logo

Empire Bootstrapping v2 – How to Pre-Automate All the Things!

ID: 46fb8b32-cd11-5795-b1b7-0c5ae93e4ee4

STIX ID: report--46fb8b32-cd11-5795-b1b7-0c5ae93e4ee4

Feed Name: Black Hills Infosec Blog

Date Published: 2017-04-19

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This blog post demonstrates automating PowerShell Empire C2 listener deployment using GNU Screen, providing example shell scripts that launch Empire in a detached session, issue commands to kill existing listeners and create a new listener (configurable name and port), and optionally attach the operator to the session; it is a tutorial-style TTP for automating C2 management rather than an incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.