Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//20340424
$UpCase - $UpCase is a file that contains a map of lowercase Unicode characters and the
uppercase equivalents.
$Extend - $Extend is a directory containing the location of extended metadata files,
$Quota, $ObjID, SReparse, and $UsnJrnl.
$Quota - $Quota file is a directory containing a list of users and files saved under their
quota restraints.
$Objid - Object Identifier is part of the NTFS Link Tracking Service (LTS). This service
enables Windows to keep track of a file or directory even when the name or location is
changed.
$Reparse - Reparse Points are similar in function to a link or shortcut file. A reparse point
can be used as a mount point for volumes, directories, or files. $Reparse is an index
containing a list of reparse points in use on the volume.
$Usnjrnl - Change Journal is designed to keep track of any changes made to $MFT
records. It provides a persistent log of changes made to files on a volume. When any file
or folder is created, modified, or deleted, NTFS adds a record to the change journal for
the volume. The change journal is turned off by default.
BIOS - BIOS stands for Basic Input Output System. It is a combination of low-level
software and drivers that function as the interface, intermediary, or layer between a
computer's hardware and its operating system. They load into RAM from the motherboard
ROM (ROM BIOS), an adapter card ROM, or from disk in the form of disk drivers.
Cluster - Cluster is the smallest allocation unit on a hard drive. It can be the size of one
sector. A cluster is normally comprised of many sectors.
File System - File System is a method of storing and retrieving data on a computer system
that allows for a hierarchy of directories, subdirectories, and files.
File Slack - File Slack is the area from the end of the logical file until the end of the
cluster.
hiberfil.sys - hiberfile.sys is a file that allows Windows to hibernate. The machine powers
off, goes to sleep, and can be brought back to the precise point where it went to sleep. To
accomplish this, the entire contents of RAM must be written to a file, hiberfile.sys.
Hives - Hives are the component files that make up the registry. There are five hives in the
registry: HKEY_CLASSES_ROOT, HKEY_CURRENT_USER,
HKEY_LOCAL_MACHINE, HKEY_USERS, HKEY_CURRENT_CONFIG.
HKEY_CLASSES_ROOT - HKCR contains information about file extension
associations. One of the five hives of the Windows registry.
SECRET//20340424
12

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh