c2 framework
Sliver
BishopFox's open-source adversary emulation framework, found deployed as a live C2 by more than one operator. Named by 2 reports, 6 detection rules, 0 IOC feeds and 2 tracked actors.
Reports
Detection rules
YARA rules whose family metadata names this family, by detection page.
Detection rules
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17
Sliver_Beacon_Memory_Import_Path, Sliver_Operator_Build_Artifacts_193_233_202_17
Detection rules
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)
MALW_ScareCrow_Go_Loader_OneDriveSync, MALW_Fraudulent_VMware_CodeSign_Cert_PE, MALW_Fraudulent_VMware_CodeSign_Cert_PEM, MALW_UPX_Packed_Sliver_Variant
Tracked actors
Designations whose profile lists this family as tooling.
- UTA-2026-001: Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
- UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
A family name here is the label the linked rule, feed or profile carries, normalised to one spelling by _data/families.yml. Where a report declines to name a family, this page does not either.