Empire
Install
$ git clone --recursive https://github.com/BC-SECURITY/Empire.git
$ cd Empire
$ sudo ./setup/install.sh
$ sudo poetry installTo compile C# agents (Covenant and Sharpire) install .NET SDK 3.1:
$ wget https://packages.microsoft.com/config/debian/10/packages-microsoft-prod.deb -O packages-microsoft-prod.deb
$ sudo dpkg -i packages-microsoft-prod.deb
$ rm packages-microsoft-prod.deb
$ sudo apt-get update; \
sudo apt-get install -y apt-transport-https && \
sudo apt-get update && \
sudo apt-get install -y dotnet-sdk-3.1
$ sudo apt-get update; \
sudo apt-get install -y apt-transport-https && \
sudo apt-get update && \
sudo apt-get install -y aspnetcore-runtime-3.1Run
Reset the database:
Cheatsheet
Basic PowerShell launcher string:
Prepare a listener:
Generate a PowerShell stager:
Generate a C# stager:
Re-inject into an interactive process (e. g., explorer.exe):
Bypass UAC to get a high integrity process:
Execute a PowerShell script from memory (e. g., Invoke-SharpSecDump.ps1):
Start a process in the background (e. g., chisel SOCKS proxy):
Invoke a custom Mimikatz command:
Plugins
Customizing Agents
Last updated