Persistence via Empire

Empire has a lot of inbuilt modules that allow us to use persistence on a system while performing a red team activity. These modules are divided into four main areas:

  • PowerBreach: This is a series of in-memory PowerShell backdoors that provide triggers for various options
  • userland: These are backdoors that execute on reboot without needing admin rights
  • elevated: These are backdoors that execute on reboot with admin rights
  • debugger triggers: These are backdoors that execute on a particular trigger (an example of this is sticky keys)

In this section, we will cover some of the modules for Linux, Windows, and macOS systems.

For Windows:

Assuming we have an agent connected on our empire from a Windows Machine:

To view ...

Get Hands-On Red Team Tactics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.