Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
wildcard
Filter used to limit the walk collection based on filename
The ‘*’ wildcard will match any string in the filename.
depth
Number of directory levels to descend, where 0 will only collect
on the root level
time_check
Type of filter used to limit the walk collection based on the
files’ modified timestamp:
‘no_check’ - do not check the file timestamp (default)
‘less’ - match timestamps less than the given time and
date
‘greater’ - match timestamps greater than the given time
and date
date
Date-Time or Date for time check, specified in ISO 8601 format
Required if time_check is not set to no_check
Date-Time: yyyy-mm-ddThh:mm:ss
Date: yyyy-mm-dd
get_walk <run_mode> <r_dir> <wildcard> <depth> [time_check=’no_check’] [date]
[offset=0] [bytes=0]
Walk the directories on the target, collecting files specified by the provided
parameters.
run_mode
Code specifying the run mode, represented by combining the
following keys:
‘r’ - run the task on receipt
‘s’ - run the task on every Implant startup
‘p’ - push the task results to the LP immediately
r_dir
Root directory of get walk on remote file system
wildcard
Filter used to limit the walk collection based on filename
The ‘*’ wildcard will match any string in the filename.
depth
Number of directory levels to descend, where 0 will only collect
on the root level
time_check
Type of filter used to limit the walk collection based on the
files’ modified timestamp:
‘no_check’ - do not check the file timestamp (default)
‘less’ - match timestamps less than the given time and
date
‘greater’ - match timestamps greater than the given time
and date
date
Date-Time or Date for time check, specified in ISO 8601 format
Required if time_check is not set to no_check
Date-Time: yyyy-mm-ddThh:mm:ss
Date: yyyy-mm-dd
offset
Byte offset into files to begin collection (default = 0)
“Get from <x> bytes into file.”
32
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh