Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

2 Introduction
Sundew is a Linux-based wireless survey tool used to identify the make and model of
wireless devices. It may also be used to re-flash the firmware on supported devices.
2.1 Definitions
Common terms used throughout this document include: network, network device, survey,
profile (Device Profile, Network Profile, and Device Type Profile), Auto-Survey, and
Mission.
2.2 Network
The term network, when used in conjunction with Sundew, is meant to refer to a wireless
local area network (WLAN) operating in infrastructure mode. In this architecture, a
wireless network is identified by an ESSID (the network name, often just referred to as a
SSID) and may contain or more wireless Access Points (AP). Each AP may then be
associated with one or more clients. Each AP is identified by a BSSID value, which in
infrastructure mode is always a MAC address.
2.3 Network Device
A network device is any wireless node that Sundew has identified through wireless
scanning. Each wireless device discovered by sundew is at least an Access Point (AP),
but it may include additional functionality (router, gateway, modem, etc.) so the more
generic term “network device” is used throughout this document.
Each wireless node is identified by a MAC address (BSSID), and it is assumed that no
two nodes will have the same MAC address. The information collected from a single
device is referred to as a “Device Profile”.
2.4 Survey
A survey is a series of tasks that inspect a network device, with the goal of identifying the
device’s unique characteristics such as it’s make and model The supported survey
techniques are covered in 4.5 Survey Task Configuration.
2.5 Profiles
Profiles are used to define or initialize the properties of devices or networks. Sundew
uses three profile types: Device, Network, and Device Type. The interaction of these
profiles is shown in Figure 1 Profile Interaction Diagram. Profile creation or editing is
covered in sections 4.3 and 4.4.
- 3 -

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh