Powershell empire: Macros

This lab is from the CyberOps Cisco training. its intent is to fire off a macro enable word file with malicious intent.

From your Kali Machine

  1. start powershell empire – ./start-empire.sh
  2. verify that it is running — screen -ls
  3. exam the attack script — cat /root/Deskstop/send-phish.sh
  4. Execute the script — ./send-phish.sh

On the victim machine

  1. Launch outlook
  2. Navigate to the email sent
  3. Open the file and enable content
  4. Within a few minutes you will see the files start to get encrypted on the machine