Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
SECRET//NOFORN
________________________________________________________________________
new value:
Tasking - Overt State File Path (string)
default:[]
new value:
Tasking - Batch Execution Timeout in seconds (number)
default:[0]
new value:
Tasking - Command Execution Timeout in seconds (number)
default:[0]
new value:
Tasking - Chunk Size - maximum number of bytes in a single block (number)
default:[0]
new value:
Tasking - Max CPU Utilization 0..100 (number)
default:[0]
new value:
Tasking - Max Processing Data Size (number)
default:[50331648]
new value:
Uninstall - Date (YYYY-MM-DDTHH:MM:SS) - UTC
default:[]
new value:
Uninstall - Deadman Delay in seconds (number)
default:[0]
new value:
Uninstall - Beacon failure attempts (number)
default:[0]
new value:
Uninstall - Kill File Path - full file path on target (string)
default:[]
new value:
Install - Target File Name (string)
default:[%SystemRoot%\System32\Microsoft\Crypto\RAS\iprcache.dll]
new value:
Install - Data File Name (string)
default:[%SystemRoot%\System32\CodeIntegrity\ras.cache]
new value:
Install - Restart service with Service Control Manager (SCM) (no,yes)
default:[yes]
new value:
[WIZARD COMPLETE]
Figure 11 - (S//NF) Builder Wizard Review
6.4 (U) Configuration
(U) This section contains the steps with detailed instructions/notes for configuring an implant.
Table 7 - (S//NF) Step-By-Step Implant Configuration Instructions
SECRET//NOFORN 15