VulnScanners Logo

Command & Control

Empire

PowerShell and Python C2 framework.

c2post-exploitation
empire — terminal
$ powershell-empire server

What it does

Empire is a post-exploitation C2 framework with PowerShell and Python agents, modules, and listeners. It's popular for Windows-centric red team operations.

Common use cases

  • Establish covert PowerShell-based C2 for Windows-centric red-team engagements.
  • Operate through HTTP, HTTPS, and DNS listeners to evade network-based detection.
  • Leverage a rich module library for credential theft, lateral movement, and host enumeration.

Key features

  • Agents run as PowerShell scripts or Python stagers for cross-platform coverage.
  • Supports multiple listener types — HTTP, HTTPS, DNS, and SMB for flexible C2.
  • Includes session staging, tasking, and built-in module browser for operator workflow.
  • Encrypted communications with optional certificate-based authentication for listeners.

Source

https://github.com/BC-SECURITY/Empire

More Command & Control tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →