Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
programs
Set of executable names to include in the whitelist, specified
as a Python list or tuple
files
Set of whitelist files, specified as a Python list or tuple
Blacklist files are whitespace-delimited lists of executable
names to include in a target blacklist.
Comms Configuration Tasks
The comms configuration tasks are used to modify the settings related to how
Assassin communicates. This includes both the transports used for
communication and the size of upload chunks.
set_transport <run_mode> [xml_file=None]
Set the communication transport configuration. If no parameters are provided,
the command will enter a subshell; see section 9.4.3 onTransport List subshells.
run_mode
Code specifying the run mode, represented by combining the
following keys:
‘r’ - run the task on receipt
‘s’ - run the task on every Implant startup
‘p’ - push the task results to the LP immediately
xml_file
XML file containing an Assassin transport list configuration
set_chunk_size <run_mode> <chunk_size>
Set chunk size to limit network traffic per beacon.
run_mode
Code specifying the run mode, represented by combining the
following keys:
‘r’ - run the task on receipt
‘s’ - run the task on every Implant startup
‘p’ - push the task results to the LP immediately
chunk_size
Maximum Implant upload size per beacon
Files larger than chunk_size bytes will be broken up to fit the
limit. Setting the size to 0 will disable upload chunking.
Operation Window Configuration Tasks
The operation window tasks are used to modify the settings related to the time
window during which the Implant will operate. This includes hibernate, scheduled
uninstall, and failure threshold settings.
set_hibernate <run_mode> <seconds>
Set the hibernate time in seconds after first execution. The Implant will lie
dormant until the hibernate period has elapsed.
105
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh