Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
SECRET//20350629
also specify the amount of space to leave on the drive, the timeout value - a time when
the application will terminate upon execution on target.
(S) A new feature for v6.2 is the execution counter. This feature creates a counter at the
end of the file. Each time the dll created by Mac-n-Cheese launches the EZCheese dll the
counter is decremented.
Figure 2: (S) Survey Options Tab
(S) The next tab is for Survey Options (Figure 2). Clicking the Enable survey options
checkbox will enable the screen. Now the user can select specific survey options to run
on the target. The first section is a set of canned Windows Management Instrumentation
queries. The user may also enter custom queries to run against the target for both WMI
and against Registry Keys. The last section allows the user to run file system surveys
based on Windows Search - as the tool Boilermaker does. Please note that this will only
work on Windows Vista and higher - it is disabled for earlier versions of Windows.
(S) The final field is for the user to specify the survey output directory on the flash drive.
The survey output directory will be the location where the collection program will save
the survey information. If the output directory is intended for the USB drive, begin the
path with a backslash or with %drive%. For example: \surveyOutput or %drive
SECRET//20350629
5