Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
o Note: Since the restoration time is dependent on the system’s clock, if the
target system has an incorrect time setting, the restoration time will be
incorrect as well.
Delay Timer – the number of minutes to delay before restoring the system to its
original state. The default value is 7 minutes.
An operator may adjust the default delay time by clicking the up or down arrows next to the
box, manually enter a value, or by using the mouse-wheel if the box has focus. The
maximum delay time is 99 minutes, and the minimum time is 0 minutes (no delay).
If the operator clicks the “Start Exit Delay” button, Dumbo will hide its window and wait the
prescribed delay amount. If the operator closes (“X”) the window at any time, Dumbo will
wait the delay amount as well.
Blue Screen
The “Blue Screen” subsection of the Exit Options tab displays the following information:
Crash Dump Setting – informs the operator how much memory will be dumped in
the event of a crash. Details on the possible options can be found below
Log Event – If enabled, an entry that the system crashed will be created in the
system’s event log
Auto-Reboot – If enabled, the system will automatically reboot after a crash. If
disabled, the blue screen error message will remain on the screen until the system is
manually rebooted.
Table of Crash Dump Settings
Color Setting Meaning
Green Disabled No memory dump will occur on a crash
Yellow Mini-dump A minimal amount of memory is written to a file on crash
Orange Kernel All kernel memory is written on a crash (Default Value)
Red Full All memory is written to a file on crash
Note: The crash dump, log event, and auto-reboot settings are determined by reading
registry values that are read only once, upon startup. Although unlikely, the system could
have changed these values, but not have rebooted since the change. This would result in
Dumbo reporting incorrect values.
(S) Note: Full crash dumps present a potential detection threat. Although it would be
extremely difficult, a motivated actor could potentially attribute the blue screen to Dumbo,
and subsequently reverse engineer the tool. Because of this, it is recommended that
the blue
screen exit option not be exercised on systems will a full crash dump setting enabled.
If the operator clicks the “Attempt Crash” button, the tool will ask for a confirmation. If
confirmed, and Dumbo is able to create a blue screen crash scenario, the tool will exit and a
blue screen should occur within 15 seconds.
SECRET//NOFORN
6

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh