{"id":9195,"date":"2025-12-14T10:03:35","date_gmt":"2025-12-14T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/14\/empire-6-3-0-launches-with-new-features-for-red-teams-and-penetration-testers\/"},"modified":"2025-12-14T10:03:35","modified_gmt":"2025-12-14T10:03:35","slug":"empire-6-3-0-launches-with-new-features-for-red-teams-and-penetration-testers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/14\/empire-6-3-0-launches-with-new-features-for-red-teams-and-penetration-testers\/","title":{"rendered":"Empire 6.3.0 Launches With New Features for Red Teams and Penetration Testers"},"content":{"rendered":"<p>    Empire 6.3.0 Launches With New Features for Red Teams and Penetration Testers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>BC Security has announced the release of\u00a0Empire 6.3.0, the latest iteration of the widely used post-exploitation and adversary emulation framework. <\/p>\n<p>This update reinforces Empire\u2019s position as a premier tool for Red Teams and<a href=\"https:\/\/cybersecuritynews.com\/top-10-gpt-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\"> penetration testers<\/a>, offering a flexible, modular server architecture written in Python 3 along with extensive agent support.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-unified-architecture-and-expanded-agent-support\"><strong>Unified Architecture and Expanded Agent Support<\/strong><\/h2>\n<p>Empire 6.3.0 continues to streamline operations with its server\/client architecture, designed to support multiplayer engagements. <\/p>\n<p>The framework allows multiple operators to collaborate seamlessly while maintaining fully encrypted communications. <\/p>\n<p>A key highlight of this <a href=\"https:\/\/github.com\/BC-SECURITY\/Empire\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">release<\/a> is the robust support for diverse agent languages, enabling operators to deploy implants across various environments. <\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Feature Category<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Capabilities and Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Supported Agents<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">PowerShell, Python 3, C#, IronPython 3, Go<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Evasion &amp; Security<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">JA3\/S &amp; JARM Evasion, ConfuserEx 2, Invoke-Obfuscation, Encrypted Comms<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Installation Support<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Docker, Kali, ParrotOS, Ubuntu 22.04\/24.04, Debian 11\/12<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Execution Modules<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Assembly Execution, BOF Execution, Mimikatz, Rubeus, Seatbelt<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Compiler Integration<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Integrated Roslyn compiler (Covenant) for in-memory .NET execution<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Interface<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CLI Client &amp; Starkiller Web GUI (Git submodule)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The inclusion of\u00a0Go agents\u00a0alongside traditional PowerShell and Python 3 agents significantly broadens the operational scope, allowing for execution on systems where interpreted languages might be restricted.<\/p>\n<p>The integrated\u00a0Starkiller\u00a0GUI, now packaged as a Git submodule, provides a modern web interface for <a href=\"https:\/\/cybersecuritynews.com\/enterprise-remote-access-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">remote server management<\/a>. <\/p>\n<p>This eliminates the need for complex independent setups, as Starkiller interfaces directly with Empire\u2019s API to offer a graphical alternative to the command-line client.<\/p>\n<p>Security evasion remains a priority in version 6.3.0. The framework incorporates\u00a0JA3\/S and JARM evasion\u00a0techniques to blend traffic profiles and bypass network detection logic. <\/p>\n<p><strong>Installation Quickstart:<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">bash<code>git clone --recursive https:\/\/github.com\/BC-SECURITY\/Empire.git\ncd Empire\n.\/setup\/checkout-latest-tag.sh\n.\/ps-empire install -y\n.\/ps-empire server<\/code><\/pre>\n<p>Additionally, integrated <a href=\"https:\/\/cybersecuritynews.com\/quasarrat-core-functionalities-along-with-encrypted-configuration\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation <\/a>tools like\u00a0ConfuserEx 2\u00a0and\u00a0Invoke-Obfuscation\u00a0help mask payloads from antivirus and EDR solutions.<\/p>\n<p>The module library now boasts over 400 supported tools, ranging from\u00a0Mimikatz\u00a0and\u00a0Seatbelt\u00a0to custom C# assemblies compiled via the integrated\u00a0Roslyn compiler. <\/p>\n<p>This modular design allows operators to rapidly extend functionality by adding custom plugins or utilizing the flexible module interface for new tools.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/empire-6-3-0-red-teams-and-penetration-testers\/\">Empire 6.3.0 Launches With New Features for Red Teams and Penetration Testers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/empire-6-3-0-red-teams-and-penetration-testers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Empire 6.3.0 Launches With New Features for Red Teams and Penetration Testers BC Security has announced the release of\u00a0Empire 6.3.0, the latest iteration of the widely used post-exploitation and adversary emulation framework. This update reinforces Empire\u2019s position as a premier tool for Red Teams and penetration testers, offering a flexible, modular server architecture written in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,767],"tags":[130],"class_list":["post-9195","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-penetration-testing","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9195"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9195"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9195\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}