ATT&CKReferencesCybereason Sliver Undated

Cybereason Sliver Undated

Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolSliver

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1027.004
Compile After Delivery
ToolSliver

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

T1055
Process Injection
ToolSliver

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1059.001
PowerShell
ToolSliver

Sliver has built-in functionality to launch a Powershell command prompt.

T1071
Application Layer Protocol
ToolSliver

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071.001
Web Protocols
ToolSliver

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.004
DNS
ToolSliver

Sliver can support C2 communications over DNS.

T1090.001
Internal Proxy
ToolSliver

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

T1105
Ingress Tool Transfer
ToolSliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.

T1548.002
Bypass User Account Control
ToolSliver

Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems.

T1558.001
Golden Ticket
ToolSliver

Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets.

T1573.002
Asymmetric Cryptography
ToolSliver

Sliver can use mutual TLS and RSA cryptography to exchange a session key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.