Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
Warning
(S//NF) Implant configuration may be completed on the low-
side; however, the operator should be aware that
cryptographic key data will be in the clear.
(S//NF) By default, the Builder will walk the operator through the process of configuring an
implant (via the wizard) that will be deployed to a target computer. Alternatively, the operator
can also input all configuration values via command line arguments in order to build an implant
with a single command.
Builder
usage: builder.py [-h] [-i SYSTEM_BINARY_PATH] [-r SYSTEM_IMPORT_XML]
[-o SYSTEM_EXPORT_PATH] [-w] [-b] [--debug]
Builder Configuration
optional arguments:
-h, --help show this help message and exit
-i SYSTEM_BINARY_PATH, --input SYSTEM_BINARY_PATH
This argument provides the location of the raw binary
data files. (NOTE: .\bin is the default path).
-r SYSTEM_IMPORT_XML, --receipt SYSTEM_IMPORT_XML
This argument defines an existing receipt filename to
be used for default values.
-o SYSTEM_EXPORT_PATH, --output SYSTEM_EXPORT_PATH
This argument provides the output directory path to
store the target files (NOTE: .\builder_output is the
default path).
-w, --wizard This argument will request information from the user
via the wizard.
-b, --bravo This argument builds the Athena BRAVO implementation.
--debug This argument allows debugging information to be
included in the output directory.
Figure 9 - (S//NF) Builder Command Line Options
6.2 (U) Command Line Options
The builder.py script has multiple command line options. For most users, no command line
options are required. The local directory will be used to output results.
Usage: python.exe builder.py
6.2.1 (U) System Binary Path
(S//NF) This argument provides the location of the raw binary data files. The default location is
in the current directory in the BIN folder. Figure 10 (below) shows the files that must reside in
the system binary path.
SECRET//NOFORN 12

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh