Skip to content

Lab 2.1 : C2 Introduction with Empire

Objectives

  • Review the features of Empire
  • Create a listener on Empire
  • Create stager payloads for your Empire listener
  • Execute the stager payload on your Slingshot VM
  • Interact with your Agent
  • Explore Empire modules

This lab will focus on the Testing Phase of a Red Team Adversary Emulation Engagement where the Red Team prepares a Command and Control listener and creates stager payloads to connect to the listener.

TTPs Emulated in this Lab

Preparation

Preparation Steps

Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.

Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:

sudo openvpn ~/Desktop/sec565-labs-range.ovpn

Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :

ping -c 4 draconem.io

If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.

curl draconem.io | head

On Your Own

  1. Create an Empire listener

  2. Create a stager payload

  3. Execute the stager to create an Agent on your Slingshot Linux VM

  4. Ensure communication works properly

  5. Review the walkthrough

Walkthrough

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

Launch Empire

1. Launch Empire by starting the server from the command line.

Please run this as sec565, do NOT become root!

cd /opt/Empire/
sudo ./ps-empire server

2. Start the StarKiller from the terminal. Ctrl+Shift+t to open a new terminal tab.

cd /home/sec565/tools/
./starkiller-1.9.0.AppImage --no-sandbox

3. Log into Starkiller UI

Enter the following values to log into the web user interface:

  • Url: https://localhost:1337
  • Username: empireadmin
  • Password: password123
  • Check the box "Remember URL and Username"

Click SUBMIT

Create Listener

4. Create an Empire listener. You will now be redirected to the listeners menu. We changed the configuration to "light mode" to make these screenshots more clear. Your instance will be in "dark mode" by default. Let's create our first listener.

Click the Create button in the upper right corner of the screen.

Select http in the drop down menu. Then provide the following values:

  • Name: interactive-http
  • Host: 10.254.252.2 <- This must be the ip address of your tun0 adapter
  • Port: 8080
  • Bind IP: 0.0.0.0
  • StagingKey: AddSomethingRandomTo32Characters

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

Note

Empire will Base64 encode the StagingKey if the string if it is not 32 characters.

5. New certificates are created by default and the next steps do not need to be taken but they are included in case you would like to generate new certificates. To create new certificates, return to your terminal. Ctrl+Shift+t to open a new terminal tab, then run the cert.sh script.

sudo su
cd /opt/Empire/setup/
./cert.sh

6. Create a second Empire listener.

On the Listeners dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy.

Provide the following values:

  • Name: interactive-https
  • Host: https://10.254.252.2:443 <- This must be the ip address of your tun0 adapter
  • Port: 443
  • Bind IP: 0.0.0.0
  • Staging key: AddSomethingRandomTo32Characters
  • CertPath: /opt/Empire/empire/server/data

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

Create Stager

7. Create an Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select multi/launcher in the drop down menu. Then provide the following values:

  • StarkillerName: http-slingshot-user
  • Listener: interactive-http
  • Language: python

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

8. Create another Empire stager. On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy.

Provide the following values:

  • StarkillerName: https-slingshot-user
  • Listener: interactive-https
  • Language: python

Leave the reset as defaults and Click the SUBMIT button in the upper right corner of the screen.

Deliver Stager

9. Deliver your stager to Slingshot Linux. On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy to Clipboard.

Open up a new terminal window as the user sec565 and enter Ctrl+Shift+v to paste the stager code. You can see here that we are echoing python code into python3. The stager is base64 encoded by default.

If we take the encoded blob and decode it with base64 -d we can see the python code that will be executed.

Press enter and a subprocess will be created, Empire will receive a web request and a new agent will be registered with the C2.

Agent Interaction

10. Click on the chain icon on the left navigation window to bring up the Agents dashboard. Your new agent will get assigned a randomly generated name. On the dashboard you will see important information about your agent:

  • The Name column is a randomly generated name assigned by Empire, you can and should change this name to something that is easy to recognize.
  • The Last Seen column will show how long it has been since the agent last checked in. This value may indicate if the agent is still alive or not. The check-in intervals are determined by the Delay and Jitter.
  • The First Seen column will display the time since the agent first registered with the C2 server.
  • The Hostname column displays the internal hostname of the system the agent is running on.
  • The Process column shows which process the agent is currently running in.
  • The Architecture column shows the CPU architecture of the target, this is significant for additional targeting. Exploits and tools must be matched to the appropriate CPU architecture.
  • The Language column shows the type code the agent is executing. PowerShell or Python.
  • The Username column shows the current user context the agent is running under.
  • The Internal IP column will usually display the private IP address of the target.

Click on the agent's name to interact with the agent.

11. To expand the console output (green font on black background), click the < icon on the right of the screen below the red trash trashcan icon. In the Shell Command input field, type id and click RUN. While your agent is running it checks in with the C2 server and looks for tasks or taskings. When you clicked RUN, that created a task, tied to that specific agent. The next time the agent checks in, it will receive the task, execute it, and then return the results on the next check-in. This asynchronous communication means that it may take a few check-in cycles to complete the task and return the results.

