Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for Sliver C2 #220

Open
hypnoticpattern opened this issue Jan 12, 2022 · 3 comments
Open

Support for Sliver C2 #220

hypnoticpattern opened this issue Jan 12, 2022 · 3 comments
Labels
c2servers Related to RedELK C2 server components enhancement New feature or request

Comments

@hypnoticpattern
Copy link

Add support for ingesting Sliver logs into RedElk. The Audit Logs are in nested-JSON format designed to be primarily machine readable.

@MarcOverIP
Copy link
Member

Thanks for brining this to our attention. We are limited in time so I don't see us picking this up in the very near future. Happy to help you though with questions if you decide to start with this yourself!

There is a walkthrough on adding a new C2 framework to RedELK on the wiki: https://github.com/outflanknl/RedELK/wiki/Red-team-tooling-support#adding-support-for-other-c2-frameworks

@MarcOverIP MarcOverIP added enhancement New feature or request c2servers Related to RedELK C2 server components labels Jan 13, 2022
@runesage
Copy link

runesage commented Aug 6, 2023

Has there been any progress on this? Was curious about leveraging this as a part of a red vs blue exercise since sliver is the more popular tooling for the event.

@MarcOverIP
Copy link
Member

Dev is ongoing and tracked in #267

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c2servers Related to RedELK C2 server components enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants