BishopFox

sliver: Run Cross-Platform Adversary Emulation

Sliver is a Go-based framework for authorized red-team testing, with cross-platform implants and multiple command-and-control options. It is actively maintained and suits teams that need to simulate adversary activity across macOS, Windows, and Linux.

Stars
12.1k
Forks
1.6k
Last commit
today
Contributors
100+
Releases, 12 months
20

Our take

Activeregular commits and releases

Health score

66/100

How it is scored
Activity
80
Community
76
Issues
52
Pull requests
57
  • Merges more pull requests than 80% of the projects we track
  • More contributors than 77% of the projects we track
  • Releases more often than 76% of the projects we track

Sliver is a capable, actively maintained choice for authorized cross-platform red-team work, provided its GPLv3 terms and operational requirements fit your environment.

Good fit if

  • Your team needs multiple C2 transports and implant support for macOS, Windows, and Linux.
  • You want a framework with frequent releases and contributions from a broad contributor base.
  • Your organization can meet GPLv3 obligations and run the Go-based tooling with Docker available where needed.

Look elsewhere if

  • You need a tool intended for defensive monitoring rather than authorized adversary emulation.
  • GPLv3 is incompatible with your distribution or integration requirements.
  • Your target platforms or workflows are not covered by the stated platform and capability support.
All health signals
Last commit2026-10-10 (today)
Commits, last 90 days100+
Releases, last 12 months20 (latest v1.7.8, 2026-10-03)
Contributors100+ (top contributor: 56% of commits)
Issues closed, last 90 days12+ (typically closed in 23 days)
Pull requests merged, last 90 days65 (typically merged in 1 day)
Project age7 years

Checked on 2026-10-11 with the GitHub API.

Overview

Sliver is a command-and-control and adversary-emulation framework for organizations conducting authorized security assessments. It helps red teams simulate attacker activity across macOS, Windows, and Linux, with a server and client that also run on those platforms.

Teams can choose from several C2 transports and build implants for engagements. The project is actively developed, with regular commits and releases, and its contributor base is not concentrated in a single person.

Key Features

  • C2 over mutual TLS, WireGuard, HTTP(S), and DNS.
  • Dynamically compiled implants with unique asymmetric encryption keys per binary.
  • Native and shellcode payload support.
  • Userspace reflective loading and built-in shellcode encoding.
  • BOF/COFF execution on amd64 and arm64 across macOS, Windows, and Linux.
  • Cross-platform server and client for macOS, Windows, and Linux.

Use Cases

  • Red teams can run authorized engagements that emulate adversary command-and-control across different operating systems.
  • Security teams can compare how network monitoring responds to mTLS, WireGuard, HTTP(S), and DNS-based C2.
  • Assessment teams can create platform-specific implants and test post-exploitation workflows in controlled environments.
  • Organizations building red-team capability can use the framework alongside its tutorials and documentation to establish an emulation workflow.

What you need

Detected in the repository

  • Go 1.27.1 or newer (from go.mod)
  • A Dockerfile, so it can run in a container
  • A test suite and automated checks on GitHub Actions

License in plain words

GPL-3.0strong copyleft

  • Commercial use: yes
  • Modify and redistribute: yes
  • You must keep: the license notice
  • Share your changes: yes, the full source of anything you distribute that includes it, under the GPL
  • Includes an explicit patent grant from the contributors:

A summary, not legal advice: the LICENSE file is what applies.

Getting Started

The README provides a Linux installer command:

curl https://sliver.sh/install | sudo bash
sliver

For setup guidance and other installation options, see the README and the Sliver documentation.

Alternatives

  • caldera: Caldera centers on ATT&CK-based adversary emulation with a web interface and plugins, while Sliver is a Go-based C2 framework with cross-platform implants.
ProjectLanguageLicenseStarsStatus
sliverGoGPL-3.012.1kActive
calderaPythonApache-2.07.4kActive

Considerations

Sliver is designed for authorized security testing, so teams should scope deployments and control access to the server and implants accordingly. The project is active, with frequent commits and releases; recent issue closures and pull request merges also indicate ongoing maintenance. Its contributors are not concentrated in one person, though the leading contributor accounts for a substantial share of contributions. The project requires Go 1.27.1 and lists Docker as a requirement. GPLv3 applies to Sliver, while some subcomponents may use separate licenses, so review the relevant license files before redistributing or integrating it.

Found this useful?

Share it with someone who would like sliver.