Files
nuclei-templates/ssl/c2/sliver-c2.yaml
Dhiyaneshwaran 2e063c3809 fix missing -
2025-10-31 13:11:58 +08:00

34 lines
1.1 KiB
YAML

id: sliver-c2
info:
name: Sliver C2 - Detect
author: johnk3r
severity: info
description: |
Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants (slivers) that can run on virtually every architecture out there, and securely manage these connections through a central server
reference:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.sliver
metadata:
verified: "true"
max-request: 1
shodan-query: product:"Sliver C2"
tags: c2,ssl,ir,osint,malware,sliver,tls,discovery
ssl:
- address: "{{Host}}:{{Port}}"
matchers-condition: and
matchers:
- type: word
part: issuer_cn
words:
- "operators"
- type: word
part: subject_dn
words:
- "CN=multiplayer"
extractors:
- type: json
json:
- " .issuer_cn"
# digest: 490a004630440220150fef5d8b8bc8f65dc405498ab2c954f44d30d523f30ecb0551cb4f253434df02204d5dffca32e3171f3a3baed94e57e2ff4f216652dc0086b55575622e54b3a207:922c64590222798bb761d5b6d8e72950