Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0363
MITRE ATT&CK Tool

Empire (S0363)

EmPyrePowerShell Empire
ShareXLinkedInRedditHN

[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure [PowerShell](https://attack.mitre.org/techniques/T1059/001) for Windows and Python for Linux/macOS. [Empire](https://attack.mitre.org/software/S0363) was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.(Citation: NCSC Joint Report Public Tools)(Citation: Github PowerShell Empire)(Citation: GitHub ATTACK Empire)

Platforms: Linux, macOS, Windows

▪Techniques implemented (73)

T1125Video CaptureT1021.003Distributed Component Object ModelT1557.001Name Resolution Poisoning and SMB RelayT1016System Network Configuration DiscoveryT1059.001PowerShellT1482Domain Trust DiscoveryT1056.001KeyloggingT1027.010Command ObfuscationT1136.001Local AccountT1113Screen CaptureT1046Network Service DiscoveryT1552.001Credentials In FilesT1560Archive Collected DataT1484.001Group Policy ModificationT1041Exfiltration Over C2 ChannelT1082System Information DiscoveryT1115Clipboard DataT1068Exploitation for Privilege EscalationT1020Automated ExfiltrationT1546.008Accessibility FeaturesT1119Automated CollectionT1555.001KeychainT1615Group Policy DiscoveryT1087.002Domain AccountT1547.005Security Support ProviderT1021.004SSHT1558.003KerberoastingT1134.005SID-History InjectionT1574.009Path Interception by Unquoted PathT1547.001Registry Run Keys / Startup FolderT1135Network Share DiscoveryT1574.008Path Interception by Search Order HijackingT1558.001Golden TicketT1210Exploitation of Remote ServicesT1569.002Service ExecutionT1567.001Exfiltration to Code RepositoryT1083File and Directory DiscoveryT1056.004Credential API HookingT1574.007Path Interception by PATH Environment VariableT1106Native APIT1047Windows Management InstrumentationT1055Process InjectionT1550.002Pass the HashT1217Browser Information DiscoveryT1127.001MSBuildT1552.004Private KeysT1567.002Exfiltration to Cloud StorageT1071.001Web ProtocolsT1134Access Token ManipulationT1040Network SniffingT1114.001Local Email CollectionT1059.003Windows Command ShellT1102.002Bidirectional CommunicationT1555.003Credentials from Web BrowsersT1518.001Security Software DiscoveryT1087.001Local AccountT1574.004Dylib HijackingT1049System Network Connections DiscoveryT1053.005Scheduled TaskT1003.001LSASS MemoryT1573.002Asymmetric CryptographyT1134.002Create Process with TokenT1543.003Windows ServiceT1059Command and Scripting InterpreterT1057Process DiscoveryT1105Ingress Tool TransferT1070.006TimestompT1547.009Shortcut ModificationT1574.001DLLT1136.002Domain AccountT1033System Owner/User DiscoveryT1548.002Bypass User Account ControlT1558.002Silver Ticket

▪Used by groups (17)

G0091SilenceG0051FIN10G0010TurlaG0090WIRTEG0034Sandworm TeamG1040PlayG0065LeviathanG1016FIN13G0073APT19G0119Indrik SpiderG0052CopyKittensG1001HEXANEG0096APT41G0140LazyScripterG0069MuddyWaterG0064APT33G0102Wizard Spider
S0363on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.