Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Empire contains an implementation of Mimikatz to gather credentials from memory. |
| T1016 System Network Configuration Discovery |
Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host. |
| T1020 Automated Exfiltration |
Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1021.003 Distributed Component Object Model |
Empire can utilize |
| T1021.004 SSH |
Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection. |
| T1027.010 Command Obfuscation |
Empire has the ability to obfuscate commands using |
| T1033 System Owner/User Discovery |
Empire can enumerate the username on targeted hosts. |
| T1040 Network Sniffing |
Empire can be used to conduct packet captures on target hosts. |
| T1041 Exfiltration Over C2 Channel |
Empire can send data gathered from a target through the command and control channel. |
| T1046 Network Service Discovery |
Empire can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
Empire can use WMI to deliver a payload to a remote host. |
| T1049 System Network Connections Discovery |
Empire can enumerate the current network connections of a host. |
| T1053.005 Scheduled Task |
Empire has modules to interact with the Windows task scheduler. |
| T1055 Process Injection |
Empire contains multiple modules for injecting into processes, such as |
| T1056.001 Keylogging |
Empire includes keylogging capabilities for Windows, Linux, and macOS systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.