WHY DID THREAT ACTORS REPLACE POSHC2 WITH SLIVERC2? COMPARISON OF TWO GREAT C2 FRAMEWORKS.
DOI:
https://doi.org/10.68302/std2026.vol3.212Keywords:
Adversarial tradecraft, command-and-control frameworks, cyber operations, infrastructure paradigms, post-exploitationAbstract
This paper presents a comparative analysis of the command-and-control (C2) frameworks PoshC2 and SliverC2, examined within the context of evolving adversarial tradecraft, shifting infrastructure paradigms and the increasing maturity of defensive capabilities. While C2 frameworks are traditionally associated with the post-exploitation phase, this study adopts a broader perspective, arguing that framework selection reflects not only tactical requirements but also strategic and operational adaptations to a rapidly changing cyber environment. The analysis is based on the recent transformations in enterprise infrastructure, notably the transition from predominantly on-premises, Active Directory-centric Windows environments to complex, distributed, and hybrid cloud ecosystems. This evolution, combined with the expanded attack surfaces across critical sectors, has imposed new constraints on adversary operations. In parallel, defensive practices have become increasingly proactive and intelligence-driven, with widespread adoption of EDR, XDR and SIEM solutions. These developments have contributed to a significant reduction in attacker dwell time and increased detection of well-established tools, techniques, and procedures (TTPs). Within this context, the paper contrasts the architectural and operational characteristics of PoshC2 and SliverC2. PoshC2 is a mature, PowerShell-centric framework optimized for Windows environments, offering extensive post-exploitation functionality but exhibiting increased detectability due to its reliance on heavily monitored technologies. In contrast, SliverC2 represents a modern, Golang-based, cross-platform approach, emphasizing dynamic payload generation, modular extensibility, and advanced communication protocols. The findings of this paper indicate that the shift from PoshC2 to SliverC2 reflects adaptive adversary behavior driven by environmental complexity and defensive pressure, rather than a simple tool substitution. Contemporary offensive operations are inherently multi-framework, with tooling selected dynamically based on operational requirements and target characteristics.
Downloads
References
[1] S. Snape, “Introducing PoshC2 v8.0,” LRQA Cyber Labs, 2022. [Online]. Available: https://www.lrqa.com/en/cyber-labs/introducing-poshc2-v8-0/. [Accessed: March 29, 2026].
[2] Bishop Fox, “Sliver: A cross-platform adversary emulation framework,” GitHub, 2023. [Online]. Available: https://github.com/BishopFox/sliver. [Accessed: March 30, 2026]..
[3] Microsoft, “How AMSI helps (Antimalware Scan Interface),” Microsoft Learn, 2023. [Online]. Available: https://learn.microsoft.com/en-us/windows/win32/amsi/how-amsi-helps. [Accessed: Apr. 04, 2026].
[4] Microsoft, “PowerShell security features: Logging and transcription,” Microsoft Learn, 2023. [Online]. Available: https://learn.microsoft.com/en-us/powershell/scripting/security/security-features. [Accessed: Apr. 02, 2026].
[5] D. Bianco, “The pyramid of pain,” Enterprise Detection & Response, Mar. 2013. [Online]. Available: https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html. [Accessed: Apr. 02, 2026].
[6] Kaspersky, “Vulnerability landscape in Q4 2025,” Securelist, Mar. 2026. [Online]. Available: https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/. [Accessed: March 29, 2026].
[7] The DFIR Report, “Threat actors’ toolkit: Leveraging Sliver, PoshC2 & batch scripts,” The DFIR Report, Aug. 2024. [Online]. Available: https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/. [Accessed: Apr. 05, 2026].
[8] The MITRE Corporation, “MITRE ATT&CK,” MITRE ATT&CK, 2025. [Online]. Available: https://attack.mitre.org/. [Accessed: Apr. 02, 2026].
[9] Fraunhofer FKIE, “APT29 - Threat actor profile,” Malpedia, 2024. [Online]. Available: https://malpedia.caad.fkie.fraunhofer.de/actor/apt29. [Accessed: Apr. 05, 2026].
[10] Kaspersky, “Vulnerability landscape analysis for Q2 2025,” Securelist, Aug. 2025. [Online]. Available: https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/. [Accessed: Apr. 05, 2026].
[11] Kaspersky, “Analyzing the vulnerability landscape in Q3 2025,” Securelist, 2026. [Online]. Available: https://securelist.com/vulnerabilities-and-exploits-in-q3-2025/118197/. [Accessed: Apr. 06, 2026].
[12] Mandiant, “M-Trends 2025: Data, insights, and recommendations from the frontlines,” Google Cloud Threat Intelligence, Apr. 2025. [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2025. [Accessed: March 30, 2026].
[13] Help Net Security, “Attackers are handing off access in 22 seconds, Mandiant finds (M-Trends 2026),” Help Net Security, Mar. 2026. [Online]. Available: https://www.helpnetsecurity.com/2026/03/24/mandiant-m-trends-2026-report/. [Accessed: Apr. 05, 2026].
[14] Red Canary, “C2 frameworks,” Red Canary Threat Detection Report, 2025. [Online]. Available: https://redcanary.com/threat-detection-report/trends/c2-frameworks/. [Accessed: Apr. 05, 2026].
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Dimitar Nikolov

This work is licensed under a Creative Commons Attribution 4.0 International License.