beacon.exe: custom Go C2 off a client’s compromised server
Pulled beacon.exe off a client’s already-compromised Windows server. The filename begged for Sliver. The pclntab and the C2 URLs said otherwise: a privately built Go implant with HTTPS plus framed TCP, AES-256-GCM, and a full post-ex menu. Not Sliver. Not Cobalt. Not stock Adaptix.