id: sliver-c2-jarm info: name: Sliver C2 JARM - Detect author: pussycat0x severity: info description: | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys. reference: - https://github.com/cedowens/C2-JARM - https://github.com/BishopFox/sliver metadata: max-request: 1 tags: c2,ir,osint,sliver,jarm tcp: - inputs: - data: 2E type: hex host: - "{{Hostname}}" matchers: - type: dsl dsl: - "jarm(Hostname) == '2ad2ad0002ad2ad00041d2ad2ad41da5207249a18099be84ef3c8811adc883'" # digest: 4a0a00473045022100d359b3fae3886dcdd5e1c86b1fe07e1b92dc10fc01043cab87f32fae611e7e5602207f1a90fef828d1489c3e7fa6f2aac19bf0e412ba92c7555789158978059526ed:922c64590222798bb761d5b6d8e72950