Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
Configuration Gyrfalcon v1.0 User Manual
2 Configuration
Use the configuration tool (eyrie.pyz) to generate a configuration file and appropriate gyrfalcon
executable for the target operating system. The configuration tool is invoked either as any other
executable on the system, or as an argument to the python interpreter:
$ ./eyrie.pyz -c
$ python2.7 ./eyrie.pyz -c
Invoked with no arguments, eyrie prints a brief help message and exits. The '-c' option is used to
configure an implant.
2.1 Global Configuration Options
Several implant-wide configuration options are available. Type the 'Command' letter at the cfg > prompt.
Option Name Command Description
Working Directory w Directory on target where gyrfalcon runs and saves collect file
Collection File c Name of collection file gyrfalcon will write (in working
directory)
Operating System o Target's operating system (linux is the only option)
Architecture r Target architecture (choice of x86, x86_64)
Max Output Size m Maximum size of collection file (in bytes)
Encrypted config name n Name of config file gyrfalcon will look for (in working directory)
when it starts up. If the config file is not found, gyrfalcon will not
run.
2.2 Per Target Configuration Options
Gyrfalcon has the ability to track multiple outbound SSH sessions. To manage this, it is configured with
a list of target IP address / netmask combinations. Use the 'a' command to add a new target. You will be
prompted with three questions:
1. Specify an IPv4 or IPv6 address/netmask:
2. Specify Collection Behavior
3. Specify path to executable file.
Each option is addressed in the following subsections.
Additionally, targets may be deleted or edited by target id. The target id is the # column in the targets
table.
To delete a target, use the 'd' command:
cfg > d 1
2 SECRET//NOFORN January 2013

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh