s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3352

📛 Threat Title

SIG:ET HUNTING Possible Sliver Age and Minisign Key Material in Internal TCP Stream

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:argonsys.com

    Config extraction When responding to a suspected intrusion, security analysts may find themselves with a malware payload with little context. Quickly extracting key configuration details from the malware like C2 address, network configurations, and other implant details is a crucial step in hunting for affected devices in the network. Many implants, including Sliver , heavily obfuscate or ...

  • web:community.emergingthreats.net

    The rule looks for age style public key material followed by minisign signature comment markers in an internal TCP stream . The intended use is internal hunting for Sliver family, Sliver derived, or similar implant key exchange material , especially where an operator may be pivoting through one internal host toward a more restricted network.

  • web:github.com

    Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP (S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys .

  • web:github.com

    The listener sends its Age public key , the minisign signature of its public key , and the encrypted session key back to the initiator The initiator verifies the listener's public key is signed by the initiator's server's minisign public key

  • web:sliver.sh

    Comprehensive documentation for Sliver , a command and control framework, including setup instructions, features, and advanced usage guides.

  • web:trym.cloud

    Answer Sliver is an open-source command- and -control framework originally built by Bishop Fox for red-team operations that is now actively used by ransomware operators and APT groups including APT29. Its Go-based implant, configurable transports (HTTPS, DNS, mTLS, WireGuard, TCP ), and in -memory execution defeat IOC-based detection. The reliable hunt strategy on Microsoft Defender XDR is ...

  • web:wizardcyber.com

    Learn how to hunt Sliver C2 using Microsoft Defender XDR and Sentinel with behaviour-based detection across endpoints and network traffic.

  • web:www.drakeaxelrod.com

    A complete and practical cheatsheet for Sliver , the open-source Command and Control (C2) framework used by red teams and penetration testers for secure post-exploitation, beaconing, and multi-platform payload delivery.

  • web:www.huntandhackett.com

    Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.

  • web:www.threatshub.org

    Unless otherwise noted, the detection and hunting guidance in this blog are designed for official, non-customized Sliver codebase available as of this writing. Customers can run the following queries in the Microsoft 365 Defender portal. These queries are examples of how hunters can key in on unique default configurations implemented by Sliver .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.