source code from the project modules. All processing is done entirely in your browser — no data is uploaded to any server. Auto-execute macros are flagged with their trigger events for security analysis.

Why Use Our VBA P-Code/Compressed Macro Extractor?

Extract VBA Macros from Office Documents

Upload DOCX, XLSX, or PPTX files to extract embedded VBA macros. Our tool automatically parses the ZIP-based Office Open XML structure, locates vbaProject.bin entries, decompresses deflate-compressed streams, and extracts macro source code from the VBA project storage stream. Works with any Office document that contains macros.

Secure & Private Macro Extraction

All VBA macro extraction, decompression, and decompilation happens entirely in your browser. Your Office documents, extracted macros, and decompressed source code never leave your device. No data uploaded to any server, no tracking, no signup required — complete privacy for sensitive document analysis.

Recover Source from Obfuscated Macros

Extract VBA macro source from documents where macros are compressed, encoded, or obfuscated. The tool decompresses PERFORMED streams using standard DEFLATE compression (RFC 1951) and reconstructs the original VBA source code from the PROJECT and module streams. Supports both compressed and uncompressed VBA project formats.

Detailed Macro Analysis with Hex View

View extracted macros with source code preview, line counts, and character analysis. Each detected macro is listed with its module name, type (Sub/Function/Module), auto-execute status, and compressed vs uncompressed sizes. Hex dump view of raw VBA project data available for forensic analysis.

Common Use Cases for VBA P-Code/Compressed Macro Extractor

Malware & Macro Virus Extraction

Security analysts extract VBA macro source code from malicious Office documents to analyze payloads. Macro malware often uses compressed or obfuscated VBA projects to hide downloaders, droppers, and shellcode from static analysis. Extracting the raw P-Code and decompressed source reveals the full malicious logic.

Phishing Document Forensics

Investigate VBA macros embedded in phishing documents that use compression to evade email security scanners. Extract and decompress the VBA project to reveal credential harvesting URLs, PowerShell download cradles, and data exfiltration targets hidden inside obfuscated macro code stored in Office Open XML archives.

Reverse Engineering Legacy Macros

Reverse engineer VBA macros from legacy Office documents where the original source code was protected by binary compression or password-based project locking. Extract the macro source from the VBA project binary stream to understand what the macro does before running it in a sandboxed environment.

Incident Response & Forensics

During incident response, analyze VBA macros extracted from compromised systems. Recover hidden IP addresses, domain names, registry keys, and file paths from compressed VBA project streams. The hex view and detailed analysis help forensic investigators understand the full scope of the compromise.

Red Team Macro Testing

Red teamers use the extractor to verify that their VBA payloads survive compression and can be reversed. Understanding how Office stores and compresses VBA projects in the OLE2 and OOXML formats helps build better detection rules and more resilient payload delivery mechanisms.

Educational Tool for VBA Internals

Learn how Office stores VBA macros internally — from the PROJECT and module streams, via PERFORMED compression, to the raw VBA source code. Understand the OLE2 compound document structure, workbook streams, and how Excel, Word, and PowerPoint embed macros in their Open XML formats.

Understanding VBA P-Code & Compressed Macro Extraction

What is VBA P-Code and Compressed Macro Storage?

VBA P-Code (pseudo-code) is an intermediate representation of VBA source code that the VBA runtime compiles before execution. When you create a macro in an Office application, the VBA source is stored in a compressed tokenized format within the document's OLE2 compound file structure. Office documents (DOCX, XLSX, PPTX) are actually ZIP archives containing XML files and binary streams. The VBA project is stored as vbaProject.bin inside the ZIP, which contains multiple streams including the PROJECT stream (module inventory and references), VBA/ModuleName streams (compressed source code using PERFORMED/DEFLATE compression), and the PROJECTTKB stream (type library and dependency information). Our tool parses this entire structure to recover the original VBA source.

How Our VBA P-Code/Compressed Macro Extractor Works

  1. 1. Upload an Office Document: Select any Office Open XML file (DOCX, XLSX, PPTX) using the file picker or drag-and-drop. The tool validates the ZIP signature and identifies the document type — Word, Excel, or PowerPoint. The file is processed entirely in your browser with no upload to any server.
  2. 2. Extract & Decompress VBA Project: The tool parses the ZIP archive to find all vbaProject.bin entries. The VBA project binary is decompressed using standard DEFLATE compression (RFC 1951) via the browser's native DecompressionStream API. The PROJECT stream is parsed to enumerate all module names, and each VBA module stream is decompressed to recover the original VBA source code.
  3. 3. View & Analyze Extracted Macros: The extracted macro source code is displayed with module names, line counts, and character analysis. Auto-execute macros are flagged with their trigger events (Document_Open, AutoOpen, Workbook_Open, etc.). A hex dump view of the raw VBA project data is available for deep forensic analysis. Click copy to save extracted source code for further investigation.

Office Document VBA Storage Structure

  • OOXML ZIP Archive: Office documents (DOCX, XLSX, PPTX) are ZIP archives containing typed XML parts and binary streams. The VBA project is stored as a binary stream at word/vbaProject.bin, xl/vbaProject.bin, or ppt/vbaProject.bin depending on the document type.
  • PROJECT Stream: Contains the module inventory listing each VBA module name, document class associations, and project references. This stream is stored as plain Unicode text and parsed to identify all module entries before extracting their source code.
  • Module Streams (VBA/ModuleName): Each VBA module has a corresponding stream containing the compressed source code. The source is compressed using PERFORMED compression, which is a variant of DEFLATE (RFC 1951) with a VBA-specific header. The tool detects and decompresses this format to recover the original VBA source code.
  • Auto-Execute Macros: Certain macro names are automatically triggered by Office events: Auto_Open, Document_Open, Workbook_Open, and more. These are flagged during extraction as they are commonly used by malware for automatic execution upon document open.

Privacy, Security & Availability

The VBA P-Code/Compressed Macro Extractor is 100% free with no signup required. All document parsing, ZIP extraction, DEFLATE decompression, and VBA project analysis is performed locally in your browser — your Office documents, extracted macros, and decompressed source never leave your device. There are no usage limits or restrictions. The tool supports drag-and-drop file upload, multiple document formats (DOCX, XLSX, PPTX), auto-execute macro detection with trigger names, hex dump view for forensic analysis, and one-click copy of extracted source code. Use it as many times as needed for your security research, malware analysis, or educational purposes.

Frequently Asked Questions About VBA P-Code/Compressed Macro Extractor

VBA P-Code (pseudo-code) is an intermediate tokenized representation of VBA source code that the VBA runtime compiles before execution. When you save a macro-enabled Office document, the VBA source is compressed and stored in a tokenized binary format within the vbaProject.bin stream. This compressed format includes the original source code compressed using PERFORMED/DEFLATE compression. The VBA P-Code/Compressed Macro Extractor reverses this process by locating the VBA project streams, decompressing the DEFLATE-compressed data, and recovering the original VBA source code that can be read and analyzed.

The tool supports all Office Open XML (OOXML) document formats that can contain VBA macros: DOCX (Word documents), XLSX (Excel workbooks), and PPTX (PowerPoint presentations). These formats are ZIP archives containing XML files and binary streams. The tool automatically detects the document type, locates the embedded vbaProject.bin file, and extracts the VBA macros. Older binary Office formats (DOC, XLS, PPT) use a different OLE2 structure and are not directly supported, but you can re-save them as OOXML in modern Office versions.

The tool can extract the compressed VBA project data from documents where the VBA project has a password lock. However, the actual VBA source code within password-protected projects may be encrypted using the project password as a key. The tool will show the raw compressed binary data and attempt DEFLATE decompression, but if the module stream is encrypted, the recovered data will appear as garbled binary rather than readable source code. For standard (non-password-protected) compressed macros, the source code is recovered fully.

Office uses PERFORMED compression, which is a proprietary variant of standard DEFLATE compression (RFC 1951) with a VBA-specific header structure. The compressed module streams begin with a signature byte (0x01 for uncompressed, 0x02 for compressed) followed by the compressed data. The tool uses the browser's native DecompressionStream API to decompress the DEFLATE stream, and handles the VBA-specific framing to recover the original source code. Decompression is performed entirely in your browser with no external dependencies.

Auto-execute macros have specific names that Office recognizes as event handlers. Common auto-execute macro names include: Auto_Open, AutoOpen, Document_Open, Workbook_Open, Auto_Close, Workbook_BeforeClose, Sheet_Activate, and App_Activate. The tool automatically detects these names and flags them with their trigger event. Auto-execute macros are commonly used by malware to run code automatically when a document is opened, so they are highlighted during extraction for security analysis.

Absolutely. The VBA P-Code/Compressed Macro Extractor runs entirely in your browser. Your Office documents, extracted macro source code, decompressed data, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All ZIP parsing, DEFLATE decompression, VBA project stream analysis, and source code reconstruction executes locally on your device with no API calls or data collection.

Office documents can store VBA projects in either compressed or uncompressed format. Uncompressed VBA projects store the module source code as plain text without compression — these are faster to extract but larger in file size. Compressed VBA projects use PERFORMED/DEFLATE compression to reduce the document size at the cost of requiring decompression to read the source code. Most modern Office applications compress VBA projects by default. Our tool handles both formats automatically: it reads the compression flag byte and applies the appropriate extraction method.

Yes — 100% free with no signup, no account, and no usage limits. Extract and decompress VBA macros from as many Office documents as you need, as many times as you want. All features — drag-and-drop upload, multiple document format support, DEFLATE decompression, auto-execute macro detection, hex dump view, source code preview, and one-click copy — are available without any restrictions. No premium tiers, hidden charges, or rate limits of any kind.