Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
15.1 Transferring Logs
The Gibson provides the Log Collector and Extractor to transfer logs generated on
the LP to the C2.
The Log Collector collects log files from a specified directory into a TAR file and
deletes the source files. It will collect any file whose name ends with '.log' and does
not begin with '~'. The collector then transmits the TAR file to the Log Extractor via
the Galleon Transport interface (version 1). The Log Collector can be invoked
directly or as a Receive Handler as defined by the Galleon Transport interface.
The Log Extractor accepts the TAR file generated by the collector and extracts it to
a specified directory. If the extractor is configured to combine the logs, it will sort
and append multiple logs of a given type to a combined final log.
127
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh