Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
2 Assassin Configuration / Receipt XML File Format
The Assassin configuration and receipt files follow a similar format and can be used
interchangeably. The receipt file consists of all configuration files required to
customize a full Assassin build. This includes a combination of implant, extractor,
launcher, and service installer configuration values and the build outputs
requested/created. This appendix will explain the formatting for each section of the
file and provide an examples of each section.
The configuration of the build is stored in a root <Config> tag, containing the
<BuildOutputs>, <Implant>, <Extractor>, <Launcher>, and <ServiceInstaller> tags
described below.
XML Example
<Config build_time="2012-03-07T11:22:25" version="1.0">
<BuildOutputs>...</BuildOutputs>
<Implant>...</Implant>
<Extractor>...</Extractor>
<Launcher>...</Launcher>
<ServiceInstaller>...</ServiceInstaller>
</Config>
Attribute Definitions
build_time
The build_time attribute specifies the time at which the build was executed and
the Assassin executables generated. The time is represented in ISO 9601 format.
version
The version attribute specifies the version of the configuration data format.
126
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh