From 58c3b75e5e60286b766002a5c8c4af02fdaefbf2 Mon Sep 17 00:00:00 2001 From: n0mad1k Date: Thu, 19 Mar 2026 17:15:43 -0400 Subject: [PATCH] Add OPSEC Principles, Physical Access, and Cyber Implants manuals --- output/manuals/04_Physical_Access.md | 390 ++++++++++++++++++ output/manuals/06_OPSEC_Principles.md | 473 ++++++++++++++++++++++ output/manuals/07_Cyber_Implants_Tools.md | 391 ++++++++++++++++++ 3 files changed, 1254 insertions(+) create mode 100644 output/manuals/04_Physical_Access.md create mode 100644 output/manuals/06_OPSEC_Principles.md create mode 100644 output/manuals/07_Cyber_Implants_Tools.md diff --git a/output/manuals/04_Physical_Access.md b/output/manuals/04_Physical_Access.md new file mode 100644 index 0000000..7e365fc --- /dev/null +++ b/output/manuals/04_Physical_Access.md @@ -0,0 +1,390 @@ +# Physical Access & Entry Manual + +> Synthesized from: CIA tradecraft manuals (declassified), physical security assessment resources, +> Grugq OPSEC analyses, FM 2-22.3, open-source tradecraft literature +> +> Classification: OPEN SOURCE — compiled from publicly available materials + +--- + +## Table of Contents + +1. Principles of Physical Access +2. Target Assessment +3. Lock Bypass Techniques +4. Social Engineering for Access +5. Surreptitious Entry Operations +6. Postal & Logistics Operations +7. Counter-Forensic Discipline +8. Physical Access Checklists + +--- + +# Chapter 1: Principles of Physical Access + +## 1.1 The Access Spectrum + +Physical access operations range from the trivial to the extraordinarily complex. The skill is in choosing the right approach for the target, not in always using the most sophisticated technique. + +**The spectrum:** +- **Social engineering** — Talking your way in. Lowest technical skill, highest human skill. Works against most targets because people are the weakest link in any security system. +- **Opportunistic access** — Exploiting unlocked doors, tailgating, maintenance windows. Requires patience and observation, not tools. +- **Technical bypass** — Defeating locks, alarms, cameras, and access control systems. Requires tools, training, and practice. +- **Forced entry** — Breaking in. Last resort. Leaves evidence. Appropriate only when covert access is not required or not possible. + +The general rule: try the simplest approach first. A $5 clipboard and a confident walk will get you through more doors than a $500 lock pick set. + +## 1.2 The Three Requirements + +Every physical access operation requires three things: + +1. **Access** — A way to get inside the target space +2. **Time** — Enough uninterrupted time to accomplish the objective +3. **Cover** — A plausible explanation for being there if discovered + +If any of these three is missing, the operation should not proceed. + +--- + +# Chapter 2: Target Assessment + +## 2.1 Pre-Operational Surveillance + +Before any physical access attempt, the target must be thoroughly assessed. This is not optional. Skipping assessment is the primary cause of physical access failures. + +**What to document:** + +**The physical space:** +- All entry and exit points (doors, windows, loading docks, emergency exits, roof access) +- Lock types on each entry point (pin tumbler, electronic, magnetic, padlock) +- Alarm system type and configuration (motion sensors, door contacts, glass break, keypads) +- Camera locations, coverage angles, and recording method (local DVR, cloud, monitored) +- Lighting conditions (interior and exterior, timers, motion-activated) +- Neighboring structures and sight lines + +**The human element:** +- Guard schedules (shift changes, patrol patterns, break times) +- Employee arrival and departure patterns +- Cleaning crew schedule and access level +- Delivery schedules (when doors are propped open, when loading docks are active) +- Neighbor patterns (who might observe your entry) + +**The timing:** +- When is the target space empty? +- When are guards least alert? (typically 2-4 AM, immediately after shift change) +- What events create access opportunities? (maintenance windows, construction, deliveries) +- How long can you be inside without discovery? + +## 2.2 Security System Assessment + +**Alarm systems:** +- Panel location (usually near main entry) +- Entry delay zones (which doors give you time to disarm) +- Immediate alarm zones (which doors trigger instantly) +- Monitoring method (central station, local siren only, or unmonitored) +- Backup power (battery duration after power cut) +- Cellular backup (does it phone home if landline is cut?) + +**Access control:** +- Credential type (key card, fob, PIN, biometric, combination) +- Can credentials be cloned? (HID Prox cards are trivially cloneable) +- Fail-safe vs fail-secure locks (fail-safe opens on power loss, fail-secure stays locked) +- Anti-passback features (must badge in before badging out) + +**Cameras:** +- Real vs dummy cameras (look for indicator lights, cable connections, lens quality) +- Recording retention period (most systems overwrite after 7-30 days) +- Monitored in real-time or reviewed only after incidents? +- Night vision capability +- Blind spots in coverage + +--- + +# Chapter 3: Lock Bypass Techniques + +## 3.1 Pin Tumbler Locks (Standard Door Locks) + +The most common lock type in residential and commercial settings. Understanding pin tumbler mechanics is fundamental to physical access tradecraft. + +**How they work:** A cylinder contains spring-loaded pins of varying heights. The correct key pushes each pin to the shear line — the boundary between the plug (rotating part) and the housing (fixed part). When all pins are at the shear line, the plug rotates and the lock opens. + +**Single Pin Picking (SPP):** +1. Insert tension wrench at bottom of keyway, apply light rotational pressure +2. Insert pick above tension wrench +3. Feel for the binding pin (the pin with the most resistance) +4. Push binding pin to shear line — you will feel a slight click and the plug will rotate fractionally +5. Find the next binding pin and repeat +6. Continue until all pins are set and the plug rotates fully + +**Difficulty factors:** Number of pins (typically 5-6), pin tolerances (tighter = harder), security pins (spool, serrated, mushroom — provide false sets). + +**Time estimate:** 30 seconds to 5 minutes for a standard 5-pin lock. High-security locks may take 15-30 minutes or be effectively unpickable. + +**Raking:** +A faster but less reliable method. Insert a rake (a pick with a wavy profile) and rapidly move it in and out while applying tension. This randomly sets pins through manipulation. Best for low-security locks when speed matters more than stealth. + +**Bump keys:** +A specially cut key that, when struck with a bump hammer, momentarily bounces all pins above the shear line simultaneously. Simple to execute, works on most standard pin tumbler locks. Defeated by security pins and anti-bump features. + +## 3.2 Other Lock Types + +**Padlocks — Shimming:** +Insert a thin metal shim (cut from a beverage can) between the shackle and the lock body. The shim pushes the locking pawl aside, releasing the shackle. Works on spring-loaded padlocks. Does NOT work on padlocks with anti-shim features (ball bearing locking mechanism). + +**Tubular locks (vending machines, utility panels):** +Defeated with a tubular lock pick — a circular tool that simultaneously manipulates all pins. Cheap, fast, minimal skill required. + +**Electronic/magnetic locks:** +- Proximity cards (HID Prox, iClass): can be cloned with $50 reader/writer +- Magnetic stripe: trivially cloned +- Smart cards with encryption: harder but not impossible +- Biometric: requires different approach (replay attack, fake fingerprint, or bypass the controller rather than the sensor) + +**Impressioning:** +Insert a blank key, apply turning pressure, examine marks left on the blank by the pins, file the blank at mark locations. Repeat until the blank becomes a working key. Time-intensive (30-60 minutes) but produces a working key that can be reused. + +## 3.3 Bypass Tools + +**Over-the-door tool:** A flexible tool that reaches around the door edge to manipulate the interior handle or thumb turn. Works on many commercial doors where the interior handle is unlocked. + +**Latch slipping:** Using a flexible card or shim to push back the spring bolt on a door. Only works on spring bolts (not deadbolts) and doors without strike plate guards. + +**Under-door tool:** A rigid tool slid under the door to pull the interior handle down. Effective on lever-style handles with sufficient gap under the door. + +## 3.4 Countermeasures to Know + +Locks that resist most bypass techniques: +- **Medeco** — Rotating pins, sidebar mechanism. Extremely difficult to pick. +- **Abloy** — Disc detainer mechanism, no springs. Requires specialized tools. +- **Mul-T-Lock** — Pin-within-a-pin design. Doubles the effective pin count. +- **Electronic deadbolts** — No mechanical keyway to attack. + +--- + +# Chapter 4: Social Engineering for Access + +## 4.1 The Fundamental Principle + +People want to be helpful. People defer to authority. People avoid confrontation. Social engineering exploits these tendencies to bypass physical security controls that cannot be bypassed technically. + +A confident person in the right uniform with the right clipboard can walk into almost any building in the world. + +## 4.2 Effective Pretexts + +**IT Technician:** +- Props: Laptop bag, cable tester, badge on lanyard (any badge — people rarely read them) +- Script: "I'm here to check the network drop in [specific room]. We've been getting intermittent connectivity issues on this floor." +- Why it works: IT issues are common, nobody wants to be responsible for blocking the fix, and few people understand IT well enough to question the request. + +**Fire Inspector / Building Inspector:** +- Props: Clipboard, camera, measuring tape, hi-vis vest +- Script: "We're doing the annual fire safety inspection. I need to check the exits and extinguisher placement on this floor." +- Why it works: Inspections are expected and periodic. Building code compliance is everyone's responsibility. Nobody wants to obstruct an inspector. + +**Delivery Driver:** +- Props: Uniform, hand truck, packages (can be empty boxes with printed labels) +- Script: "Delivery for [name from LinkedIn/company directory]. Can you sign?" +- Why it works: Deliveries happen constantly. The recipient's name adds credibility. People sign without thinking. + +**Contractor / Maintenance:** +- Props: Tool bag, hard hat, hi-vis vest, work boots +- Script: "Facilities called us about the [HVAC/plumbing/electrical] issue on the third floor." +- Why it works: Maintenance is constant in commercial buildings. Workers go everywhere. + +**New Employee:** +- Props: Business casual attire, slightly confused expression +- Script: "Hi, I just started in [department]. I think I got turned around — can you show me where [room] is?" +- Why it works: People empathize with being new. They want to help. They'll escort you past security checkpoints. + +## 4.3 Tailgating + +Following an authorized person through a secured door before it closes. The simplest and most effective physical access technique. + +**When it works best:** +- Shift change (many people entering at once) +- Lunch hour (heavy traffic in and out) +- When someone is carrying items (they can't hold the door AND challenge you) +- Loading docks (constant traffic, casual atmosphere) + +**Counter the challenge:** If someone asks "can I see your badge?" — pat your pockets, look frustrated, say "I must have left it at my desk. I'm [name], I work with [department]." Most people will let you through rather than make a scene. If they insist, leave gracefully and try another entry point. + +## 4.4 Authority Exploitation + +People obey authority figures reflexively. This can be exploited by projecting authority through appearance, behavior, and language. + +**Authority indicators:** +- Suit and tie (or appropriate professional attire) +- Confident, purposeful walk +- Giving directions rather than asking for permission +- Name-dropping specific internal contacts +- Using internal jargon and acronyms +- Looking busy and slightly annoyed (important people are always in a hurry) + +**The key insight:** Nobody challenges the person who acts like they belong. Security guards challenge people who look uncertain, who hesitate, who make eye contact and then look away. Walk in like you own the building and most people will assume you do. + +--- + +# Chapter 5: Surreptitious Entry Operations + +## 5.1 Planning + +A surreptitious entry — also known as a "black bag job" — is a covert entry to a target location for intelligence collection without leaving evidence of intrusion. This is the most complex physical access operation and requires thorough planning. + +**Team composition:** +- **Entry specialist** — handles lock bypass and alarm neutralization +- **Inside operator** — conducts the search, photographs documents, plants devices +- **Lookout/communications** — monitors the perimeter, provides early warning +- **Driver** — manages transport, maintains escape vehicle + +Minimum team: 2 (entry + lookout). Optimal: 3-4. + +**Pre-operation requirements:** +1. Complete target assessment (Chapter 2) +2. Guard schedule confirmed through multi-day observation +3. Alarm system identified and bypass method determined +4. Entry point selected and lock bypass method practiced +5. Communication plan established (radios, signals, check-in schedule) +6. Time limit defined (30-60 minutes maximum for most operations) +7. Abort criteria defined (what triggers immediate withdrawal) +8. Escape routes planned (minimum 2 routes from target) + +## 5.2 Execution Procedures + +1. **Pre-entry:** Lookout confirms area is clear. Driver positions escape vehicle. Team approaches via planned route. +2. **Entry:** Bypass lock. Neutralize alarm (if present). Confirm interior is clear. +3. **Document existing state:** Before touching anything, photograph the room. Note the position of objects, papers, doors, drawers. Everything must be returned to its exact original position. +4. **Conduct operation:** Search systematically. Photograph documents in place. If planting a device, select a location that will not be disturbed. +5. **Time checks:** Lookout provides regular time checks. Operations cease at the pre-defined time limit regardless of completion status. +6. **Exit preparation:** Verify everything is returned to original position. Check for evidence of entry (footprints, disturbed dust, moved objects). +7. **Exit:** Re-secure lock. Restore alarm. Depart via planned route. +8. **Post-operation:** Separate departure by team members. Counter-surveillance on departure route. No post-operation communication for defined period. + +## 5.3 Evidence Discipline + +The entire point of surreptitious entry is that the target never knows it happened. This requires fanatical attention to evidence. + +- Wear gloves at all times (latex underneath, nitrile on top — double layer reduces print risk and tearing) +- Wear shoe covers or shoes purchased for this operation only +- Do not eat, drink, smoke, or spit inside the target space (DNA) +- Photograph everything before touching it +- Replace every object in its exact position (use the photographs as reference) +- Check for hair, fibers, or other trace evidence before departing +- If you move furniture or equipment, note its exact position and return it precisely + +--- + +# Chapter 6: Postal & Logistics Operations + +## 6.1 The Postal Channel + +Physical mail remains one of the most effective channels for covert material transfer. It is anonymous (no ID required to mail a package), ubiquitous (billions of packages annually), and relatively uninspected (inspection rates are very low for domestic mail). + +However, postal inspection services have developed profiling criteria to identify suspicious packages. Understanding and avoiding these triggers is essential. + +## 6.2 FBI/USPS Profiling Criteria + +From leaked inspection guidelines (analyzed by the Grugq): + +**Packaging red flags:** +- Heavy taping along seams +- Package reuse (old labels, previous shipping marks) +- Uneven weight distribution +- Poor preparation for mailing + +**Labeling red flags:** +- Handwritten labels (most business mail uses printed labels) +- Misspellings +- Person-to-person (not business-to-individual) +- Return zip code doesn't match the accepting post office zip code +- Fictitious return address +- Sender/recipient names that are obviously generic (John Smith) +- No connection between sender name and return address + +**Content indicators:** +- Weight approximately equal to round metric amounts (1 kg + packaging) +- Express Mail for non-document items (Express Mail is primarily used for business document delivery) +- Origination from known source locations + +## 6.3 Countermeasures (Avoiding Profiling) + +**Packaging:** +- Use new, professional packaging (not reused boxes) +- Minimal, clean taping — enough to secure, not suspicious +- Use appropriate box size for contents (no excessive padding) +- Package should look like normal commercial mail + +**Labeling:** +- Print labels (never handwrite) +- Use a business-to-individual format +- Include a plausible business name as sender +- Return address must be real and verifiable (backstopped) +- Return zip code must match the post office where you mail it +- Recipient name should match someone at the delivery address + +**Backstopping:** +- The return address must correspond to a real location +- The sender name should match someone who could plausibly be at that address +- If checked, the address should not raise immediate flags +- Research the identity — don't invent one. Borrow one. + +As the Grugq notes: "Don't make shit up, do your research and steal an identity with a real address. The complexity and depth of that backstop are dependent on how deeply the cover will be investigated." + +--- + +# Chapter 7: Counter-Forensic Discipline + +## 7.1 Tamper-Evident Awareness + +Many targets employ passive tamper detection — indicators that reveal whether a space has been accessed: + +- **Hair or thread across door crack** — Falls when door is opened. Check before entry. +- **Dust patterns** — Undisturbed dust on surfaces indicates no recent access. Your presence will disturb it. +- **Tamper-evident seals** — Adhesive seals on containers, cabinets, or doors that show signs of removal. +- **Powder traps** — Fine powder on floors or surfaces that captures footprints. +- **Hidden cameras** — Motion-activated cameras in non-obvious locations (clocks, smoke detectors, power outlets). +- **Object positioning** — Items deliberately placed to detect movement (paper at specific angle, pen position on desk). + +## 7.2 Digital Forensic Awareness + +If the operation involves accessing a computer: +- Do NOT boot the target machine (creates forensic artifacts) +- If the machine is already on, do NOT log in without understanding what logging is enabled +- Photograph the screen before touching anything +- Use forensic tools that minimize artifacts (live USB, hardware imager) +- If planting a device, ensure it does not create detectable artifacts in system logs + +--- + +# Chapter 8: Physical Access Checklists + +## 8.1 Social Engineering Checklist + +- [ ] Pretext selected and rehearsed +- [ ] Props acquired (uniform, badge, clipboard, tools as appropriate) +- [ ] Target contact names researched (for name-dropping) +- [ ] Internal jargon researched +- [ ] Entry time selected (shift change, delivery hours, lunch) +- [ ] Backup pretext prepared +- [ ] Exit strategy defined +- [ ] Communications plan established + +## 8.2 Surreptitious Entry Checklist + +- [ ] Target assessment complete (layout, security, schedule) +- [ ] Multi-day observation confirms patterns +- [ ] Entry point selected and bypass method tested +- [ ] Alarm type identified and bypass planned +- [ ] Team briefed and roles assigned +- [ ] Communication equipment tested +- [ ] Gloves, shoe covers, and evidence discipline gear ready +- [ ] Camera for documenting original state +- [ ] Time limit defined (30-60 minutes) +- [ ] Abort criteria defined +- [ ] Primary and secondary escape routes planned +- [ ] Counter-surveillance planned for approach and departure +- [ ] Cover story prepared if intercepted +- [ ] Post-operation communication blackout period defined + +--- + +*This manual is a living document. Content will be enriched as additional sources are collected and analyzed.* diff --git a/output/manuals/06_OPSEC_Principles.md b/output/manuals/06_OPSEC_Principles.md new file mode 100644 index 0000000..3f13215 --- /dev/null +++ b/output/manuals/06_OPSEC_Principles.md @@ -0,0 +1,473 @@ +# OPSEC Principles Manual + +> Synthesized from: Allen Dulles "Some Elements of Intelligence Work," the Grugq's OPSEC analyses +> (Silk Road, Harvard bomb hoax, Morris Worm, PIRA, Reservoir Dogs, Yardbird), JSOU Report 12-3, +> CIA CHECKPOINT travel intelligence +> +> Classification: OPEN SOURCE — compiled from publicly available materials + +--- + +## Table of Contents + +1. OPSEC Fundamentals +2. The Dulles Foundation +3. Compartmentation +4. The Operational Phase Framework +5. Identity & Persona Management +6. Communications Security +7. The STFU Principle +8. Informant Awareness & Counter-Intelligence +9. Case Studies +10. The OPSEC Checklist + +--- + +# Chapter 1: OPSEC Fundamentals + +## 1.1 What OPSEC Is (And What It Isn't) + +OPSEC is not a tool. It is not encryption software. It is not Tor. It is not a VPN. It is not a burner phone. + +**OPSEC is a mode of operating.** + +This distinction matters because people who think OPSEC is a tool believe they can install it, configure it, and forget it. They are wrong. They will be caught. + +OPSEC is the continuous discipline of minimizing the information available to your adversary about your identity, intentions, capabilities, and activities. It encompasses every decision you make — what you say, where you go, what you buy, who you associate with, what devices you use, what patterns you create. + +As the Grugq writes: "OPSEC is a mode of operating, not a tool or a collection of tools." And: "It is more important to compartment sensitive activities and structure your operational environment for impact containment than to install particular software." + +## 1.2 The OPSEC Tradeoff + +High OPSEC means low efficiency. High efficiency means weak OPSEC. There is no way around this tradeoff. Every security measure adds friction — latency in communications, complexity in logistics, constraints on behavior. The question is never "how much OPSEC do I need?" but rather "how strong is my adversary?" + +The strength of opposing forces dictates minimum security requirements. Operating against a corporate security team requires different OPSEC than operating against a nation-state intelligence service. Calibrate accordingly, but when in doubt, overestimate the adversary. + +## 1.3 The Practice Imperative + +"Amateurs practice until they get it right. Professionals practice until they can't get it wrong." + +OPSEC routines must be automatic. Under stress, you will not rise to the level of your aspirations — you will fall to the level of your training. If you have never practiced an SDR, you will not execute one properly when you actually need it. If you have never used a dead drop, your first attempt under operational pressure will be clumsy and observable. + +The Dulles corollary: "The man or woman who does not indulge in the daily security routine, boring and useless though it may sometimes appear, will be found lacking in the proper instinctive reaction when dealing with the bigger stuff." + +Practice your security routines during peacetime. Make them habitual. When the moment comes, habit will save you where conscious thought cannot. + +--- + +# Chapter 2: The Dulles Foundation + +Allen Dulles distilled a career of intelligence work into a set of principles that have not been improved upon in seventy years. They are presented here not as historical curiosities but as operational fundamentals. + +## 2.1 Security Above All + +"The greatest of them all is security. All else must be subordinated to that." + +This is the meta-rule. Every other principle derives from this one. When in conflict between security and any other objective — speed, convenience, thoroughness, ego — security wins. Always. + +## 2.2 Security Lives in the Details + +"The little things are in many ways more important than the big ones. It is they which oftenest give the game away." + +You are more likely to be compromised by a careless phone call than by a broken cipher. You are more likely to be identified by a receipt in your pocket than by a failed dead drop. The big operational decisions get careful thought. The small daily habits are where discipline breaks down. + +Specific Dulles directives: +- Never leave things unattended or where you might forget them +- Learn to write lightly — the blank page underneath has been read +- Destroy documents thoroughly, not casually +- Carry as little written material as possible, for the shortest possible time +- Never carry names or addresses in clear text — use a personal code only you understand +- If you must clip small papers to larger ones, do so — loose papers get lost + +## 2.3 Never Admit + +"Even though you feel the curious outsider has probably a good idea that you are not what you purport to be, never admit it. Keep on playing the other part." + +People doubt their own suspicions. If you maintain your cover consistently, observers will often convince themselves they were wrong. But the moment you admit — even partially, even indirectly — the game is over. No half-admissions. No "well, I'm a little involved in that." Nothing. + +## 2.4 Vanity Is the Enemy + +"The next greatest vice is that of vanity. Its offshoots are multiple and malignant." + +The need to be recognized, to show how clever you are, to hint at your secret life — this is the operational equivalent of painting a target on your chest. The Provisional IRA lost members because they boasted in pubs. Ross Ulbricht lost Silk Road because he needed social validation on forums. Robert Morris lost his freedom because he couldn't resist explaining his worm to friends. + +The best operative is the one nobody suspects. If you need external validation for your work, find a different profession. + +## 2.5 The Telephone Problem + +"The greatest material curse to the profession is undoubtedly the telephone." + +Written in the 1950s, this warning has only become more relevant. Modern phones are tracking devices that record your location, contacts, timing, metadata, and potentially content. The telephone is not merely a temptation to slackness — it is an active surveillance device you carry voluntarily. + +Dulles's rule: "Always act on the principle that every conversation is listened to." This was prudent caution in 1955. In 2025, it is a documented fact. + +Modern application: See Chapter 6 (Communications Security) for detailed phone OPSEC procedures. + +## 2.6 Carelessness Is Irreversible + +"Mistakes made generally cannot be rectified." + +In most professions, a mistake is a learning experience. In operational security, a mistake is a compromise. You cannot un-send the email that contained your real name. You cannot un-visit the location that linked your cover to your identity. You cannot un-say the words that confirmed a suspicion. + +Think before you act. Then think again. Then act. + +--- + +# Chapter 3: Compartmentation + +## 3.1 The Principle + +Compartmentation is the separation of information, people, and activities into discrete cells with no interaction, access, or knowledge of each other. It is the cornerstone of any solid counter-intelligence program. + +If any single compartment is compromised — by informant, surveillance, or technical penetration — the damage stops at the compartment boundary. Without compartmentation, a single compromise cascades through the entire operation. + +## 3.2 Types of Compartmentation + +**Organizational compartmentation:** Structuring a group so that cells are isolated from each other. Members of Cell A know only Cell A's members and have contact with one liaison in Cell B. That is the limit of their knowledge. + +**Functional compartmentation:** Separating activities so that each function (surveillance, logistics, execution, communications) is performed by a different team with no cross-visibility. + +**Temporal compartmentation:** Regularly changing communications platforms, identities, and infrastructure to create chronological silos. Old identities and channels are abandoned. Compromise of a current compartment cannot reach into past compartments. + +**Personal compartmentation:** Separating your own illicit activity from your regular life. This is what CIA case officers do — they compartment their espionage from their cover life. The first rule: never discuss your illicit activities with anyone outside the compartment. + +## 3.3 Compartmentation for Individuals + +The Grugq provides a practical framework for personal compartmentation: + +**The threat model:** Two people (Alice and Bob) want to exchange information. They need to protect against an adversary learning: +1. That two people have been in contact (low risk) +2. That Bob has been in contact with someone (medium risk) +3. That Alice has been in contact with someone (high risk) +4. That Alice has been in contact with Bob (extreme risk) + +Each risk level requires different countermeasures. Protecting against (1) requires hiding the existence of communication. Protecting against (4) requires complete persona separation. + +**Practical implementation:** +- Separate devices for separate compartments (never use the same laptop for personal and operational activity) +- Separate locations for separate compartments (never conduct operational communications from home) +- Separate identities for separate compartments (no shared usernames, emails, or behavioral patterns) +- Never cross-contaminate between compartments +- If a compartment is compromised, the others survive + +## 3.4 The Cost of Poor Compartmentation + +Ross Ulbricht ran the Silk Road marketplace for over two years. He was caught because his operational persona (Dread Pirate Roberts) and his personal identity (Ross Ulbricht) shared: +- Ideology (Austrian School of Economics, mises.org) +- Geographic location (San Francisco) +- Timezone (evident in posting patterns) +- Technical interests (PHP, Bitcoin security) +- An email address (posted from the "altoid" operational persona on BitcoinTalk) +- Server access location (frosty@frosty.com admin accessed Silk Road server from 500 feet from Ulbricht's Gmail login location) + +Any ONE of these links might not have been sufficient. Together, they were damning. Compartmentation must be total or it is meaningless. + +--- + +# Chapter 4: The Operational Phase Framework + +## 4.1 The Five Phases + +Every operation — cyber or physical, offensive or defensive — moves through five distinct phases: + +1. **Target Selection** — Choosing what to attack/collect/influence +2. **Planning & Surveillance** — Gathering information, developing the plan +3. **Deployment** — Moving into position, preparing infrastructure +4. **Execution** — Conducting the operation +5. **Escape & Evasion** — Getting away clean + +Most failures happen because phases 4 and 5 receive less attention than phases 1-3. The Grugq notes that "all real criminals know that the most important part of an operation is the getaway." Hackers and amateur operatives routinely neglect the escape phase. + +## 4.2 Phase Analysis + +**Target Selection:** This is where strategy meets intelligence. Poor target selection wastes resources and creates unnecessary exposure. Security forces prioritize identifying people involved in target selection and planning — they are the principals, more valuable than the people who execute. + +**Planning & Surveillance:** The phase where most intelligence collection occurs. Pattern of life analysis, vulnerability assessment, route planning. Also the phase where pre-operational contact creates the most risk. Every meeting, every communication, every reconnaissance visit creates a potential link. + +**Deployment:** Moving from planning to readiness. Infrastructure is activated, teams are positioned, logistics are finalized. This is the point of commitment — once deployment begins, the operation is live. + +**Execution:** The operation itself. Duration should be minimized. The longer you are exposed, the greater the risk. Execute the plan, don't improvise unless the plan fails. + +**Escape & Evasion:** The most neglected and most critical phase. How do you leave the scene? How do you dispose of evidence? How do you break the link between yourself and the operation? How do you return to normal life without anomalous behavior? + +## 4.3 The Harvard Bomb Hoax — Phase Failure Analysis + +In December 2013, Harvard student Eldo Kim sent bomb threats to avoid a final exam. His operational analysis through the phase framework: + +**Target Selection:** Correct — buildings where his exam was held. +**Planning:** Minimal — chose Tor Browser Bundle and GuerillaMail. +**Deployment:** Fatal error — used Tor from the Harvard campus network. +**Execution:** Succeeded — emails were sent. +**Escape & Evasion:** Non-existent — no plan for what happens after. + +The deployment error was decisive. Using Tor from the campus network reduced the anonymity set from "anyone on the internet" to "Harvard students using Tor at the time the bomb threats were sent." That was a very small number. He was identified within hours. + +The lesson: **Never take an action that reduces the pool of suspects.** If all students are suspects, you only need to avoid narrowing the pool. Using an anonymizing tool from a specific location during a specific time window does exactly the opposite. + +--- + +# Chapter 5: Identity & Persona Management + +## 5.1 The Contamination Problem + +Contamination occurs when information from one persona leaks into another. It is the most common cause of identity compromise, and it is almost always caused by convenience or carelessness, not by technical failure. + +**Types of contamination:** +- **Direct link:** Using a personal email from an operational account (Ulbricht) +- **Behavioral link:** Both personas share ideology, writing style, or interests (DPR/Ulbricht) +- **Geographic link:** Accessing both personas from the same location (Ulbricht) +- **Temporal link:** Both personas are active at the same times, inactive at the same times +- **Technical link:** Same device, same browser fingerprint, same IP, same VPN exit node + +## 5.2 Persona Separation Rules + +1. **Separate devices.** Never use the same physical device for different personas. If this is impossible, use separate VMs with separate network paths. +2. **Separate locations.** Never access different personas from the same physical location. This includes WiFi networks — your home WiFi MAC address is unique. +3. **Separate behaviors.** Different personas should have different writing styles, different interests, different posting schedules, different political views. +4. **Separate infrastructure.** Different email providers, different VPNs, different cryptocurrency wallets, different SIM cards. +5. **Never cross-contaminate.