Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED
Cherry Bomb Program Cherry Blossom Internal Test Procedures
From the flytrap, the VPN link can be confirmed by watching the output log and
ensuring that the “pa” process is started and that the OpenVPN link is brought
up.
Pass/Fail: The test passes if a valid VPN Link is created when and only when
the target is detected.
Note: Additional notes and information about the VPN link can be found in
<Test>/vpnProxy_configuration.txt.
4.2.28 Target Based VPN Proxy Action Test
Description: Tests the target based proxy action.
Setup: Plan/Assigned a mission with a target based Proxy action. Connect two
client computers to the flytrap.
Run: Generate an Alert at one of the client computers. Verify the VPN Link is up.
Verify (via ping) connection to the flytrap. Verify port scan (via netcat) of a service
running on the client computer. Verify network traffic of the client computer is
proxied through the VPN Server (check the proxydata directory found at
~cbuser/CherryBlossom/CherryTree/Release/proxydata).
Pass/Fail: The test passes if a valid VPN Link is created when and only when
the target is detected, the VPN Server indicates a proxied connection from the
Client Computer (and not the Second Client Computer), and the Client Computer
experiences no difference from normal behavior when surfing the internet.
Note: Additional notes and information about the VPN link can be found in
<Test>/vpnProxy_configuration.txt.
4.2.29 VPN Link Global Action Test
Description: Tests the VPN Link global action.
Setup: Plan/Assign a mission with the global action set to ‘VPN Link.’
Run: Verify the VPN Link is up upon receipt of the Mission. Verify (via ping)
connection to the flytrap. Verify port scan (via netcat) of a service running on the
client computer.
Pass/Fail: The test passes if a valid VPN Link is created when the new Mission
is received.
Note: Additional notes and information about the VPN link can be found in
<Test>/vpnProxy_configuration.txt.
UNCLASSIFIED
36