Netskope Threat Labs

Sliver

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Sliver is an open source red team framework that threat actors abuse for command and control, lateral movement, and post exploitation activities. Its Go based implants support encrypted channels, on demand payload generation, and cross platform execution, which lets crews generate unique tooling for each victim. Major ransomware groups and state sponsored actors have adopted it, so defenders should treat unexplained Sliver infrastructure as strong evidence of an active intrusion.

First seen
October 2022
Last seen
October 2026

23 techniques across 8 tactics.

TA0002 Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1049System Network Connections Discovery
  • T1083File and Directory Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
DeepScan:Generic.Sliver.E.0131007E
DeepScan:Generic.Sliver.E.0EBB8C66
DeepScan:Generic.Sliver.E.3514BA0C
DeepScan:Generic.Sliver.E.3B919088
DeepScan:Generic.Sliver.E.3D7BFB72
DeepScan:Generic.Sliver.E.4087CF89
DeepScan:Generic.Sliver.E.46CEEF12
DeepScan:Generic.Sliver.E.6189B3A1
DeepScan:Generic.Sliver.E.74B95337
DeepScan:Generic.Sliver.E.799EA9C9