finds.dev← search

// the find

BishopFox/sliver

★ 11,956 · Go · GPL-3.0 · updated Oct 2026

Adversary Emulation Framework

Sliver is Bishop Fox's Go-based adversary emulation framework. It has a team server, an operator console, and implants for Windows, macOS, and Linux that call back over mTLS, WireGuard, HTTP(S), or DNS. It is aimed at red teams and pentesters running authorized engagements who want a self-hosted alternative to commercial C2 platforms.

Implants are compiled per build with unique asymmetric keys, so separate binaries from the same server don't share key material. The transport choice is broad: mTLS and HTTP(S) cover the common paths, and WireGuard and DNS are useful when egress is tightly filtered. The client supports BOF/COFF execution, reflective loading, and shellcode encoding on amd64 and arm64. The repo runs CI for unit tests, golangci-lint, CodeQL, shellcode tests, and an end-to-end workflow, which is more test coverage than most projects in this space carry. It was pushed to yesterday, so it is clearly still under active work.

Its popularity works against it. Defenders have documented the default implant and network behaviour widely, so a stock build tests less than the README implies. The README is thin, and the real documentation lives on sliver.sh and the wiki. The Linux install is a curl-to-sudo-bash one-liner, which asks you to run a remote script as root before you have read it. The README says implants may run on other Go targets but are not regularly tested there, so anything beyond Windows, macOS, and Linux is your own verification job. GPLv3 with sub-components under separate licenses means embedding or redistributing it in a closed product creates obligations that need a legal read first.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →