Over the past 12 months, the Mimecast Research Labs has discovered four Microsoft Office vulnerabilities, three of which have since been patched by Microsoft: CVE-2020-1321, CVE-2020-1332, and CVE-2019-1463. All had been resident in their respective Office applications for years. So why did they take so long to discover? Why do Mimecast researchers focus so much on Office? What techniques and tools are our researchers using that most others are not? How do these tools and techniques impact the future of vulnerability research? These questions and more will be answered in this session and will include an in-depth look at some of our techniques.