Skip to main content

One post tagged with "empire"

View All Tags

Empire – Modifying Server C2 Indicators

· 6 min read
Andrew Chiles
Red Team Operator

Overview

This post is intended as a follow-on to Jeff Dimmock's detailed write-up on creating communication profiles for Empire. Empire 1.6's “DefaultProfile” setting for modifying C2 indicators doesn't directly allow modification of the server-side parameters. When faced with an experienced group of defenders, default C2 server indicators can quickly reveal your infrastructure. HTTPS listeners with valid certificates can certainly hinder traffic monitoring, but isn't a silver bullet.