Skip to content

Releases: BC-SECURITY/Empire

Empire v3.5.2

22 Oct 05:27
01b073d
Compare
Choose a tag to compare

Beginning with Empire 3.5.0, we recommend the use of Poetry or the Docker images to run Empire as we will be transitioning to these platforms.

Changelog

  • Fixed token manipulation (steal_token) functionality in Windows 10 - #355 (@Hubbl3)
  • Fixed lateral movement module New-GPOImmediateTask - #362 (@Cx01N)
  • Fixed Invoke-PSRemoting blocking current agent - #359 (@mjokic)

Empire v3.5.1

14 Oct 05:12
cc18b46
Compare
Choose a tag to compare

Beginning with Empire 3.5.0, we recommend the use of Poetry or the Docker images to run Empire as we will be transitioning to these platforms.

Changelog

Empire v3.5.0

13 Oct 06:27
f0ecc93
Compare
Choose a tag to compare

Beginning with Empire 3.5.0, we recommend the use of Poetry or the Docker images to run Empire as we will be transitioning to these platforms.

Changelog

v3.4.0

16 Sep 03:34
f6efd5a
Compare
Choose a tag to compare

Empire 3.4.0

  • Added Malleable C2 HTTP Listener - #287 (@johneiser, @Cx01N, @Hubbl3)
  • Added reflective load ability for files - #309 (@Hubbl3)
  • Added Invoke-DomainPasswordSpray - #295 (@Cx01N)
  • Added Invoke-WinPEAS - #293 (@Cx01N)
  • Added Invoke-Watson - #294 (@Cx01N)
  • Added plugins being loaded at startup - #301 (@Cx01N)
  • Updated moduleName to display full directory - #299 (@Cx01N)
  • Updated info in Invoke-SMBExec to indicate single target - #286 (@Cx01N)
  • Updated Slack API notifications to webhooks - #303 (@Cx01N)
  • Fixed spaces for IIS default page in HTTP listener - #302 (@adamczi)
  • Fixed agent spawning issue with MS-16-032 - #292 (@Cx01N)
  • Fixed min language version for modules (@Cx01N)
  • Fixed CLI stager incorrectly shutting down - #198 (@Cx01N)
  • Fixed error message from active agents during shutdown - #308 (@Cx01N)

v3.4.0-RC2

09 Sep 04:19
Compare
Choose a tag to compare
v3.4.0-RC2 Pre-release
Pre-release

Empire 3.4.0-RC2

v3.4.0-RC1

03 Sep 04:16
Compare
Choose a tag to compare
v3.4.0-RC1 Pre-release
Pre-release

Empire 3.4.0-RC1

Note: Confirmed working Malleable C2 Profiles can be found here.

v.3.3.4

18 Aug 04:38
2a20e2e
Compare
Choose a tag to compare

Empire 3.3.4

  • Fixed preobfuscate error: could not read module source path - #282 (@Cx01N)
  • Fixed issues http_foreign listener issue - #283 (@Cx01N)

v3.3.3

12 Aug 04:13
c1bdbd0
Compare
Choose a tag to compare

Empire 3.3.3

  • Added get_gpo_computer module - #271 (@byt3bl33d3r)
  • Added port forwarding module - #265 (@snovvcrash)
  • Updated HTTP/HTTP_com listeners to closer resemble IIS 7.5 - #277 (@adamczi)
  • Updated lateral movements (invoke_smbexec/invoke_dcom/invoke_executemsbuild/invoke_wmi) to include option for custom commands - #247 (@Invoke-Mimikatz)
  • Updated Mimikatz 2.2.0 20200809 AzureAd x-ms-RefreshTokenCredential & DPAPI everywhere - #279 (@Cx01N)
  • Fixed issue with duplicate results in db - #266 (@byt3bl33d3r)
  • Fixed empty token issue in API - #274 (@vinnybod)
  • Fixed missing keyword argument in ETWBypass - #273 (@Cx01N)

v3.3.2

05 Aug 06:44
d00626a
Compare
Choose a tag to compare

Empire 3.3.2

  • Added Event Tracing for Windows (ETW) Bypass to stagers - #269 (@Hubbl3)
  • Updated Mimikatz 20200805 CloudAP Key Derivation - #268 (@Cx01N)
  • Updated Invoke-Kerberoast to John The Ripper format - #263 (@kazkansouh)
  • Fixed indentation issues in schtasks - #267 (@adamczi)

v3.3.1

20 Jul 04:33
b16e030
Compare
Choose a tag to compare

Empire 3.3.1

  • Updated Mimikatz to 20200715 NPLogonNotify passwords - #260 (@Cx01N)
  • Fixed syntax errors in Get-GPPPassword and MS16-135 - #259 (@PaulWhitingS2)
  • Fixed missing keylogger character issue - #252 (@Cx01N)
  • Fixed missing agentPSversion variable - #262 (@Cx01N)