Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

o Slow Retry Pause (sec) – the amount of time pause for a slow retry in the
beacon logic.
o Fast Retry Pause (sec) – the amount of time pause for a fast retry in the
beacon logic.
Target Monitoring Parameters:
o Session Timeout (sec) – the amount of time in seconds to wait before
timing out a Target’s session. If a Target is inactive (i.e., has no network
activity) for at least Session Timeout, and then becomes active (i.e.,
generates network activity) again on the same Flytrap, the Flytrap will
send another Alert.
o Target Monitor Interval (sec) – the interval in seconds at which to send
target monitor updates. Set this to “0” to disable target monitoring.
Otherwise, the smaller this value is set, the faster the Flytrap will send
feedback on target activity.
Filter Parameters:
o Port Scanning – “Scan All Ports” will search network traffic for email/chat
Targets on all ports, “80 and Chat Ports” will only search traffic on port 80
(i.e., HTTP) and common chat service ports for email/chat Targets
o Protocol Scanning – “Scan All Protocols” will search network traffic for
email/chat Targets on all protocols, “Only Scan TCP” will only search
TCP traffic for email/chat Targets
o Remove Accept Encoding (gzip) from All Traffic – “yes” will remove the
“Accept Encoding” HTTP parameter from browser requests, so that a
webserver will not return gzip-encoded traffic. “no” will not remove the
“Accept Encoding” HTTP parameter. Selecting “yes” will typically result
in detection of a wider range of email addresses, but can increase the size
of page downloads by as much as a factor of 10.
Harvest & Global Actions:
o Harvest Email & Chat – select “Yes” to enable harvest. Note that harvest
data is sent at each Beacon, so a smaller Periodic Beacon Interval will
result in more responsive harvesting.
o Global Action – select “None” for no Global Action. Select “Copy All” to
copy all Flytrap data. Select “VPN Proxy All” to proxy all TCP and UDP
data. Select “VPN Link” to establish a VPN tunnel between the Flytrap
and the CB-VPN. Select “Copy VoIP” to copy all VoIP (RTP, RTCP, and
SIP) traffic.
o Copy All Timer if the “Copy All” or “Copy VoIP” Global Action has
been selected, this sets the duration over which to perform the copy
Action. The copy timer starts when the first packet of client data passes
through the Flytrap (which could occur at some time after the Mission is
retrieved). The copy action ends when either the “Copy All Timer”
expires, or the Flytrap retrieves a different Mission. Note that a value of
“0” performs the copy indefinitely.
o VPN Action Timer if the “VPN Proxy All” or “VPN Link” Global
Action has been selected, this sets the duration over which to perform the
Action. The timer starts when the Mission is successfully retrieved. The
38

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh