Empire

S0363

Tool.View on attack.mitre.org

About this tool

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.

Techniques used73

Procedure examples73

TechniqueProcedure example
T1003.001
LSASS Memory

Empire contains an implementation of Mimikatz to gather credentials from memory.

T1016
System Network Configuration Discovery

Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host.

T1020
Automated Exfiltration

Empire has the ability to automatically send collected data back to the threat actors' C2.

T1021.003
Distributed Component Object Model

Empire can utilize Invoke-DCOM to leverage remote COM execution for lateral movement.

T1021.004
SSH

Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection.

T1027.010
Command Obfuscation

Empire has the ability to obfuscate commands using Invoke-Obfuscation.

T1033
System Owner/User Discovery

Empire can enumerate the username on targeted hosts.

T1040
Network Sniffing

Empire can be used to conduct packet captures on target hosts.

T1041
Exfiltration Over C2 Channel

Empire can send data gathered from a target through the command and control channel.

T1046
Network Service Discovery

Empire can perform port scans from an infected host.

T1047
Windows Management Instrumentation

Empire can use WMI to deliver a payload to a remote host.

T1049
System Network Connections Discovery

Empire can enumerate the current network connections of a host.

T1053.005
Scheduled Task

Empire has modules to interact with the Windows task scheduler.

T1055
Process Injection

Empire contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1056.001
Keylogging

Empire includes keylogging capabilities for Windows, Linux, and macOS systems.

View all 73 procedure examples

Groups that use it17

Campaigns1

References3

  1. GitHub ATTACK Empire Open source
    Stepanic, D. (2018, September 2). attck_empire: Generate ATT&CK Navigator layer file from PowerShell Empire agent logs. Retrieved March 11, 2019.
  2. Github PowerShell Empire Open source
    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.
  3. NCSC Joint Report Public Tools Open source
    The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.