You can also execute a module, the drop down menu contains all the loaded modules in Empire. This version of Empire has 398 modules loaded by default.

12. Click on the FILE BROWSER tab to explore the file system on the target. When navigating to this tab, a task will automatically be created to get a directory listing of the root of the file system. If you click on a folder a new task will get created to get the contents of that folder.

13. Click on the TASKS tab to see a running list of all tasks for that agent. You also get information on which user created that task. The latest versions of Empire are designed to be multi-user or multi-player to allow a team to work together. The lists of task are also critical in generating reports with timestamps to share with the Blue Team.

Do NOT Rename the agent, this sometimes causes a bug that is going to invalidate communications with your agent.

14. Click on the VIEW tab to see additional metadata about the agent. Here you can rename the agent by providing a new value in the Name field. Take a look at the other data available:

  • Session ID: The original ID when the agent registered with the C2.
  • Name: A friendly name to keep agents organized.
  • External IP: The external or public IP of the target.
  • Internal IP: The internal or private IP of the target.
  • Host Name: The hostname of the target.
  • Username: The user that the agent is running under.
  • Listener: The C2 listener the agent is calling back to, this value can be changed to move the agent to a different listener. Something we will explore more in the Attack Infrastructure lesson.
  • Kill Date: The date that the agent should exit and remove itself from the system.
  • Working Hours: These hours instruct the agent to sleep when outside of those working hours. This field should be used to lower the risk of detection and must be in the format 00:00-24:00.
  • Delay: Is the sleep interval, how many seconds the agent should sleep between check-ins.
  • Jitter: Is the amount of randomness to add or remove from the sleep interval (Delay) to avoid a consistent pattern that could get detected with network monitoring tools.

Note

Red Team Tip: Always set a Kill Date to ensure an agent doesn't live forever if it can not make contact with the C2 server.

Modules

15. Click on the six square icon on the left navigation window to bring up the Modules dashboard. This page will display all the loaded modules along with their characteristics and mapping to MITRE ATT&CK Techniques. You'll notice that most of the modules are for Windows targets.

Explore

16. For the remainder of the lab, interact with your agent and explore the different modules that you can use. If you are wondering why we create two listeners and you have extra time during this lab, look at the bonus content below.

Conclusion

In this lab, you reviewed the features of Empire and configured a listener that will communicate with agents. The listener was tested by creating a stager payload and executing it on your Slingshot Linux VM. This is a test the Red Team should always run to ensure successful initial access to the target environment. There are additional tests that should be conducted before interacting with the target, we will conduct those tests in a later lab.

After creating an agent we executed commands remotely and reviewed the available modules.

Starkiller is a graphical user interface for Empire that helps to keep information organized. You may also interact with Empire entirely form the command line.

Bonus

Network Footprint

17. From a terminal screen start Wireshark with sudo wireshark & and start sniffing on the local adapter by double clicking on Loopback: lo. You should see a lot of HTTP traffic from the agent to the C2 server. You'll notice that all this traffic is using clear text HTTP.

Right click on an HTTP packet and select Follow->TCP Stream.

You'll see that the entire HTTP exchange is captured in clear text. The agent and C2 server are following the settings that were originally set when they were created. Those values create traffic that blends into the target environment but not entirely. The success of blending in, depends on the monitoring capabilities of the target network and the scrutiny the Blue Team will put on examining traffic.

18. Spend a few minutes looking at the traffic, create tasks to see how the agent receives that information and returns the output. The screenshot below is when the agent receives a task, notice the encrypted data that is highlighted in the web server's response.

This next screenshot is of the agent returning the results of that task, the highlighted part of the capture is the encrypted results.

Even though the contents of this communication are encrypted, we want to make it even harder for the Blue Team to see our activity. Let's create a new agent that will call back using TLS to protect the connection.

If you still have the stager you created in step 8, feel free to skip over the next step:
19. Create a new Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select multi/bash in the drop down menu. Then provide the following values:

  • StarkillerName: https-slingshot-user
  • Listener: interactive-https
  • Language: python

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

20. Deliver your stager to Slingshot Linux. On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu for the https-slinghsot-user stager. Click Copy to Clipboard.

Open up a new terminal window as the user sec565 and enter Ctrl+Shift+v to paste the stager code. When you paste this time the terminal window will close after starting the agent. You should now have a new agent!

In Wireshark you can apply the search filter tcp.port == 443 to only see that agent's traffic. Notice that these communications are now protected by TLS.

The main take away from this bonus section is to dig a little deeper and see what your tool looks like on the network. A few extra steps in the setup will make it much harder for the Blue Team to detect your actions. As you improve your skillset, learn more and more about your tools to inform decisions during Red Team Engagements.