Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

Elsa User Manual.doc
15
SECRET//NOFORN
5.1 (S) SvcHost Mode Installation
(S) This mode will add Elsa as a windows service, running within one of the svchost.exe
processes on the system. Installation proceeds as follows:
1) Run the patcher with the appropriate processor architecture specified:
1. Select SvcHost as the Mode
2. Select SvcHost.exe as the target process filename
3. Enter a service name, display name, description and service group – these will
be visible to the target user
4. Complete the remaining patcher options
2) Place the patched Elsa dll on the target system
3) Check that the wlansvc and eaphost services are running as follows (see
troubleshooting section if they are not running):
> sc query wlansvc
> sc query eaphost
4) Substituting the appropriate dll name, silently load the dll using the RegSvr32
utility:
> RegSvr32 /s C:\ELSA.DLL
5) You can now verify that the display name (e.g. - “Windows Management
Instrumentation Device Extensions”) in the services panel.
6) The service is just registered in the Services panel – it is not running. It will
automatically start on reboot, but if you want to run it immediately use the
following command with the appropriate service name (not display name):
> net start wmidx
-or-
> sc start wmidx
7) The service will restart automatically on reboot.
5.2 (S) DllHost/Task Scheduler Mode Installation
(S) Dllhost mode is highly analogous to svchost mode; the dll must be registered and then
a Windows system process must be instructed to load it. In this case the Windows Task
Scheduler loads the dll as a 'task'. This will only work on systems with Task Scheduler
2.0 or greater.
(S) Since creating the task scheduler entry is more complex than starting the service in
SvcHost mode, a script has been provided (see “Scripts for DllHost Mode Install /
Uninstall”). The operator can either manually run this script or let Elsa run it
automatically when it is registered using the RegSvr32 utility. This script is just an

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh