Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20350112
Figure 2: Alerting/Target Monitoring/Session Activity Example
(S) Figure 2 shows an Alerting/Target Monitoring/Session Activity example. First, the
Flytrap retrieves a Mission with Target Monitoring enabled. Next, an email or chat
Target is detected (the first green dot on the timeline), which triggers the Flytrap to send
an Alert. Then at each Target Monitor Interval, an Active or Inactive message is sent –
Active is sent if the Target’s client MAC generated network activity during the interval,
and Inactive is sent otherwise. Once the client MAC has been Inactive for the Mission-
configured “Session Timeout”, no more Active/Inactive messages are sent. In this
example, the same client MAC then becomes active again after being inactive for Session
Timeout. This generates a Derived MAC Alert, which is then followed by another Target
Monitor session until the client MAC is again inactive for Session Timeout.
7.7 (S) Target Actions
(S) Once the Flytrap has detected a Target and sent an Alert, it then performs Mission-
configurable Actions on that Target’s network traffic. Actions include Browser Redirect
(Windex), Copy, and VPN Proxy/Link (see 5.2.3.9). As stated before, all Targets are
tracked by MAC address (either a primitive MAC Target, or a Derived MAC derived
from an email address, chat user, or VoIP number). This MAC address tracking is
necessary to perform Target Actions. Note that the Flytrap ceases/clears any ongoing
Actions upon receipt of a new Mission (i.e., a Mission different than the one currently
executing).
7.7.1 (S) Target Action Inheritance
(S) When an email/chat/VoIP Target detection occurs, a Derived MAC is created. The
Actions to be performed on the email/chat/VoIP Target must be passed on to the Derived
MAC as well. A Derived MAC Target will immediately inherit any actions of the
email/chat/VoIP Target that generated the Derived MAC.
35
SECRET//20350112

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh