Netskope Threat Labs

Empire

ATP Sandbox Adv. HeuristicsAV

Empire is an open source post exploitation framework that cyberattackers abuse for command and control, reconnaissance, and lateral movement across Windows, Linux, and cloud platforms. Its PowerShell and Python agents run entirely in memory, which complicates disk based detection, and its module library automates credential theft and privilege escalation. Security teams and red teams both use the framework, so defenders should evaluate detections against authorized testing activity.

First seen
May 2022
Last seen
September 2026
EmPyreEmpyre

73 techniques across 11 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation
  • T1546Event Triggered Execution
  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1046Network Service Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery
  • T1135Network Share Discovery
  • T1217Browser Information Discovery
  • T1482Domain Trust Discovery
  • T1518Software Discovery
  • T1615Group Policy Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1020Automated Exfiltration
  • T1041Exfiltration Over C2 Channel
  • T1567Exfiltration Over Web Service

TA0112 Defense Impairment

  • T1484Domain or Tenant Policy Modification
Alert Name
Binary.Malware.Empire
Binary.Virus.Empire
ByteCode-MSIL.Trojan.Empire
Document-HTML.Trojan.Empire
Dump:Generic.Trojan.Empire.A.38673A95
Gen:Variant.Trojan.MAC.Empire.2
Gen:Variant.Trojan.MAC.Empire.3
Generic.Powershell.Empire.A.1488E863
Generic.Powershell.Empire.A.263E5D7C
Generic.Powershell.Empire.A.D12FA9D1