Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
3. (U) System Description
3.1 (U) Technical References
Table 2 - (S//NF) Included Files
File Name Size MD5
nf_table_6_64.ko 9672 2CB8954A3E683477AA5A084964D46
65D
(S//NF) When the module is loaded, the hidden table is named “dpxvke8h18”.
3.2 (U) Concept of Operation (CONOP)
(S//NF) The OutlawCountry tool consists of a kernel module for Linux 2.6. The Operator
loads the module via shell access to the target. When loaded, the module creates a new
netfilter table with an obscure name. The new table allows certain rules to be created
using the “iptables” command. These rules take precedence over existing rules, and are
only visible to an administrator if the table name is known. When the Operator removes
the kernel module, the new table is also removed.
Figure 1 - (S//NF) OutlawCountry Concept of Operation
2
SECRET//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh