Malicious PowerPoint presentation with embedded macro
Macro-laden Office documents remain one of the most reliable initial access vectors, with PowerPoint files a frequent carrier: opening a malicious .pptm triggers embedded VBA that downloads or executes the next stage. The user is the entry point — the click that launches the macro — a pattern mapped to T1204.002 (User Execution: Malicious File). This demo presents a PowerPoint file containing a benign macro that simply opens Calculator, demonstrating the risk without any harmful payload. Deep CDR (Content Disarm and Reconstruction) inspects the presentation, strips the macro and other active content, and rebuilds a clean .pptm that opens normally but can no longer execute code — preserving usability while removing the attack vector.
Attack Technique
PowerPoint macro
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