SourcePoint

SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.

Stars
1K
Committers
5

Bot releases are hidden (Show)

SourcePoint - v3.2 Latest Release

Published by Tylous 11 months ago

Bug Fix

  • Fixed issue with one of the Magic_MZ options
  • Fixed syscall_method printout display
  • Fixed Post-Ex PE name generation array
SourcePoint - v3.1

Published by Tylous 11 months ago

Bug Fix

  • Fixed issue random value generator for Magic_PE values
  • Fixed syscall_method syntax
SourcePoint - v3.0

Published by Tylous 11 months ago

New Features

  • Added direct and indirect Syscall methods.
  • Added support for different HTTP beacon Libraries.
  • Created a dynamic set of Magic_MZ header values to help avoid any detection rules looking for MZ in the PE header.
  • Created a dynamic function to generate unique Magic_PE header values.
  • Added Thread spoofing.
  • Created a unique thread-spoofing list of 9 of the most common Windows base thread modules along with a random number generator to ensure each base address spoofed is unique.
  • Updated the Pipe list to ones that are no longer linked to any IOCs.
  • Updated PE_Clone options and values to reflect the latest versions with the most recent version of Windows.
  • Stripped out IOCs related to Bofs and in-memory execution.
  • Added triggers for Post-ex UDRL cleanup.

Bug Fix

  • Fixed path issue with some post-ex processes
  • Fixed strepp for powerpick
SourcePoint - v2.4

Published by Tylous about 2 years ago

Shout out to hsfetty for helping with this

Bug Fixes


  • Fixed indexing error for PE Name
SourcePoint - v2.3

Published by Tylous over 2 years ago

Shout out to Nahid5 for helping with this

New Features


  • Added support for all the new features of Cobalt Strike 4.6

Bug Fixes


  • Fixed some missing HTTPS-certificate
  • Update the README
SourcePoint - v2.2

Published by Tylous over 2 years ago

Huge shout out to Xenov-X for helping with these new features

New Features


  • Added customuriGET and customuriPOST arguments
  • Made valid SSL optional for custom profiles
  • Added support for custom user agent

Bug Fixes


  • Fixed some missing quotes in Peclone_list
  • Fixed numerous errors with Custom Profiles
  • Fixed missing quotes on struct variable
  • Fixed issue with Spawnto option "pcaui.exe"
  • Update the README
SourcePoint - v2.1

Published by Tylous over 2 years ago

Bug Fixes


  • Fixed URI issue with Profile 7.
  • Fixed Stage Flag issue.
SourcePoint - 2.0

Published by Tylous about 3 years ago

New Features


  • Added Field-Keyword profile.
  • Updated Safebrowing URI profile to be more uniquely generated.
  • Added more random values for each profile.
  • Added 4 new DLL for spoofing.
  • Added more Verbose messages related to the profile generated.

Bug Fixes


  • Fixed HTTP-Forwarder header issue with Profile 4.
SourcePoint - v1.3.1

Published by Tylous about 3 years ago

Bug Fixes


  • Fixed typo with PE Clone option audioeng.dll.
SourcePoint - v1.3

Published by Tylous about 3 years ago

New Feature


  • Added option to allow X-Forwarded-For HTTP header.

Bug Fixes


  • Fixed issue with go get.
  • Fixed issue with URI's missing / when no profile is specified.
  • Fixed issue with cross-architecture with Strrep.
SourcePoint - v1.2

Published by Tylous about 3 years ago

Bug Fixes


  • Fixed error generating values for the profile’s HTTP max-age.
  • Fixed issue with SSL CN value when the operator doesn’t specify a profile.
  • Fixed padding on certain subsections.
  • Fixed issue when host_staged is set to “true”.
SourcePoint - v1.1

Published by Tylous about 3 years ago

Changelog

9bad7dc deleted: .DS_Store
b14ded7 Fix incorrect array reference
d135047 Merge pull request #3 from Xenov-X/main
956bdc0 Updated Loader
68ae124 v1.0

SourcePoint - v1.0

Published by Tylous about 3 years ago

Changelog

9bad7dc deleted: .DS_Store
991b594 Initial commit
f88be6c Update .gitignore
68ae124 v1.0