Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
18.2.5 ServiceInstaller Configuration
This section will describe the xml formats for all of the configuration values
contained under the <ServiceInstaller> XML tag. An example of a complete service
installer configuration is shown below:
XML Configuration Example
<ServiceInstaller bits="64">
<RegKeyPath>SYSTEM\CurrentControlSet\Services\TestPath</RegKeyPath>
<RegistryDescription>Assassin 64-bit</RegistryDescription>
<RegistryName>Implanted</RegistryName>
<DllPath>c:\temp\64\64assn.dll</DllPath>
</ServiceInstaller>
Attribute Definitions
bits
The bits attribute defines the bitness of the installer being configured, either 32
or 64. If the attribute is omitted, the configuration is assumed for all bitnesses.
Field Definitions
Registry Key Path
The registry key path field describes the registry entry that will be used to store
the values required for persistence. The default is to store the entries under
“SYSTEM\CurrentControlSet\Services\”.However, if the user provides the full
path, any other path can be set.
In the example above, the registry key path value will be set to
“SYSTEM\CurrentControlSet\Services\TestPath”.
Registry Description
The registry description field defines the overt description of the service that will
be used to start the Launcher. This value can be seen by the user and should be
set taking that into account.
In the example above, the registry description field will be set to “Assassin 64-
bit”
Registry Name
The registry name field defines the overt name that will show up in the services
list in windows. This value can be easily seen by the user and should be set
taking that into account.
In the example above, the registry name field will be set to “Implanted”.
DLL Path
The DLL path field defines the path that the launcher specific DLL will be copied
to. If the directory doesn’t exist, it will be created, however it will not be deleted
during uninstall. Therefore, it is recommended that an existing directory is used
for this value.
154
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh