Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED//LES
connectstothesamenetworkwithadifferentnetworkinterface(e.g.switchesfromwiredtowireless)
thenFulcrumwillstopworkingbu tthepivotmachinewillremainonline.
3.3 ARPSCANNINGAND/ORARPSPOOFINGMAYATTRACTATTENTIONFROM
SECURITYPRODUCTS
Description:TheuseofAR PscansandARPspoofsonanetworkmaydrawtheattentionofsecurity
productsdeployedonthepivotmachineoranywhereonthenetwork.
Reason:FulcrumusesgratuitousARPrepliesforitsMITMattackandwillsometimesuseARPrequestsin
ascanlikefashioninordertofindthetarget.Variousclassesofsecurityproductsincludingsome
IntrusionDetectionSystems(IDS)a ndPersonalFirewallsaswellaspurpose‐builttools(e.g.arpwatch,
arpfreeze)candetectARPscansand/orARPspoofs.Sometoolsevengoastepfurtherandthwartthe
spoofingattempt.
RecommendedMitigatio n:Dont useFulcrumonnetworkswhic harelikelytohaveIDSand/ornetwork
monitoringinplace(e.g.corporateorenterprisenetworks).Wheneverpossible,identifywhichPerso nal
SecurityProducts(PSP)are runningonthepivotmachinetodetermineifthereareanyknownissues
withthatproduct.IfFulcrumisuntest edagainstthatspecificPSPorversion,thenanin‐housetest
mimicking t he real environment should be done first in order to provide some measure of assurance.
AdditionalNotes:Thisisthesame techniquecurrentlyemployedonwirelessLANengagements.
3.4 FULCRUMWILLSTOPRUNNINGIFTHEPIVOTMACHINEIS REBOOTED
Description:IfthepivotboxwhichFulcrumisrunningonreboots,Fulcrumwillnotauto‐restart.
Reason:Fulcrumdoesnotprovideanypersistentmechanisms.
RecommendedMitigatio n:Whatevermechanismisusedtodeliver,command,andcontrolFulcrumis
responsibleforeitherrestartingFulcrumornotifyingtheoperatorthatthemachinehasbeenrebooted
andamanualrestartofFulcrum isrequired.
AdditionalNotes:
3.5 POTENTIAL LOSSOFCONTROLOFFULCRUM
Description:Fulcrummayrunindefinitelyifcommunicationsarelostwiththepivotmachine.
Reason:Fulcrumdoesnotimplementanycommunicationschannelorhaveasuicidedate.Fulcrumwill
runindefinitelyuntiliteitherhits the targetsuccessfully,unsuccessfullytries11times,thepivot
machineisrebooted,ortheparen tprocessdies(ifrunasaDLLviaLoadLibrary).Ifthetargetmachineis
rarelyorneveronlinewhenthepiv otmachineisandthecommunications channeltothepivotmachine
issevered,thenFulcrumwillrun indefinitelyuntiloneoftheseconditions occur.
UNCLASSIFIED//LES
Page5