Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED//FOUO
Processing: D:\Window10 - Copy (x64::standard)
>> Reg: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
netsvcs -> Dnscache
>> Reg: SYSTEM\CurrentControlSet\Services\Dnscache
ObjectName -> LocalSystem
ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs
Start -> 0x02
Type -> 0x20
>> Reg: Parameters
extension -> %SystemRoot%\System32\Microsoft\Crypto\DNS\dnsclext.dll
>> Source: D:\Development\Athena\offline\win\x64\Debug\target_x64.dll
Dest: D:\Window10 - Copy\system32\microsoft\crypto\dns\dnsclext.dll
>> Source: D:\Development\Athena\offline\win\x64\Debug\target_x64.dat
Dest: D:\Window10 - Copy\system32\codeintegrity\dns.cache
SUCCESS
Ramonly
The ramonly capability allows the full functionality of the Athena framework without
persistence or write access to the local machine. All other capabilities are available
when run in this mode.
UNCLASSIFIED//FOUO