| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
Sliver can encode binary data into a .PNG file for C2 communication. |
| T1003.001 LSASS Memory |
Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting. |
| T1016 System Network Configuration Discovery |
Sliver has the ability to gather network configuration information. |
| T1027 Obfuscated Files or Information |
Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection. |
| T1027.004 Compile After Delivery |
Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments. |
| T1027.013 Encrypted/Encoded File |
Sliver can encrypt strings at compile time. |
| T1041 Exfiltration Over C2 Channel |
Sliver can exfiltrate files from the victim using the |
| T1049 System Network Connections Discovery |
Sliver can collect network connection information. |
| T1055 Process Injection |
Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine. |
| T1059.001 PowerShell |
Sliver has built-in functionality to launch a Powershell command prompt. |
| T1071 Application Layer Protocol |
Sliver can utilize the Wireguard VPN protocol for command and control. |
| T1071.001 Web Protocols |
Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.004 DNS |
Sliver can support C2 communications over DNS. |
| T1083 File and Directory Discovery |
Sliver can enumerate files on a target system. |
| T1090.001 Internal Proxy |
Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.