** Never copy-paste between persona environments. Never visit a personal site from an operational browser. Never use operational tools from a personal device. + +## 5.3 Isolation and Its Dangers + +Underground operatives face a severe psychological challenge: isolation. The security requirements of deep cover preclude normal social interaction. Ulbricht's case illustrates what happens: + +- He rented a room under an assumed name +- He had no "mainstream" social circle to calibrate against +- His only social interaction was with Silk Road forum members and admins +- Social isolation drove him toward ideological extremism +- Isolation degraded his security discipline over time + +**Mitigation:** Maintain a cover social life that provides genuine human connection. Have non-operational friends. Exercise. Maintain routines that keep you grounded in normal reality. The underground life, sustained too long in isolation, produces bad judgment. + +--- + +# Chapter 6: Communications Security + +## 6.1 The Four Goals + +Secure communications must achieve four objectives, in ascending order of difficulty: + +1. **Content protection** — Make the message unreadable to unauthorized parties. Solved by encryption. +2. **Meaning protection** — Make the message's significance inaccessible even if the text is readable. Addressed by codes. +3. **Traffic analysis resistance** — Prevent the adversary from knowing that a connection exists between the communicating parties. Very difficult. +4. **Channel concealment** — Prevent the adversary from knowing that the communication channel exists at all. Extremely difficult. + +Most people stop at goal 1. Encryption is the easy part. Goals 3 and 4 are where operations succeed or fail. + +## 6.2 Metadata Kills + +The content of your message matters less than the fact that you sent it. Modern intelligence services collect metadata — who communicated with whom, when, for how long, from where — at massive scale. Metadata reveals: +- Organizational structure (who talks to whom) +- Operational tempo (communication frequency increases before operations) +- Geographic patterns (where calls originate) +- Relationships (contact frequency indicates relationship strength) + +**Encryption protects content. It does not protect metadata.** The CIA Lebanon rollup demonstrates this: Hezbollah identified CIA agents not by breaking encryption but by identifying phones that were used exclusively for handler communication. The pattern — dedicated device, static location, predictable activation schedule — was the vulnerability. + +## 6.3 The Telephone Rules (Modern Application) + +Dulles warned about the telephone in the 1950s. The Grugq updated these warnings for the mobile era: + +**Physical identifiers:** +- IMEI — unique hardware identifier for the phone device itself +- IMSI — unique subscriber identifier on the SIM card +- Both must be changed together to break the link + +**Location tracking:** +- 4 location data points will uniquely identify 90% of mobile phone users +- Your mobility pattern (home → commute → work → gym) is as unique as a fingerprint +- "Mirroring" — when two devices travel together — links them permanently + +**Burner phone rules:** +1. Phone OFF means battery removed, SIM removed, placed in shielded bag +2. Never power on at locations associated with you — home, work, friends +3. Never turn on your burner at the same location as your personal phone +4. Never let your personal phone go OFF when your burner goes ON (paired events are indicators of relation) +5. Never carry phones for different compartments together +6. Store the burner away from your home +7. Keep your personal phone showing normal usage pattern at all times +8. Buy with cash, never register, discard after limited use + +## 6.4 Codes vs. Encryption + +Codes protect meaning. Encryption protects content. They serve different purposes. + +The US Army COMSEC handbook warns against "talking around" — trying to discuss sensitive subjects using circumlocution. "Self-made reference systems" rarely work because "few people are clever enough to refer to an item of information without actually revealing names, subjects, or other pertinent information." + +**Practical code discipline:** +- Keep codes generic and consistent +- Limit codes to simple signaling (go/no-go, danger/safe, meeting confirmed/canceled) +- Do not attempt to discuss complex operational details via code +- Pre-arrange all codes before the operation begins +- Use different code systems for different compartments + +--- + +# Chapter 7: The STFU Principle + +## 7.1 The Rule + +If someone is not actively sharing the risk of an operation, they have no need to know about it. Period. + +This is the single most violated principle in operational security. People talk. They talk because they are proud, because they are scared, because they are drunk, because they want to impress someone, because they need to process what they've experienced. Every word spoken to someone outside the operation is a potential compromise. + +## 7.2 The Morris Worm — Case Study in Talking + +Robert Morris created the first major internet worm in 1988. He was brilliant. He was also incapable of keeping quiet. + +Morris briefed his friends on all aspects of the worm: how it was developed, how it worked, what vulnerabilities it exploited. At one meeting at a Legal Seafood restaurant, he was so excited that "he literally jumped up on a table pacing back and forth on the table explaining how it worked." + +His friends were subpoenaed. They testified. Morris was convicted. + +His lawyer later reflected: "He did testify that he wrote the worm. He came in and testified, 'I did it, and I'm sorry.' I turned to my co-counsel and asked, 'Should I prove he didn't do it or he's not sorry?'" + +## 7.3 Need-to-Know Evaluation + +Before sharing any operational information, ask: +1. Is this person actively sharing the risk of this operation? +2. Do they need this specific piece of information to perform their role? +3. Will withholding this information degrade their ability to function? + +If the answer to any of these questions is no, do not share. Even within the operation, restrict knowledge to the specific aspects each person needs. The team driver does not need to know the exfiltration plan. The lookout does not need to know the target's name. + +--- + +# Chapter 8: Informant Awareness + +## 8.1 The Oldest Threat + +Technical surveillance can be defeated with tradecraft. Cryptography can protect communications. Compartmentation can contain damage. But none of these measures protect against an informant — a member of your own organization who reports to the adversary. + +When a group with robust security practices is compromised and the technical indicators don't explain how, the answer is almost always an informant. + +## 8.2 The PIRA Lesson + +The Provisional IRA in the 1970s demonstrated every form of self-incrimination possible: +- Singing IRA songs in pubs (public affiliation) +- Boasting about operations while drunk (direct disclosure) +- Responding to inquiries with "a nod and a wink" (confirmation) +- Attending pro-IRA rallies (surveillance opportunity) +- Socializing with operational colleagues off-duty (pre-operational contact) + +British security forces exploited this systematically. Known members (identified through public behavior) were monitored. Their social contacts were mapped. Unknown members were identified through association. The entire organizational graph was eventually exposed through link analysis starting from a handful of pub boasters. + +**The lesson is simple:** Never publicly display operational affiliation. Never socialize with operational contacts in personal contexts. Never discuss operations outside of operational necessity. Alcohol is a vulnerability, not a social lubricant. + +## 8.3 Detection Indicators + +Signs that an organization may have been penetrated: +- Opposition demonstrates knowledge of operations that should be compartmented +- Arrests or disruptions that don't match the opposition's known technical capabilities +- Indictments with unusually specific geographic information about members +- Operations fail in ways that suggest foreknowledge +- "Lucky" coincidences that benefit the opposition repeatedly + +The Grugq's analysis of the Lauri Love hacking case: "The lack of information on how Mr Love was caught, along with the revelation of good security practices suggests one thing: informant." + +## 8.4 Anti-Informant Measures + +From the Reservoir Dogs SOP (Fatah/BSO methodology): +1. **Assigned aliases** — Random, per-operation, prevents pattern development +2. **Just-in-time assembly** — Form team immediately before operation +3. **Dedicated support teams** — Each function compartmented +4. **Strict need-to-know** — No one knows the complete plan except the principal +5. **Post-operation dispersal** — Team disbanded, infrastructure destroyed + +These measures limit the damage an informant can cause but do not prevent infiltration. The only true defense against informants is rigorous vetting and the acceptance that some level of penetration risk is inherent in any organization with human members. + +--- + +# Chapter 9: Case Studies + +## 9.1 Silk Road — The Complete Failure + +**Timeline:** 2011-2013 +**Actor:** Ross Ulbricht (Dread Pirate Roberts) +**Outcome:** Arrested, convicted, life sentence + +**What went right:** +- Tor hidden service for the marketplace +- Bitcoin for financial transactions +- Pseudonymous identity (DPR) + +**What went wrong (everything else):** +1. Used personal email from operational persona (altoid → rossulbricht@gmail.com) +2. Shared ideology between personas (Austrian economics on both accounts) +3. Same geographic location (San Francisco) and