Skip to content

Commit

Permalink
Create sliver-c2.yaml
Browse files Browse the repository at this point in the history
  • Loading branch information
johnk3r authored Apr 11, 2024
1 parent 3aa1589 commit 3abdffb
Showing 1 changed file with 33 additions and 0 deletions.
33 changes: 33 additions & 0 deletions ssl/c2/sliver-c2.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
id: sliver-c2

info:
name: Sliver C2 - Detect
author: johnk3r
severity: info
description: |
Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants (slivers) that can run on virtually every architecture out there, and securely manage these connections through a central server
reference: |
https://malpedia.caad.fkie.fraunhofer.de/details/win.sliver
metadata:
verified: "true"
max-request: 1
shodan-query: ssl:"multiplayer" tag:c2
tags: c2,ssl,ir,osint,malware,sliver
ssl:
- address: "{{Host}}:{{Port}}"
matchers-condition: and
matchers:
- type: word
part: issuer_cn
words:
- "operators"

- type: word
part: subject_dn
words:
- "CN=multiplayer"

extractors:
- type: json
json:
- " .issuer_cn"

0 comments on commit 3abdffb

Please sign in to comment.