Description
Empire is an open source post exploitation framework that cyberattackers abuse for command and control, reconnaissance, and lateral movement across Windows, Linux, and cloud platforms. Its PowerShell and Python agents run entirely in memory, which complicates disk based detection, and its module library automates credential theft and privilege escalation. Security teams and red teams both use the framework, so defenders should evaluate detections against authorized testing activity.
Stats
- First seen
- May 2022
- Last seen
- September 2026
Also known as
EmPyreEmpyre
MITRE ATT&CK techniques
73 techniques across 11 tactics.
TA0002 Execution
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
- T1016System Network Configuration Discovery
- T1033System Owner/User Discovery
- T1046Network Service Discovery
- T1049System Network Connections Discovery
- T1057Process Discovery
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087Account Discovery
- T1135Network Share Discovery
- T1217Browser Information Discovery
- T1482Domain Trust Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
- T1615Group Policy Discovery
TA0008 Lateral Movement
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Binary.Malware.Empire |
| Binary.Virus.Empire |
| ByteCode-MSIL.Trojan.Empire |
| Document-HTML.Trojan.Empire |
| Dump:Generic.Trojan.Empire.A.38673A95 |
| Gen:Variant.Trojan.MAC.Empire.2 |
| Gen:Variant.Trojan.MAC.Empire.3 |
| Generic.Powershell.Empire.A.1488E863 |
| Generic.Powershell.Empire.A.263E5D7C |
| Generic.Powershell.Empire.A.D12FA9D1 |