timezone +4. Server admin access from same physical location as personal Gmail +5. Social isolation drove extremism and poor judgment +6. Sought social validation on forums, lowering security discipline +7. No backstopping of operational personas +8. Used same computer for personal and operational activity + +**Key lesson:** Compartmentation is binary. It either exists or it doesn't. A single contamination link between personas makes all other security measures irrelevant. + +## 9.2 Harvard Bomb Hoax — Anonymity Set Reduction + +**Timeline:** December 2013 +**Actor:** Eldo Kim (Harvard student) +**Outcome:** Identified within hours + +**The operation:** Send bomb threats to cancel a final exam. +**The method:** Tor Browser Bundle + GuerillaMail from Harvard campus. +**The failure:** Using Tor from the campus network reduced the suspect pool to Harvard Tor users during the threat window — a very small number. + +**Key lesson:** Anonymity tools provide anonymity only within the set of users at that location and time. Smaller the set, less the anonymity. He should have used a nearby cafe with no connection to the university. + +## 9.3 CIA Lebanon — Phone Pattern Analysis + +**Timeline:** 2011 +**Actor:** CIA spy network +**Adversary:** Hezbollah counter-intelligence +**Outcome:** Entire network rolled up + +**The tradecraft:** Agents used dedicated mobile phones for handler communication. Phones kept at static locations. Pre-arranged meeting at fixed location. + +**The failure:** Hezbollah identified the pattern — dedicated devices that activated only for specific contacts, from specific locations, at predictable intervals. The pattern, not the content, was the vulnerability. + +**Key lesson:** Encryption protects content. Anonymity protects identity. Systems based on secrecy alone — where usage itself is anomalous — attract attention and enable pattern analysis. Anonymity must come before encryption. + +--- + +# Chapter 10: The OPSEC Checklist + +## 10.1 Pre-Operation + +- [ ] Threat model defined (who is the adversary, what are their capabilities?) +- [ ] OPSEC level calibrated to adversary strength +- [ ] Operational compartmentation established +- [ ] Separate devices for separate compartments +- [ ] Separate identities with no cross-contamination +- [ ] Communication plan established (methods, schedules, emergency protocols) +- [ ] Cover story developed and backstopped (if applicable) +- [ ] Need-to-know enforced for all participants +- [ ] SDR procedures planned (if physical component) +- [ ] Escape and evasion plan developed +- [ ] Evidence disposal plan developed +- [ ] Emergency abort criteria defined + +## 10.2 During Operation + +- [ ] SDR executed before any operational activity +- [ ] Cover maintained at all times +- [ ] Communications limited to operational necessity +- [ ] No unnecessary logs or records created +- [ ] Devices used only for designated compartment +- [ ] No pre-operational contact with team members outside operational context +- [ ] Counter-surveillance awareness maintained +- [ ] Anomalies noted and assessed + +## 10.3 Post-Operation + +- [ ] Operational infrastructure sanitized or destroyed +- [ ] Temporary identities retired +- [ ] Devices wiped or physically destroyed +- [ ] No post-operational contact with team members +- [ ] No discussion of operation with anyone outside need-to-know +- [ ] Return to normal behavioral patterns without anomalies +- [ ] After-action review conducted (lessons learned, security assessment) +- [ ] STFU + +--- + +*This manual is a living document. Content will be enriched as additional sources are collected and analyzed.* diff --git a/output/manuals/07_Cyber_Implants_Tools.md b/output/manuals/07_Cyber_Implants_Tools.md new file mode 100644 index 0000000..9fcdb32 --- /dev/null +++ b/output/manuals/07_Cyber_Implants_Tools.md @@ -0,0 +1,391 @@ +# Cyber Implants & Tools Manual + +> Synthesized from: WikiLeaks Vault 7 (CIA Hacking Tools), Vault 8 (CIA Source Code), +> CIA Engineering Development Group documentation, classified tool user guides and design documents +> +> Classification: Source material is SECRET//NOFORN (leaked). This synthesis is for +> educational/red team reference purposes. + +--- + +## Table of Contents + +1. Overview — CIA Cyber Arsenal +2. Implants & Backdoors +3. Persistence Frameworks +4. Network Device Exploitation +5. Air-Gap Operations +6. Credential Theft +7. Collection Tools +8. Support & Evasion Tools +9. False Flag Operations (Umbrage) +10. Operational Patterns & Detection + +--- + +# Chapter 1: Overview — CIA Cyber Arsenal + +## 1.1 The Engineering Development Group + +The majority of Vault 7 tools were developed by the CIA's Engineering Development Group (EDG), a unit within the Directorate of Digital Innovation. EDG functions as the CIA's internal offensive tool development shop — the equivalent of NSA's TAO (Tailored Access Operations) but focused on human-deployed tools rather than network-based exploitation. + +Tools are classified SECRET//NOFORN and follow a formal development lifecycle with requirements documents, user guides, test plans, Independent Verification & Validation Review (IVVRR) checklists, and Tool Delivery Reviews (TDR). This bureaucratic rigor means the tools are well-documented — and that documentation is now public. + +## 1.2 Tool Design Philosophy + +Analyzing the Vault 7 tools reveals consistent design patterns: + +**Platform coverage:** Windows is the primary target (Athena, Angelfire, AfterMidnight, Pandemic, Dumbo, EzCheese, Brutal Kangaroo). Linux has dedicated tools (OutlawCountry, Aeris, Gyrfalcon). macOS has limited coverage (Achilles). Mobile platforms have specialized tools (HighRise for Android). Network devices are targeted with firmware implants (CherryBlossom). + +**Persistence over capability:** Most tools prioritize survival — staying on the target system undetected — over offensive capability. The persistence mechanisms are sophisticated (boot sector modification, DLL hijacking, kernel modules, covert filesystems). The actual collection/exfiltration capabilities are often straightforward once persistence is achieved. + +**Modularity:** Tools like AfterMidnight use a modular architecture where the persistence mechanism (the "platform") is separate from the capability modules ("Gremlins"). This allows operators to deploy the platform once and load/unload capabilities as needed without re-deploying the implant. + +**Minimal footprint:** Tools are designed to minimize their forensic footprint. BadMFS creates a covert filesystem invisible to the OS. Marble obfuscates strings to defeat forensic analysis. Dumbo disables recording devices during physical access operations. + +--- + +# Chapter 2: Implants & Backdoors + +## 2.1 Athena (Windows) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG + Siege Technologies (contractor) +**Platforms:** Windows 7, 8, 10 +**MITRE ATT&CK:** T1574.001 (DLL Search Order Hijacking), T1543.003 (Windows Service) + +**What it is:** A beacon-loader implant that runs in user space and communicates from within the srvhost process. At its core, Athena is deceptively simple — it hijacks a system DLL, loads into a legitimate service process, and beacons to a command-and-control server. + +**Two variants:** + +**Athena-Alpha** targets the RemoteAccess service. This service enumerates the registry to find an IP support DLL called `iprtrmgr.dll`. The implant replaces this DLL and forwards all original export functions to the legitimate module. When the service starts, the implant loads alongside it. By default, the RemoteAccess service is disabled — the installer enables it. + +**Athena-Bravo** targets the Dnscache service. This service looks for a support DLL called `dnsext.dll`. This extension is available on Windows 7 and 8 (not legacy OS). By default, this service is active, making Bravo less conspicuous than Alpha (no need to enable a disabled service). + +**Persistence mechanism — DLL Forwarding:** +The target DLLs export a small number of functions. The implant DLL forwards those function calls to the original DLL at startup time. The service continues to function normally while the implant runs in the background. This is invisible to the user and to most security software because the service behaves exactly as expected. + +**Key technical detail:** After installation, the srvhost process must be updated to allow the implanted service to run as SYSTEM. The installer modifies the srvhost list to include the service in a SYSTEM srvhost with correct privileges. Until a reboot, the tool has limited security access. + +**Detection indicators:** +- Unexpected `iprtrmgr.dll` or `dnsext.dll` in system directories with non-Microsoft signatures +- RemoteAccess service enabled on systems where it should be disabled +- Modified srvhost service grouping +- Beacon traffic from srvhost process to unknown external IPs +- DLL forwarding chains (imports that redirect to other DLLs) + +## 2.2 Pandemic (Windows) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Version:** 1.1 (January 2015) +**Platforms:** Windows (SMB file servers) +**MITRE ATT&CK:** T1080 (Taint Shared Content), T1221 (Template Injection) + +**What it is:** A file system minifilter driver that replaces files on-the-fly as remote users access them via SMB. When a target system running Pandemic serves files to a remote client, the files are replaced with trojanized versions during transit. The original files on disk are never modified. + +**How it works:** Pandemic installs as a Windows filesystem minifilter driver — the same type of driver used by antivirus software to intercept file operations. When a remote user requests a file via SMB, the minifilter intercepts the read operation and substitutes a different file. The original file remains untouched on disk. Only the remote user receives the modified version. + +**Operational significance:** This is a lateral movement and distribution tool. A single Pandemic installation on a file server can distribute trojanized software to every user who accesses that server. The infection spreads as users execute the files they download. + +**Detection indicators:** +- Unexpected minifilter driver registered in the filter manager stack +- Files served via SMB that differ from their on-disk copies (compare network capture vs disk forensics) +- Minifilter driver with no corresponding legitimate software installation + +## 2.3 OutlawCountry (Linux) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Version:** 1.0 (June 2015) +**Platforms:** Linux (CentOS 6.x, 64-bit with kernel 2.6.32) +**MITRE ATT&CK:** T1014 (Rootkit), T1599 (Network Boundary Bridging) + +**What it is:** A Linux kernel module that provides covert netfilter-based internet traffic redirection. Once loaded, it creates hidden iptables rules that are invisible to user-space tools (`iptables -L` does not show them). This allows the operator to redirect network traffic through controlled infrastructure without the system administrator's knowledge. + +**How it works:** OutlawCountry loads as a standard kernel module but creates a hidden netfilter table that is not visible through normal iptables interfaces. The operator can add rules to this hidden table to redirect outbound traffic (DNS, HTTP, HTTPS) to CIA-controlled servers for interception or modification. + +**Operational significance:** This is a persistent network interception tool. On a Linux server that routes traffic for an organization, OutlawCountry can silently redirect all traffic through CIA infrastructure. + +**Detection indicators:** +- Unexpected kernel modules loaded (`lsmod`, `/proc/modules`) +- Netfilter tables that don't match the visible iptables configuration +- Network traffic taking unexpected routes (traceroute anomalies) +- Kernel module files in unexpected locations + +## 2.4 Aeris (POSIX) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Linux, Solaris, FreeBSD, and other POSIX-compliant systems +**MITRE ATT&CK:** T1071.001 (Web Protocols), T1573.002 (Asymmetric Cryptography) + +**What it is:** A POSIX-compatible implant written in C. Supports automated file exfiltration, configurable beacon intervals, and TLS-encrypted communications with the C2 server. + +**Operational significance:** Aeris is the CIA's general-purpose implant for Unix-like systems. Where Athena targets Windows, Aeris provides equivalent capability across the POSIX ecosystem. Its portability across Linux, Solaris, and BSD makes it suitable for targeting servers, networking equipment running Unix-like OS, and embedded systems. + +## 2.5 AfterMidnight (Windows) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1574.001 (DLL Hijacking), T1129 (Shared Modules) + +**What it is:** A modular Windows implant framework. The base implant masquerades as a Windows DLL, self-persists, and supports dynamically loaded payload modules called "Gremlins." + +**Architecture:** AfterMidnight is a two-component system: +1. **The platform** — A persistent DLL that loads at boot and provides a framework for loading, executing, and unloading Gremlins +2. **Gremlins** — Payload modules that provide specific capabilities (keylogging, screen capture, file exfiltration, etc.) + +**Operational significance:** The modular design means the platform is deployed once. Capabilities are added and removed as needed without re-deploying the implant. AlphaGremlin is the task scheduling component that manages when and how Gremlins execute. + +--- + +# Chapter 3: Persistence Frameworks + +## 3.1 Angelfire / Wolfcreek (Windows) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1542.003 (Bootkit), T1014 (Rootkit), T1564.005 (Hidden File System) + +**What it is:** A five-component Windows persistence framework that modifies the boot process to load implants before the OS fully initializes. + +**The five components:** + +1. **Solartime** — Modifies the partition boot sector to load Wolfcreek during the Windows boot process. This executes before the OS kernel is fully loaded, giving the implant a privileged position. + +2. **Wolfcreek** — A kernel-mode driver loaded by Solartime. Provides a platform for loading additional user-mode implants. Operates at the kernel level, making it invisible to user-space security tools. + +3. **Keystone** — The user-mode component loaded by Wolfcreek. Provides the interface between the kernel-mode persistence mechanism and the operational payloads. + +4. **BadMFS** — A covert file system. Creates a hidden storage partition that is invisible to the operating system. Used to store implant components, configuration data, and exfiltrated material where forensic tools cannot easily find them. + +5. **Windows Transitory File System** — A component for loading file-based implants without leaving artifacts on the standard file system. + +**Operational significance:** Angelfire represents the most sophisticated persistence mechanism in the Vault 7 collection. By modifying the boot sector and loading before the OS, it bypasses all OS-level security controls. The covert filesystem (BadMFS) ensures that even if the OS is forensically imaged, the implant storage is not visible through standard analysis. + +**Detection indicators:** +- Modified partition boot sector (compare against known-good boot sector hashes) +- Unexpected kernel drivers loaded early in the boot sequence +- Disk sectors containing data that don't correspond to any visible filesystem +- Anomalous disk I/O to sectors not mapped to any partition + +--- + +# Chapter 4: Network Device Exploitation + +## 4.1 CherryBlossom (Wireless Routers) + +**Classification:** SECRET//NOFORN +**Developer:** CIA + SRI International (contractor) +**Platforms:** Wireless routers and access points (multiple vendors) +**MITRE ATT&CK:** T1557 (Adversary-in-the-Middle), T1200 (Hardware Additions) + +**What it is:** A framework for exploiting wireless networking devices (routers, access points). CherryBlossom replaces the router's firmware with an implanted version that provides persistent access to all network traffic flowing through the device. + +**Architecture:** + +- **Flytrap** — The implanted firmware installed on the target router. Replaces the stock firmware while maintaining normal router functionality. Beacons to the CherryTree server. +- **CherryTree** — The command-and-control server that manages Flytrap implants. Receives beacons, issues tasking, and collects intercepted data. +- **CherryWeb** — A browser-based interface for operators to manage implanted devices through the CherryTree server. +- **Mission** — The tasking system that defines what data to collect from the target network. + +**Test infrastructure (from leaked documents):** +The CherryBlossom test environment used IPs in the 10.6.6.0/24 and 10.6.7.0/24 ranges with VPN tunnels between components. Components included: Mobile VPN server, Flytrap (implanted router), CherryTree server, Beacon, Mission, Snoball, and ICON. + +**Operational significance:** Compromising a router gives access to ALL traffic on that network without touching any endpoint. This is a network-level implant that is invisible to endpoint security tools. The target organization's computers, phones, and IoT devices are all monitored through their own infrastructure. + +--- + +# Chapter 5: Air-Gap Operations + +## 5.1 Brutal Kangaroo / Drifting Deadline + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Version:** 1.2 (February 2016) +**Platforms:** Windows, USB removable media +**MITRE ATT&CK:** T1091 (Replication Through Removable Media), T1052.001 (Exfiltration Over USB) + +**What it is:** A toolsuite for penetrating air-gapped networks using infected USB drives as the bridge. Drifting Deadline is the primary component that creates a covert data exfiltration channel across the air gap. + +**How it works:** The attack chain: +1. Infect a USB drive that will be used by someone with access to the air-gapped network +2. When the USB is inserted into a computer on the air-gapped network, the implant executes +3. The implant surveys the air-gapped network and collects target data +4. Collected data is staged on the USB drive in a covert partition +5. When the USB is returned to an internet-connected computer, the data is exfiltrated + +**Operational significance:** Air-gapped networks are considered the gold standard of network security — physically disconnected from the internet. Brutal Kangaroo demonstrates that air gaps can be bridged through the human element: people who move USB drives between connected and disconnected networks. + +## 5.2 EzCheese (Removable Media Exploitation) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1091 (Replication Through Removable Media), T1203 (Exploitation for Client Execution) + +**What it is:** An exploitation tool that triggers when Windows Explorer displays the folder contents of an infected removable drive. The exploit fires automatically when the user browses to the drive — no file execution required. + +**Operational significance:** EzCheese lowers the bar for USB-based infection. The target doesn't need to run a file — merely opening the drive in Explorer is sufficient. This makes USB-based attacks more reliable and harder to defend against through user education ("don't run unknown executables" doesn't help when browsing a folder is enough). + +--- + +# Chapter 6: Credential Theft + +## 6.1 BothanSpy (Windows SSH) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows (targets Xshell SSH client) +**MITRE ATT&CK:** T1056.001 (Keylogging), T1555 (Credentials from Password Stores) + +**What it is:** A credential harvesting tool that targets the Xshell SSH client on Windows. BothanSpy steals usernames, passwords, and SSH session content from active sessions. + +**Operational significance:** SSH credentials provide access to remote servers, often in privileged contexts. A single compromised SSH session can provide access to entire server farms, especially if key-based authentication is used with shared keys. + +## 6.2 Gyrfalcon (Linux SSH) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Linux (targets OpenSSH client) +**MITRE ATT&CK:** T1056.001 (Keylogging), T1555 (Credentials from Password Stores) + +**What it is:** The Linux counterpart to BothanSpy. Gyrfalcon captures usernames, passwords, and full session content from OpenSSH client sessions on Linux. + +**Together:** BothanSpy (Windows) + Gyrfalcon (Linux) give the CIA coverage of SSH credential theft across both major desktop platforms. + +--- + +# Chapter 7: Collection Tools + +## 7.1 ExpressLane (Biometric Collection) + +**Classification:** SECRET//NOFORN +**Developer:** CIA OTS (Office of Technical Service) +**Platforms:** Windows (biometric collection systems) +**MITRE ATT&CK:** T1005 (Data from Local System), T1036 (Masquerading) + +**What it is:** A covert biometric data collection tool disguised as a software update for OEM liaison biometric systems. When the CIA provides biometric collection equipment to liaison services (foreign intelligence partners), ExpressLane is installed alongside it. During "software updates," ExpressLane exfiltrates the biometric data the liaison service has collected. + +**Operational significance:** This reveals that the CIA backdoors equipment it provides to allied intelligence services. The "updates" are a pretext for data theft from partners. This has significant implications for international intelligence cooperation trust. + +## 7.2 CouchPotato (Video Capture) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1125 (Video Capture), T1557 (Adversary-in-the-Middle) + +**What it is:** A remote tool for capturing RTSP/H.264 video streams from IP cameras and surveillance systems. + +## 7.3 ELSA (WiFi Geolocation) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1614 (System Location Discovery), T1016 (System Network Configuration Discovery) + +**What it is:** A WiFi geolocation tool that collects nearby WiFi access point MAC addresses and signal strengths, then uses geo-lookup databases to determine the target device's physical location. No GPS required — WiFi access point mapping provides location data accurate to tens of meters in urban areas. + +--- + +# Chapter 8: Support & Evasion Tools + +## 8.1 Dumbo (Device Disabling) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Windows +**MITRE ATT&CK:** T1562.001 (Disable or Modify Tools) + +**What it is:** A tool that identifies and disables webcams and microphones on a target system. Designed to support physical access operations — when CIA operatives need to enter a room without being recorded, Dumbo is deployed first to disable all recording devices. + +**Operational significance:** Dumbo bridges cyber and physical operations. It is deployed before a physical entry to ensure the operative is not captured on webcam or recorded by microphone. This implies a workflow where cyber access precedes physical access. + +## 8.2 HighRise (Android SMS Proxy) + +**Classification:** SECRET//NOFORN +**Developer:** CIA EDG +**Platforms:** Android +**MITRE ATT&CK:** T1437 (Application Layer Protocol), T1573 (Encrypted Channel) + +**What it is:** An Android application that redirects SMS messages through an internet-based relay to a CIA listening post. Used for covert communications — a compromised Android device can serve as an SMS relay without the user's knowledge. + +## 8.3 Protego (Missile Control) + +**Classification:** SECRET//NOFORN +**Platforms:** Embedded PIC microcontroller + +**What it is:** PIC-based missile control system electronics with GPS targeting, in-flight guidance, and self-destruct capability. This is not a cyber tool — it is a weapons system. Its presence in the Vault 7 archive indicates CIA EDG's scope extends beyond cyber operations into weapons engineering. + +--- + +# Chapter 9: False Flag Operations (Umbrage) + +## 9.1 The Umbrage Program + +**Organizational home:** Remote Development Branch (RDB), CIA +**Purpose:** Borrow techniques, code, and TTPs from other threat actors to create false attribution in CIA cyber operations. + +**Components:** +- **Hacking Team Source Dump Map** — Analysis and cataloging of Hacking Team's source code (leaked in 2015) for reusable components +- **PIQUE Assessments** — Evaluations of tools and techniques from other actors for potential adoption +- **Component Library** — Reusable code modules borrowed from other actors' tools + +**Operational significance:** Umbrage allows the CIA to conduct operations that, if discovered, would be attributed to other threat actors rather than the CIA. By using code patterns, techniques, and infrastructure associated with Russian, Chinese, or criminal groups, the CIA can create false flag cyber operations. + +**Implications for threat intelligence:** If the CIA maintains a library of other actors' techniques specifically for false flag operations, then code-level attribution of cyber attacks is fundamentally unreliable. The presence of "Russian" or "Chinese" code in an attack does not prove the attack was conducted by Russia or China — it may prove only that the attacker had access to that code. + +--- + +# Chapter 10: Operational Patterns & Detection + +## 10.1 Common CIA Patterns + +Analyzing the Vault 7 tools reveals patterns that can inform both red team operations and defensive detection: + +**Persistence preferences:** +- DLL hijacking (Athena, AfterMidnight) — low visibility, survives reboots +- Kernel modules (OutlawCountry, Wolfcreek) — highest privilege, hardest to detect +- Boot sector modification (Solartime/Angelfire) — pre-OS execution +- Service manipulation (Athena) — using legitimate Windows services as hosts + +**Communication patterns:** +- Beacon-based C2 (periodic check-in rather than persistent connection) +- TLS encryption for C2 traffic +- Blending with legitimate traffic (HTTP/HTTPS beaconing) +- Use of legitimate process (srvhost) as network client + +**Deployment patterns:** +- Physical access tools (Dumbo, ExpressLane) suggest human deployment alongside technical +- USB-based tools (Brutal Kangaroo, EzCheese) for air-gapped targets +- Router firmware replacement (CherryBlossom) for network-level access + +## 10.2 Detection Framework + +**Endpoint indicators:** +- Unexpected DLLs with export forwarding chains +- Modified boot sectors +- Kernel modules not associated with installed software +- Minifilter drivers with no corresponding application +- Services enabled that should be disabled (RemoteAccess) +- Modified srvhost service groupings + +**Network indicators:** +- Periodic beacon traffic to unknown external IPs from system processes +- Router firmware hash mismatches against known-good images +- DNS/HTTP traffic taking unexpected routes +- TLS connections from processes that shouldn't be making network calls + +**Physical indicators:** +- Webcam/microphone drivers disabled without user action +- USB devices with hidden partitions +- Biometric system behavior during "software updates" + +--- + +*This manual is a living document. As additional Vault 7 PDFs are parsed, deeper technical details +will be extracted and incorporated. Regenerate with `python mosaic.py manual`.*