1200KM / tool
Empire — Attack Tool
Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Empire, EmPyre, PowerShell Empire
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Turla · G0010 · Pinned relationship source (relationship--40848159-b266-42df-9cf8-785b2f78bcfc)
- Sandworm Team · G0034 · Pinned relationship source (relationship--6d06f2d2-9037-47d6-b374-156a35256097)
- FIN10 · G0051 · Pinned relationship source (relationship--1e809121-085d-419e-a763-c9e2309af074)
- CopyKittens · G0052 · Pinned relationship source (relationship--a622b97a-e473-45a5-9e93-85c883f02074)
- APT33 · G0064 · Pinned relationship source (relationship--d3b5af98-ac27-4135-9da6-8e917cc0769d)
- Leviathan · G0065 · Pinned relationship source (relationship--732d754a-b02d-4ec6-8ba2-364c3a8510de)
- MuddyWater · G0069 · Pinned relationship source (relationship--baec4c99-f8f9-4789-a73d-c6b652299048)
- APT19 · G0073 · Pinned relationship source (relationship--89b157e1-3972-421e-87c9-f9e83b26ec90)
- WIRTE · G0090 · Pinned relationship source (relationship--464c9ae2-09b1-499d-8477-c05926537e6b)
- Silence · G0091 · Pinned relationship source (relationship--1567fbd3-5d2b-4040-a736-11f3d5e2139f)
- APT41 · G0096 · Pinned relationship source (relationship--b4e20afc-56a8-4a05-8f73-076b17e3794e)
- Wizard Spider · G0102 · Pinned relationship source (relationship--d73c0fd6-cbd9-4eaa-abca-a1626364ab1b)
- Indrik Spider · G0119 · Pinned relationship source (relationship--8efc016b-af48-4cfd-a117-142a88b7c9d9)
- LazyScripter · G0140 · Pinned relationship source (relationship--ba2b3c40-f9d2-4663-a5bd-3bb158553572)
- HEXANE · G1001 · Pinned relationship source (relationship--aa83b2a0-9941-461f-b9be-a758315f0c4d)
- FIN13 · G1016 · Pinned relationship source (relationship--830ebcfb-58a9-4a11-b319-ca49ce7bfe1b)
- Play · G1040 · Pinned relationship source (relationship--6f82c79c-ef15-4625-b2cf-433e2b600f1e)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1020 · Automated Exfiltration · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1027.010 · Command Obfuscation · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1056.004 · Credential API Hooking · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059 · Command and Scripting Interpreter · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1102.002 · Bidirectional Communication · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1115 · Clipboard Data · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1134.002 · Create Process with Token · Detection rules & anomalies
- T1134.005 · SID-History Injection · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1136.001 · Local Account · Detection rules & anomalies
- T1136.002 · Domain Account · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1217 · Browser Information Discovery · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1484.001 · Group Policy Modification · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.005 · Security Support Provider · Detection rules & anomalies
- T1547.009 · Shortcut Modification · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1555.001 · Keychain · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1558.001 · Golden Ticket · Detection rules & anomalies
- T1558.002 · Silver Ticket · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.004 · Dylib Hijacking · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1574.008 · Path Interception by Search Order Hijacking · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1615 · Group Policy Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Access · DC0071
- Active Directory Object Modification · DC0066
- Application Log Content · DC0038
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- Container Enumeration · DC0091
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Scheduled Job Creation · DC0001
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Authentication · DC0002
- User Account Creation · DC0014
- User Account Metadata · DC0013
- User Account Modification · DC0010
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.