Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
The status result dir filesfield is a custom status result that provides a file walk of
all of the files in the target implants directories.
XML Example
<StatusResultDirFiles>
<FileWalkRecord>
<FileName>c:\temp\input\zvC3VP</FileName>
<FileSize>32b</FileSize>
<CreatedTime>2011-12-21T16:15:06</CreatedTime>
<ModifiedTime>2011-12-21T16:15:11</ModifiedTime>
<AccessedTime>2011-12-21T16:15:06</AccessedTime>
</FileWalkRecord>
<FileWalkRecord>
<FileName>c:\temp\output\zvC3VP.WqTCxg</FileName>
<FileSize>3k231b</FileSize>
<CreatedTime>2011-12-21T16:15:11</CreatedTime>
<ModifiedTime>2011-12-21T16:15:11</ModifiedTime>
<AccessedTime>2011-12-21T16:15:11</AccessedTime>
</FileWalkRecord>
. . .
</StatusResultDirFiles>
Field Definitions
File Walk Record
The file walk record entries are the results of a file walk command ran on
the target Implant directories. For a definition of the file walk record
entries see the section on get walk results.
Status Result Comms
The status result comms field is a custom status result that provides the target
implant’s communication settings.
XML Example
<StatusResultComms>
<ChunkSize>1m</ChunkSize>
<TransportList>
<Transport type=”HTTPS” tries="2">
<Host>assassin_lp</Host>
<Port>443</Port>
<ProxyCredentials />
</Transport>
</TransportList>
172
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh