Starting with Empire and getting an agent is easy, but what if we tried to perform a mass phishing attack on the whole organization? How will we know if we got an agent alive or not? What if the agent connects back to our Empire C2 in the middle of the night and we're not online to check it?
It may not seem a serious issue, but a barrage of agents is difficult to manage. For cases like these, let's use Slack. Slack is a messaging application which allows teams to communicate. We can use Slack as the alert application to get an alert whenever an agent connects back to the Empire C2.
Let's register with Slack first by visiting https://slack.com. Once registered, open up the URL shown in the following screenshot to create a legacy API token:
An issued legacy token will look something like this:
Empire gives us the option to add...