OneNote Notebook Hides an Embedded Executable
OneNote notebooks are a favorite container for initial access because users treat .one files as harmless notes. Attackers embed executable files, scripts, or download stubs inside notebook pages, where they appear as unassuming attachments waiting to be double-clicked. This demo presents a .one file carrying a benign embedded command that only opens Calculator — the same structure real campaigns use to drop payloads. Deep CDR parses the notebook structure and reconstructs it from scratch, stripping embedded objects, OLE content, and active links while preserving the readable note text. The sanitized file keeps its business utility but contains no code that could execute on an endpoint.
Attack Technique
OneNote embedded file
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