PowerShell Empire

E192912

PowerShell Empire is a post-exploitation and adversary emulation framework that leverages PowerShell for stealthy command-and-control and offensive security operations.

All labels observed (1)

Label Occurrences
PowerShell Empire canonical 1

How this entity was disambiguated

Statements (51)

Predicate Object
instanceOf adversary emulation framework ⓘ
command-and-control framework ⓘ
offensive security tool ⓘ
post-exploitation framework ⓘ
developedFor penetration testing ⓘ
red team operations ⓘ
security research ⓘ
feature HTTP C2 channel ⓘ
HTTPS C2 channel ⓘ
Mimikatz integration ⓘ
PowerShell agent ⓘ
credential harvesting ⓘ
encrypted communications ⓘ
fileless post-exploitation ⓘ
lateral movement ⓘ
listener management ⓘ
modular architecture ⓘ
named pipe C2 channel ⓘ
obfuscation options ⓘ
persistence mechanisms ⓘ
plugin system ⓘ
stager generation ⓘ
staging over PowerShell ⓘ
hasComponent Empire agent ⓘ
Empire listeners ⓘ
Empire modules ⓘ
Empire server ⓘ
isWrittenIn PowerShell ⓘ
Python ⓘ
license BSD 3-Clause License ⓘ
linked to: BSD license
primaryUse adversary emulation ⓘ
command and control ⓘ
post-exploitation ⓘ
red teaming ⓘ
programmingLanguage PowerShell ⓘ
securityDomain offensive security ⓘ
post-exploitation ⓘ
supportsOperation bypass of application whitelisting ⓘ
data exfiltration ⓘ
keylogging ⓘ
network reconnaissance ⓘ
pivoting ⓘ
privilege escalation ⓘ
script execution ⓘ
shell command execution ⓘ
supportsPlatform Linux ⓘ
Windows ⓘ
macOS ⓘ
usesTechnology .NET Framework ⓘ
PowerShell Remoting ⓘ
Windows Management Instrumentation ⓘ

How these facts were elicited

Referenced by (1)

Full triples — surface form annotated when it differs from this entity's canonical label.

Kali Linux → includesTool → PowerShell Empire ⓘ