Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED//FOUO
Srvhost cannot access foreground desktop due to os restrictions.
Does this command execute programs exclusively or shell commands as
well? If cmd, we may
want a CMD command or just tell the users to use “cmd /C”.
Get:
Command needs dword offset/size to support 4.5.1.4/4.5.2.4.
What does override flag do for the GET command?
Is dword 4GB enough for files?
Is there any way to get a file listing except via cmd?
What happens if a directory is selected?
Put:
Command needs dword offset to support 4.5.1.4/4.5.2.4.
Is dword 4GB enough for files?
What happens if the file already exists (overwrite?)
What happens if the file refers to a directory?
Memload:
Is nickname really what you want to transmit or is an internal memload ID
enough and the
server views the user “nickname” on the backend?
Does this command only support nod persistent dlls or pic or axe as well?
Memunload:
Should probably remove nickname and just have an internal memload ID.
Set:
BYTE ATHENA_CONFIG_TYPE_XXX (dword/time/string/stringlist/buffer)
ULONG value (dword/time)
or
ULONG size (string/stringlist/buffer)
UCHAR buffer
Is there a way to delete the dynamic value and reset to default?
Is there a way to disable the setting to override the default but make it
inactive? Most values of
0 are inactive.
Uninstall:
Should this command at least respond saying that the command has been
received?
UNCLASSIFIED//FOUO

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh