Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20350629
(S) Mac-n-Cheese has the option to have the dll create a file with a process list and OS
version. Specify the location where you want the file to be created. It will be created
system and hidden in that location. Make sure the location is on the usb drive.
(S) A option for v6.3 is the “execution counter”. If you check this option then you can
use the execution counter option in EZCheese. In EZSurvey GUI main screen you can
specify how many times the executable should be launched by the Dll.
(S) If no processes or OS / Service Pack combinations are to be avoided, the
configuration may be complete at this point.
(S) It is a good idea to save the configuration file on the configuration machine or another
non-operational drive for easy reference.
Figure 7: (S) OS Avoid List tab
(S) The next tab is the “OS Avoid List”. If the payload executable is known to have
issues with specific OS or Service Pack combinations, they can be specified here. For
example, if the payload will not work with Windows 7 Service Pack 1, select Windows 7
from the Operating System drop-down, then Service Pack 1 from the Service Pack drop-
down, then click the Add button.
(S) If the payload should not be launched on future versions of windows, click the
“Avoid unknown OSs” checkbox.
SECRET//20350629
11

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh