Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
Action / Help Text Notes
1
Target - Parent ID (4 chars)
default:[RnzI]
new value:
The name used for this group of implants.
Name – 4 characters in length
2
Target - Child ID (number - dword)
default:[]
new value:
The optional name of a specific implant known as a
child. This option allows the user to define a
specific implant otherwise the system will use the
first 4 bytes of the mac address or a random
number.
Name – dword – default is mac address (4bytes)
3
Target - dynamic data config type
(internal,file,registry)
default:[internal]
new value:
---------------------------------------------------------------------
Target - dynamic data config type
(internal,file,registry)
default:[internal]
new value: file
File - define the full path and file name
NOTE: name can include environment
variables
Examples: c:\temp\a.txt or c:\
%SystemRoot%\a.txt
Target - dynamic data config path (file
name or registry value name)
default:[None]
new value:
c:\temp\myfile.txt
---------------------------------------------------------------------
Target - dynamic data config type
(internal,file,registry)
default:[internal]
new value:
registry
Registry - define the full path to the
registry value
HKLM -> HKEY_LOCAL_MACHINE
HKCR -> HKEY_CLASSES_ROOT
HKCC -> HKEY_CURRENT_CONFIG
HKCU -> HKEY_CURRENT_USER
HKUS -> HKEY_USERS
Examples:
HKLM\SOFTWARE\Microsoft\Value
Target - dynamic data config path (file
name or registry value name)
default:[None]
new value:
HKLM\SOFTWARE\Microsoft\myvalue
The default location of configuration settings that
change on the target.
internal - 0 - use data file to store config
file - 1 - use external file to store config
registry - 2 - use registry to store config
Default Hives:
HKLM -> HKEY_LOCAL_MACHINE
HKCR -> HKEY_CLASSES_ROOT
HKCC -> HKEY_CURRENT_CONFIG
HKCU -> HKEY_CURRENT_USER
HKUS -> HKEY_USERS
Example:
HKCU\SOFTWARE\ATHENA
or
HKLM\SOFTWARE\Microsoft\ATHENA
The user must enter a subsequent value when
selecting the file or registry option. See example
entries in
blue.
4
Beacon - Interval in seconds (number)
default:[86400]
new value:
The default time between beacons.
Time in seconds
SECRET//NOFORN 16

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh