Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
Color Meaning
Green The file has been corrupted, but still exists
Orange The file has not been corrupted
Gray The file has been deleted, and the path is no longer valid
The “Files” table is interactive. The currently selected entry in the table is highlighted blue.
Right-clicking an entry in the table will display a menu with the following options:
Show in Folder – open the file’s location in Explorer with the file selected
Corrupt – Writes random data to the entirety of the file, corrupting it
Corrupt and Delete – Writes random data to the file, then deletes it from the system
Corrupt All – Attempts to corrupt all files that are visible in the table
o Selecting this option will prompt a confirmation request
A deleted file (whose entry should be color-coded gray) cannot be “shown in folder”. If
Dumbo fails to corrupt or delete any file, a warning will be displayed to the operator.
Microphones Section
The microphone section is located in the bottom left corner of the “Camera & Microphone”
tab. This section displays whether all microphones are muted, or if at least one microphone
is unmuted and could be actively recording.
To restore the microphones to their previous unmuted/muted state, before Dumbo gained
execution, click on the “Restore Initial” button. If all microphones were muted before
Dumbo gained execution, clicking the button will not have any effect. If at least one
microphone is unmuted, the button will change to a “Mute All” option.
If Dumbo fails to mute any microphone, a warning will be displayed to the operator.
Link to view a screenshot of the Camera & Microphone tab
3.2.4 (U) Exit Options Tab
The “Exit Options” tab is broken into two subsections, based on the desired exiting method:
Exit Delay
Blue Screen
Exit Delay
The “Exit Delay” subsection of the Exit Options tab displays the following information:
Restoration Time – the time that network adapters, microphones, and suspended
processes will be restored to their original status. This time is calculated by adding
the system’s current time and the number of minutes to delay.
SECRET//NOFORN
5

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh