Cross-platform Electron GUI for the Sliver C2 framework, providing session and beacon dashboards, payload generation, listeners, loot, and cloud deployment management.
Sliver GUI is a cross-platform Electron desktop application for Sliver. It combines backend connections, live status views, dedicated workspaces, and a native Sliver console in a React interface built with HeroUI, HeroUI Pro, and Font Awesome.
The GUI does not implement every upstream command or option. Operator connections use mTLS; WireGuard operator configurations are recognized but cannot connect. See the operator parity report for tracked coverage and the feature documents below for specific boundaries.
The supported versions and locked dependencies are recorded in package.json and package-lock.json. Application code uses strict TypeScript; build helpers use Node.js ES modules.
npm ci --strict-allow-scripts
npx heroui-pro login
npx heroui-pro install --yes
npm run dev
The HeroUI login/install steps are needed for initial workstation setup; they
can be skipped when HEROUI_AUTH_TOKEN is already configured for installation.
Keep credentials out of tracked files.
npm run dev builds and launches the static application at
sliver://app/index.html, using the production content security policy.
Restart the command after source changes; this workflow does not use HMR.
The TypeScript client is installed from the pinned sliver-script npm package.
An adjacent client checkout is not needed. Ordinary application development
does not require a Sliver source checkout; building the native console does.
The default Sliver client root is ~/.sliver-client; SLIVER_CLIENT_ROOT_DIR
can select another root. Application preferences, including Overview graph
options, are saved in gui/application-settings.json; workspace zoom is saved in
gui/workspace-zoom.json, and text editor preferences in
gui/text-editor-settings.json beneath that root. The GUI discovers existing
operator configs in configs/ and updates the
open selector when a valid config is saved there. It saves configs selected
through Import as private file references in gui/operator-configs.json.
Import and Forget do not copy or delete the source configs.
Ghostty-compatible terminal colors are configured in Settings → Terminal and
saved to gui/ghostty/config. Custom themes belong in gui/ghostty/themes/;
installed native Ghostty themes are discovered automatically. See
terminal appearance and Ghostty themes for config
sharing, the Monaco editor, platform transparency support, and runtime limits.
| Command | Purpose |
|---|---|
npm run typecheck | Check the main/preload and renderer TypeScript projects. |
npm test | Run Vitest unit and component tests. |
npm run test:watch | Run Vitest interactively. |
npm run test:e2e:electron | Build and exercise Electron through its renderer, preload, and IPC. |
npm run protocol:check | Verify the pinned client, upstream baseline, and parity artifacts. |
npm run build | Typecheck and build application output in dist/. |
npm run build:console | Build the pinned native Sliver console. |
npm run package | Create an unpacked application under release/. |
npm run dist | Create platform installers under release/. |
npm run test:e2e:packaged | Verify and test an existing unpacked application against a local fixture. |
Unit and component tests live beside source files; Electron scenarios live in
src/e2e/. Actual-server tests are separate, opt-in checks requiring configured
disposable infrastructure. A fixture test does not establish live-server or
installed-package compatibility.
The protocol check uses Go and fetches the pinned upstream source into a temporary directory. See protocol documentation for provenance checks and using an explicitly selected local baseline.
Console and distribution builds require Go 1.27.1 and a clean Sliver checkout
at the commit and tree recorded in
console provenance. Place it in
sliver/ or set SLIVER_SOURCE_DIR. The console build validates the source;
it does not fetch or modify that checkout.
The build disables automatic Go toolchain switching. Put the required Go binary
on PATH or set SLIVER_GO_BINARY to its absolute path. Universal macOS console
builds require macOS and /usr/bin/lipo.
npm run package and npm run dist prepare the native runtime, console, and
license inventory before packaging. Generated output under dist/, release/,
native/sliver-console/, and .e2e-dist/ is ignored by Git.
The CI packaging matrix is:
| Platform | Packages | Automatic updates |
|---|---|---|
| macOS universal | DMG and ZIP | Installed app downloads the ZIP update. |
| Windows x64 | NSIS installer and portable EXE | NSIS installations only; portable builds update manually. |
| Linux x64 | AppImage and DEB | AppImage only; DEB packages update manually. |
Supported packages are configured to check GitHub Releases, download updates in the background, and install on Restart to update or normal application exit. Stable builds do not accept prerelease updates. No GitHub token is embedded in the application.
The initial v0.0.1 release uses persistent self-signed code-signing certificates.
macOS Check for Updates offers the native certificate trust dialog before
the first update check; the app must first be allowed to launch through
Gatekeeper. Windows installations need the public signing certificate trusted
on the destination machine. See self-signed installation and updates
for the trust bootstrap, public fingerprints, and release key policy.
Build targets and minimum-runtime certification are separate. See the platform support ADR for runtime requirements, certification status, and signing/update policy.
The build workflow runs protocol and
parity checks, Electron E2E, and native package jobs. Application jobs need the
HEROUI_AUTH_TOKEN Actions secret; public-fork pull requests run only the
non-secret protocol/parity job. Native jobs test unpacked applications against
a loopback mTLS fixture.