Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
ToolSliver | Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection. |
| T1055 Process Injection |
ToolSliver | Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine. |
| T1071.001 Web Protocols |
ToolSliver | Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.004 DNS |
ToolSliver | Sliver can support C2 communications over DNS. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.