Empire

Install

$ git clone --recursive https://github.com/BC-SECURITY/Empire.git
$ cd Empire
$ sudo ./setup/install.sh
$ sudo poetry install

To compile C# agents (Covenantarrow-up-right and Sharpirearrow-up-right) installarrow-up-right .NET SDK 3.1:

$ wget https://packages.microsoft.com/config/debian/10/packages-microsoft-prod.deb -O packages-microsoft-prod.deb
$ sudo dpkg -i packages-microsoft-prod.deb
$ rm packages-microsoft-prod.deb

$ sudo apt-get update; \
  sudo apt-get install -y apt-transport-https && \
  sudo apt-get update && \
  sudo apt-get install -y dotnet-sdk-3.1

$ sudo apt-get update; \
  sudo apt-get install -y apt-transport-https && \
  sudo apt-get update && \
  sudo apt-get install -y aspnetcore-runtime-3.1

Run

Reset the database:

Cheatsheet

Basic PowerShell launcher string:

Prepare a listener:

Generate a PowerShell stager:

Generate a C# stager:

Re-inject into an interactive process (e. g., explorer.exe):

Bypass UAC to get a high integrity process:

Execute a PowerShell script from memory (e. g., Invoke-SharpSecDump.ps1arrow-up-right):

Start a process in the background (e. g., chiselarrow-up-right SOCKS proxy):

Invoke a custom Mimikatz command:

Plugins

Customizing Agents

Last updated