logo

Detecting Sliver C2: When Advanced Beaconing Tries to Hide in Plain Sight by Lucie Cardiet

ID: 36af115c-1bd3-5c82-966a-b437e1e4a7dc

STIX ID: report--36af115c-1bd3-5c82-966a-b437e1e4a7dc

Feed Name: Vectra AI Blog

Threat Score
70/100

Date Published: 2026-03-23

Date Updated: 2026-05-01

...
...

The report analyzes Sliver, an open-source post-exploitation command-and-control framework increasingly abused by attackers; it details how Sliver's procedural data jitter and encoder rotation obfuscate beaconing patterns (making traditional timing- and size-based detection ineffective), cites observed use following exploits such as React2Shell and campaigns targeting FortiWeb appliances, and recommends behavioral, telemetry-driven detection methods to identify command-and-control activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.