Tools: csv_dissector_V0_0_2.zip.
Blog post: Lua CSV Wireshark Dissector
Tools: parse-cs-http-traffic.py, 1768.py, pecheck.py and pybeacon.
ISC diary entry: Decoding Cobalt Strike Traffic
Tools: oledump.py, YARA.
NVISO blog post: Detecting DDE in MS Office documents
ISC diary entry: DDE and oledump
Tool: pdftool.py
Blog posts: Solving a Little PDF Puzzle, Shoulder Surfing a Malicious PDF Author, New Tool: pdftool.py.
Tools: CyberChef
CyberChef Recipe: here
Sample: f84b3a056abcbcfd5976afe8776a35c5894b379e65c411ddc421941d3a2a4b8b
ISC diary entry: Doc & RTF Malicious Document