Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
8.3 (U) User Interface
(S//NF) The Tasker shell interface allows for an interactive processing mode. There are two
input options. By simply selecting a management feature or command feature and pressing
enter, a wizard interface will be presented to select all required options for the feature.
Alternatively, for more advanced users, a command line option with tab-complete can be used to
process commands on a single line. The formatting of the command features is identical to the
script output format.
Management Features
============================================================
receipt generate ls rm import id help
Command Features
============================================================
execute get put memload memunload set delete uninstall
Exit Commands:
============================================================
bye exit
Welcome to the Athena Tasker shell. Type help or ? to list commands.
Figure 17 - (S//NF) Tasker Main Menu
8.3.1 (U) Management Features
(S//NF) The Tasker Management Features provide control of the batch file created to task a
specific implant. The receipt defines the Parent ID of the target to process. Each command set is
known as a batch. Each batch file contains a unique Batch ID.
8.3.1.1 (U) Receipt
(S//NF) This command updates the target reference by loading the receipt.xml file defined for
the target.
Usage: receipt <receipt filename>
Example: receipt builder_output\test_ABCD0064\test_ABCD0064.receipt.xml
Output:
New Receipt Loaded:
Receipt File: builder_output\test_ABCD0064\test_ABCD0064.receipt.xml
Parent ID: test
8.3.1.2 (U) Generate
(S//NF) This command will generate an encrypted batch file ready for deployment on the
Listening Post. This command has additional options:
Priority (number 0..255): 0-highest, 255-lowest – priority for the server to process batch
Persist (bool): true-do not delete, false-delete once sent – force a file to always be run
SECRET//NOFORN 28

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh