# Finer detail on mime types

**URL:** <https://community.zeek.org/t/finer-detail-on-mime-types/4931>\
**Category:** Zeek\
**Created:** [July 7, 2017, 8:11pm UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931 "2017-07-07T20:11:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [July 7, 2017, 8:11pm UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/1 "2017-07-07T20:11:39Z")

</div>

So in looking at xlsm/docm files I noticed this...where bro says:

application/vnd.openxmlformats-officedocument.spreadsheetml.sheet

but the pcap says:

application/vnd.ms-excel.sheet.macroenabled.12

Is there a way to fine tune this in bro? Identifying files flying around with macros would be wonderful...thank you.

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [July 10, 2017, 8:09pm UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/2 "2017-07-10T20:09:07Z")

</div>

That is a bit of an overloaded mime-type I'm afraid. We did build the  
files framework in Bro so that it could be extended to provide quite a  
bit of extra information when the file is "sniffed". The primary  
problem that we'd have with providing that information at the moment  
is lack of a way to analyze excel files.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [July 10, 2017, 10:04pm UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/3 "2017-07-10T22:04:13Z")

</div>

Understood and thanks Seth. At this point an analysis of the Macro enabled Excel/Word file is secondary to bro just being able to read and report the "macroeanbled" mime type. Lemme see if I can get protosigs to do something exciting....thank you!

James

---

<div class="post-metadata">

**Author:** ![Christian](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/christian/32/593_2.png) [@Christian](https://community.zeek.org/u/Christian)\
**Post date:** [July 11, 2017, 6:33am UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/4 "2017-07-11T06:33:00Z")

</div>

Once you know you're dealing with an OOXML archive, in my experience the following works well: take the presence of a vbaproject.bin file in the archive as a prerequisite for macro-enabledness, then leverage a .docm/.pptm/.xlsm filename suffix to distinguish application, and fall back to Word for others.

I'd be interested to hear what approaches others have used.

Thanks,  
-C.

---

<div class="post-metadata">

**Author:** ![Christian](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/christian/32/593_2.png) [@Christian](https://community.zeek.org/u/Christian)\
**Post date:** [July 11, 2017, 7:25am UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/5 "2017-07-11T07:25:44Z")

</div>

I forgot: the directory layout in such archives is also telling -- look for word/, xl/, ppt/ ...

It's been a while. 🙂

Cheers,  
-C.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/finer-detail-on-mime-types/4931/6 "2022-05-06T15:45:06Z")

</div>


