Which option is a PowerShell-based post-exploitation tool that can maintain persistence on a compromised system and run PowerShell agents without the need for powershell.exe?
- Empire
- Veil
- Patator
- Security Onion
Explanation & Hint:
Empire is a PowerShell-based post-exploitation framework that is very popular among pen testers. Empire is an open-source framework with PowerShell Windows and Python Linux agents. Empire implements the ability to run PowerShell agents without the need for powershell.exe. It allows you to rapidly deploy post-exploitation modules, including keyloggers, reverse shells, Mimikatz, and adaptable communications to evade detection. |