Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20340424
HKEY_CURRENT_USER - HKCU contains user information, preferences, and settings
for the currently logged in user. One of the five hives of the Windows registry.
HKEY_LOCAL_MACHINE - HKLM contains information specific to the computer.
One of the five hives of the Windows registry.
HKEY_USERS - HKU contains user information from the user currently logged in and
the default profile. The user information here is an alias to HKCU. One of the five hives of
the Windows registry.
HKEY_CURRENT_CONFIG - HKCC is dynamically created during the boot process
and contains information associated with the hardware configuration.
INFO2 - INFO2 file contains a single record for each deleted file or folder in Windows.
Junctions - Junctions are similar to volume mount points. Junctions are directory mount
points that point a folder to another folder.
NTUSER.DAT - NTUSER.DAT is a file that contains user specific registry settings such
as personal configuration, preferences, and program settings.
NTUSER.DAT.log - NTUSER.DAT.log is a log file that records changes made to the
User registry hives within the NTUSER.DAT file.
Prefetch File - Prefetch Files are trace files that enable expedient loading of previously
launched applications into memory.
Page file - A file on disk that is used to cache RAM memory. It is also called a swap file.
pagefile.sys - Pagefle.sys is a file on disk that is used to cache RAM memory. Windows
NT based operating systems use the pagefile.sys as temporary storage for data dumped
from primary memory (RAM). The pagefile is often used to store unused memory pages
when all existing space within physical RAM is full.
Partition - Partition is a collection of consecutive sectors within a volume and is a
container for a file system, with specific boundaries and properties.
Registry - Registry is a hierarchal database in Windows that contains system and user
specific data.
ROM - Read Only Memory holds data permanently. It is nonvolatile.
RAM - Random Access Memory is a temporary workspace for storing data, code,
settings, and so forth.
Ram Slack - Ram Slack or Sector Slack is the area of space after the data until the end of
SECRET//20340424
13

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh