Empire Operations: Tactics (Turla)

Empire Operations: Tactics (Turla)

In this course, we will explore how to leverage Empire to emulate Turla, a notorious Russian APT. Leveraging a case study of a recent campaign, students will use Empire to deploy TTPs such as IronPython tradecraft, Office Doc exploitation, and more.

Emulate Turla with Empire

Explore how to leverage Empire to emulate Turla, a notorious Russian APT. Using a recent campaign case study, deploy TTPs including IronPython tradecraft, Office Doc exploitation, and advanced evasion techniques.

Course Modules

Hands-on operator workflows to emulate Turla TTPs in realistic lab environments.

Contact

Intro to Threat Emulation - Turla

Threat emulation basics, command and control theory, and overview of Turla's history and modern TTPs.
Contact

Turla's Attack Infrastructure and Tools

Emulating Turla with Empire, leveraging file hosting services and DropBox as a C2 channel, and IronPython for evasion.
Contact

Exploiting the Target

Office Doc exploitation, establishing persistence and leveraging exclusions, and pivoting with Win-RM.
Work With Us

Ready to Test Your Defenses Against Real Threats?

Talk to BC Security about penetration testing, red team operations, or hands‑on training. We’ll map real adversary TTPs to your environment and help you make risk‑based decisions.

Veteran Owned & Operated

Founded and operated by U.S. military veterans bringing mission-focused discipline to cybersecurity

0000

Serving Clients Since

Offensive security assessments and training delivered since 2018.

00000 +

Community Members

Practitioners in the BC Security Discord community.