25 lines
1015 B
YAML
25 lines
1015 B
YAML
id: sliver-c2-jarm
|
|
|
|
info:
|
|
name: Sliver C2 JARM - Detect
|
|
author: pussycat0x
|
|
severity: info
|
|
description: |
|
|
Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys.
|
|
reference:
|
|
- https://github.com/cedowens/C2-JARM
|
|
- https://github.com/BishopFox/sliver
|
|
metadata:
|
|
max-request: 1
|
|
tags: jarm,network,c2,ir,osint,cti,sliver
|
|
tcp:
|
|
- inputs:
|
|
- data: 2E
|
|
type: hex
|
|
host:
|
|
- "{{Hostname}}"
|
|
matchers:
|
|
- type: dsl
|
|
dsl:
|
|
- "jarm(Hostname) == '2ad2ad0002ad2ad00041d2ad2ad41da5207249a18099be84ef3c8811adc883'"
|
|
# digest: 490a00463044022018dacd852adfda29bc10fc93a53311d69334d582250e9a34c4a3a08c217d38b3022036811e74ad505a275a2536fc499738fe00d36634dac662162c4a70d604c9e632:922c64590222798bb761d5b6d8e72950 |