Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Will not work on windows 10 #1232

Closed
drforbin opened this Issue Sep 16, 2018 · 5 comments

Comments

Projects
None yet
4 participants
@drforbin
Copy link

drforbin commented Sep 16, 2018

Empire Version

latest

OS Information (Linux flavor, Python version)

windows 10

Expected behavior and description of the error, including any actions taken immediately prior to the error. The more detail the better.

I cannot get the launcher to connect back to the listener.
When it's run on windows 10 the powershell launcher just exits
It works on windows 7

Screenshot of error, embedded text output, or Pastebin link to the error

Any additional information

@mr64bit

This comment has been minimized.

Copy link
Contributor

mr64bit commented Sep 16, 2018

@drforbin

This comment has been minimized.

Copy link
Author

drforbin commented Sep 16, 2018

Interesting. Thank you. I have designed other powershell launchers which stage shellcode of my own design and it's not caught. Please explain to me why empire is being caught?

@mr64bit

This comment has been minimized.

Copy link
Contributor

mr64bit commented Sep 17, 2018

@xorrior xorrior closed this Sep 17, 2018

@poopaapoopaa

This comment has been minimized.

Copy link

poopaapoopaa commented Sep 20, 2018

This trick was working until a few days ago. Now it's detected even when SafeChecks is false.

If the detection is overridden and the file is allowed to run, stage 1 stager is sent, and then blocked.
The process ends with:

[*] Sending POWERSHELL stager (stage 1) to ..

If real time virus protection is turned off completely, it works as before.

The -ver 2 option doesn't seem to work at all.

Any further ideas?

@drforbin

This comment has been minimized.

Copy link
Author

drforbin commented Sep 20, 2018

Yes, I am having the same problem.
My costume made shellcode works fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.