Sliver
Cross-platform adversary emulation and command-and-control framework built for authorized red team operations and testing.
Technical Architecture & Overview
Sliver is an open-source, cross-platform adversary emulation and command-and-control (C2) framework developed by Bishop Fox. It supports multiplayer operations, dynamic implants, WireGuard and mTLS transport encryption, and a wide range of implant generation and beaconing capabilities for authorized red team engagements.
Targeted Technical Use Cases
Authorized red team operations, adversary emulation, and defensive control testing.
Evaluation & Trade-offs
Core Strengths
- +Cross-platform implant support for Windows, Linux, and macOS.
- +Multiplayer collaboration for team-based red team operations.
- +WireGuard and mTLS encrypted transport with dynamic implant generation.
Trade-Offs & Limitations
- -C2 frameworks require careful operational security and authorization scoping.
- -Implant signatures may be detected by modern EDR solutions without customization.
Defensive Security Application
Testing EDR detection capabilities, blue team response procedures, and network monitoring controls.
Frequently Asked Questions
What is Sliver?→
Sliver is an open-source, cross-platform adversary emulation and command-and-control (C2) framework developed by Bishop Fox. It supports multiplayer operations, dynamic implants, WireGuard and mTLS transport encryption, and a wide range of implant generation and beaconing capabilities for authorized red team engagements.
What is Sliver used for?→
Authorized red team operations, adversary emulation, and defensive control testing.
What are the strengths of Sliver?→
- +Cross-platform implant support for Windows, Linux, and macOS.
- +Multiplayer collaboration for team-based red team operations.
- +WireGuard and mTLS encrypted transport with dynamic implant generation.
What are the limitations of Sliver?→
- +C2 frameworks require careful operational security and authorization scoping.
- +Implant signatures may be detected by modern EDR solutions without customization.
How is Sliver used defensively?→
Testing EDR detection capabilities, blue team response procedures, and network monitoring controls.