Sliver

S0633

Tool.View on attack.mitre.org

About this tool

Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1001.002
Steganography

Sliver can encode binary data into a .PNG file for C2 communication.

T1003.001
LSASS Memory

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1016
System Network Configuration Discovery

Sliver has the ability to gather network configuration information.

T1027
Obfuscated Files or Information

Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection.

T1027.004
Compile After Delivery

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

T1027.013
Encrypted/Encoded File

Sliver can encrypt strings at compile time.

T1041
Exfiltration Over C2 Channel

Sliver can exfiltrate files from the victim using the download command.

T1049
System Network Connections Discovery

Sliver can collect network connection information.

T1055
Process Injection

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1059.001
PowerShell

Sliver has built-in functionality to launch a Powershell command prompt.

T1071
Application Layer Protocol

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071.001
Web Protocols

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.004
DNS

Sliver can support C2 communications over DNS.

T1083
File and Directory Discovery

Sliver can enumerate files on a target system.

T1090.001
Internal Proxy

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

View all 23 procedure examples

Groups that use it3

Campaigns1

References2

  1. Bishop Fox Sliver Framework August 2019 Open source
    Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021.
  2. Cybereason Sliver Undated Open source
    Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.