{"name":"sliver: Run Cross-Platform Adversary Emulation","description":"Sliver is a Go-based framework for authorized red-team testing, with cross-platform implants and multiple command-and-control options. It is actively maintained and suits teams that need to simulate adversary activity across macOS, Windows, and Linux.","github":"https://github.com/BishopFox/sliver","url":"https://osrepos.com/repo/bishopfox-sliver","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/bishopfox-sliver","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/bishopfox-sliver.md","json":"https://osrepos.com/repo/bishopfox-sliver.json","topics":["security","go","cross-platform","security-tools","red-team","command-and-control"],"keywords":["security","go","cross-platform","security-tools","red-team","command-and-control"],"stars":null,"summary":"Sliver is a Go-based framework for authorized red-team testing, with cross-platform implants and multiple command-and-control options. It is actively maintained and suits teams that need to simulate adversary activity across macOS, Windows, and Linux.","content":"## Overview\n\nSliver is a command-and-control and adversary-emulation framework for organizations conducting authorized security assessments. It helps red teams simulate attacker activity across macOS, Windows, and Linux, with a server and client that also run on those platforms.\n\nTeams can choose from several C2 transports and build implants for engagements. The project is actively developed, with regular commits and releases, and its contributor base is not concentrated in a single person.\n\n## Key Features\n\n- C2 over mutual TLS, WireGuard, HTTP(S), and DNS.\n- Dynamically compiled implants with unique asymmetric encryption keys per binary.\n- Native and shellcode payload support.\n- Userspace reflective loading and built-in shellcode encoding.\n- BOF/COFF execution on amd64 and arm64 across macOS, Windows, and Linux.\n- Cross-platform server and client for macOS, Windows, and Linux.\n\n## Use Cases\n\n- Red teams can run authorized engagements that emulate adversary command-and-control across different operating systems.\n- Security teams can compare how network monitoring responds to mTLS, WireGuard, HTTP(S), and DNS-based C2.\n- Assessment teams can create platform-specific implants and test post-exploitation workflows in controlled environments.\n- Organizations building red-team capability can use the framework alongside its tutorials and documentation to establish an emulation workflow.\n\n## Our Take\n\nSliver is a capable, actively maintained choice for authorized cross-platform red-team work, provided its GPLv3 terms and operational requirements fit your environment.\n\n**Good fit if:**\n- Your team needs multiple C2 transports and implant support for macOS, Windows, and Linux.\n- You want a framework with frequent releases and contributions from a broad contributor base.\n- Your organization can meet GPLv3 obligations and run the Go-based tooling with Docker available where needed.\n\n**Look elsewhere if:**\n- You need a tool intended for defensive monitoring rather than authorized adversary emulation.\n- GPLv3 is incompatible with your distribution or integration requirements.\n- Your target platforms or workflows are not covered by the stated platform and capability support.\n\n## Project Health\n\n| Signal | Value |\n|---|---|\n| Status | **Active**: regular commits and releases |\n| Last commit | 2026-10-10 (today) |\n| Commits, last 90 days | 100+ |\n| Releases, last 12 months | 20 (latest v1.7.8, 2026-10-03) |\n| Contributors | 100+ (top contributor: 56% of commits) |\n| Issues closed, last 90 days | 12+ (typically closed in 23 days) |\n| Pull requests merged, last 90 days | 65 (typically merged in 1 day) |\n| Project age | 7 years |\n\nChecked on 2026-10-11 with the GitHub API.\n\n## Project Facts\n\n- Language: Go\n- License: GPL-3.0\n- Stars: 12.1k\n- Forks: 1.6k\n- Topics: adversarial-attacks, adversary-simulation, c2, command-and-control, dns, dns-server, golang, gplv3\n- Archived: no\n\n## What You Need\n\nDetected in the repository:\n\n- Go 1.27.1 or newer (from go.mod)\n- A Dockerfile, so it can run in a container\n- A test suite and automated checks on GitHub Actions\n\n## Getting Started\n\nThe README provides a Linux installer command:\n\n```sh\ncurl https://sliver.sh/install | sudo bash\nsliver\n```\n\nFor setup guidance and other installation options, see the [README](https://github.com/BishopFox/sliver) and the [Sliver documentation](https://sliver.sh/).\n\n## License in Plain Words\n\n**GPL-3.0** (strong copyleft).\n\n- Commercial use: yes\n- Modify and redistribute: yes\n- You must keep: the license notice\n- Share your changes: yes, the full source of anything you distribute that includes it, under the GPL\n- Includes an explicit patent grant from the contributors\n\nA summary, not legal advice: the LICENSE file is what applies.\n\n## Alternatives\n\n- [caldera](https://osrepos.com/repo/apache-caldera): Caldera centers on ATT&CK-based adversary emulation with a web interface and plugins, while Sliver is a Go-based C2 framework with cross-platform implants.\n\n| Project | Language | License | Stars | Status |\n|---|---|---|---|---|\n| **sliver** | Go | GPL-3.0 | 12.1k | Active |\n| [caldera](https://osrepos.com/repo/apache-caldera) | Python | Apache-2.0 | 7.4k | Active |\n\n## Considerations\n\nSliver is designed for authorized security testing, so teams should scope deployments and control access to the server and implants accordingly. The project is active, with frequent commits and releases; recent issue closures and pull request merges also indicate ongoing maintenance. Its contributors are not concentrated in one person, though the leading contributor accounts for a substantial share of contributions. The project requires Go 1.27.1 and lists Docker as a requirement. GPLv3 applies to Sliver, while some subcomponents may use separate licenses, so review the relevant license files before redistributing or integrating it.","metrics":{"detailViews":2,"githubClicks":0},"dates":{"published":null,"modified":"2026-10-11T15:50:19.000Z"}}