Sliver C2 is an adversary-emulation and command-and-control framework developed by Bishop Fox. Its implant component has been observed in intrusions as a Windows service and has been associated with use of a PsExec module for lateral movement and remote command execution. Sliver C2-related activity has also been associated with process-injection behavior on Windows. Qilin ransomware affiliate operations have used Sliver C2 alongside other command-and-control and remote-management tooling. Windows telemetry relevant to Sliver C2 includes service-creation events and Sysmon process-access events indicative of injection into other processes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The following analytic detects the creation of a Windows service named "Sliver" with the description "Sliver Implant," indicative of SliverC2 lateral movement using the PsExec module.
The following analytic detects the creation of a Windows service named "Sliver" with the description "Sliver Implant," indicative of SliverC2 lateral movement using the PsExec module.
The following analytic detects the creation of a Windows service named "Sliver" with the description "Sliver Implant," indicative of SliverC2 lateral movement using the PsExec module.
The following analytic detects the creation of a Windows service named "Sliver" with the description "Sliver Implant," indicative of SliverC2 lateral movement using the PsExec module.
The following analytic detects the creation of a Windows service named "Sliver" with the description "Sliver Implant," indicative of SliverC2 lateral movement using the PsExec module.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe... This behavior is often associated with the SliverC2 framework by BishopFox.
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe... This behavior is often associated with the SliverC2 framework by BishopFox.
The following analytic detects any outbound network connection from an endpoint process to a known suspicious or non-standard port... processes communicating over ports like 4444, 2222, or 51820 are commonly used by tools like Metasploit, SliverC2 or other pentest, red team or malware.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source command-and-control and post-exploitation framework observed in operations associated with Qilin activity.
A command-and-control framework/implant used for lateral movement, remote command execution, and persistence on compromised Windows systems, including service creation via its PsExec module.
A command-and-control framework associated here with process injection into commonly abused Windows processes to execute malicious code, potentially enabling arbitrary code execution, privilege escalation, or persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.