
Cobalt Strike용 다형성 C2 프로필 생성기로, HTTP, DNS 및 프로세스 인젝션을 위한 무작위 옵션으로 탐지를 회피하는 비콘 구성을 자동으로 생성합니다.
SourcePoint는 Go로 작성된 Cobalt Strike C2용 다형성 C2 프로필 생성기입니다. SourcePoint는 즉석에서 고유한 C2 프로필을 생성할 수 있게 해주어 우리의 침해 지표("IoCs")를 줄이는 데 도움을 주며, 운영자가 최소한의 노력으로 복잡한 프로필을 생성할 수 있게 합니다. 이는 핵심 기능과 수정 가능한 기능을 식별하기 위해 문서와 패치 노트를 광범위하게 검토함으로써 이루어졌습니다. SourcePoint는 우리의 C2 활동을 탐지하기 더 어렵게 만드는 문제를 해결하려는 의도로 설계되었으며, 악성 IoC에서 의심스러운 IoC로 이동하는 데 초점을 맞추고 있습니다. 여기서의 목표는 우리의 IoC가 본질적으로 악성이 아니어서 탐지하기 더 어렵게 만들고, 의심스러운 본질을 발견하기 위해 추가 조사가 필요하도록 하는 것입니다. SourcePoint에는 프로필을 수정하기 위해 선택할 수 있는 다양한 구성 옵션이 포함되어 있습니다(대부분의 경우 비워두면 SourcePoint가 무작위로 선택합니다). 생성된 프로필은 C2의 모든 측면을 수정합니다. 이 프로젝트의 목표는 탐지 기반 통제를 우회하는 데 도움을 줄 뿐만 아니라 C2 트래픽과 활동을 환경에 섞이게 하여 해당 활동을 탐지하기 어렵게 만드는 것입니다.
go install github.com/Tylous/SourcePoint
$go get gopkg.in/yaml.v2
$go build SourcePoint.go
#./SourcePoint -h
_____ ____ _ __
/ ___/____ __ _______________ / __ \____ (_)___ / /_
\__ \/ __ \/ / / / ___/ ___/ _ \/ /_/ / __ \/ / __ \/ __/
___/ / /_/ / /_/ / / / /__/ __/ ____/ /_/ / / / / / /_
/____/\____/\__,_/_/ \___/\___/_/ \____/_/_/ /_/\__/
(@Tyl0us)
Usage of ./SourcePoint:
-Allocation string
Minimum amount of memory to request for injected content (must be higher than 4096)
-BeaconGate string
Specify beacon gate options (All, Comms, Core, Cleanup) or specific APIs
-CDN string
CDN cookie name (typically used for AzureEdge profiles)
-CDN-Value string
CDN cookie value (typically used for AzureEdge profiles)
-Customuri string
The base URI for custom HTTP GET/POST profile - Cannot be used with CustomuriGET or CustomuriPOST
-CustomuriGET string
The base URI for custom HTTP GET profile - Must be used with CustomuriPOST
-CustomuriPOST string
The base URI for custom HTTP POST profile - Must be used with CustomuriGET
-Datajitter string
Appends a value to HTTP-Get and HTTP-Post server output (default "50")
-Forwarder
Enabled the X-forwarded-For header (Good for when your C2 is behind a redirector)
-Host string
Team server domain name
-Httplib string
Select the default HTTP Beacon library:
[*] wininet
[*] winhttp' (default "winhttp")
-Injector string
Select the preferred method to allocate memory in the remote process:
[*] VirtualAllocEx (Great for cross architecture i.e x86 -> x64 and x64->x86)
[*] NtMapViewOfSection (A more stealthly option, however fails over to VirtualAllocEx, generating more events when it does)
-Jitter string
Jitter percentage for beacon call home
-Keylogger string
Select the preferred method the beacon will use to log keystrokes:
[*] GetAsyncKeyState (Uses GetAsyncKeyState API (Separate DLL for x86/x64 process))
[*] SetWindowsHookEx (Uses SetWindowsHookEx API)
-Keystore string
SSL keystore name
-Metadata string
Specifies how to transform and embed metadata into the HTTP request:
[*] base64
[*] base64url
[*] netbios
[*] netbiosu (default "base64url")
-Outfile string
Name of output file
-PE_Clone string
PE file beacon will mimic (Use the number):
[1] ActivationManager.dll
[2] audioeng.dll
[3] AzureSettingSyncProvider.dll
[4] BingMaps.dll
[5] DIAGCPL.dll
[6] EDGEHTML.dll
[7] FILEMGMT.dll
[8] FIREWALLCONTROLPANEL.dll
[9] GPSVC.dll
[10] gpupvdev.dll
[11] libcrypto.dll
[12] srvcli.dll
[13] srvsvc.dll
[14] Windows.Storage.Search.dll
[15] Windows.System.Diagnostics.dll
[16] Windows.System.Launcher.dll
[17] Windows.System.SystemManagement.dll
[18] Windows.UI.BioFeedback.dll
[19] Windows.UI.BlockedShutdown.dll
[20] Windows.UI.Core.TextInput.DLL
[21] winsqlite3.dll
[22] WMNetMgr.DLL
[23] wwanapi.dll
[24] WWANSVC.DLL
[25] wow64win.dll
[26] wow64.dll
[27] ctiuser.dll (Carbon Black's DLL)
[28] InProcessClient.dll (SentinelOne's DLL)
[29] umppc.dll (CrowdStrike's DLL)
[30] CyMemDef64.dll (Cylance's DLL)
-Password string
SSL certificate password
-PostEX_Name string
File Post-Ex activities will spawn and inject into (Use the number):
[1] WerFault.exe
[2] WWAHost.exe
[3] choice.exe
[4] bootcfg.exe
[5] w32tm.exe
[6] expand.exe
[7] fsutil.exe
[8] gpupdate.exe
[9] gpresult.exe
[10] logman.exe
[11] mcbuilder.exe
[12] mtstocom.exe
[13] pcaui.exe
[14] powercfg.exe
[15] svchost.exe
-Profile string
HTTP GET/POST profile (Use the number):
[1] Windowsupdate
[2] Slack
[3] Gotomeeting
[4] Outlook.Live
[5] Safebrowsing [Cloudfront Compatible]
[6] AzureEdge [AzureEdge Compatible]
[7] Field-Keyword [Cloudfront Compatible]
[8] Custom (Used with ProfilePath)
-ProfilePath string
Path of custom HTTP GET/POST profile...
-Sleep string
Initial beacon sleep time
-Stage string
Disable host staging (Default: False) (default "false")
-Syscall string
Defines the ability to use direct/indirect system calls instead of the standard Windows API functions calls:
[*] None
[*] Direct
[*] Indirect (default "None")
-TasksDnsProxyMaxSize string
The maximum size (in bytes) of proxy data to transfer via the DNS communication channel at a check in
-TasksMaxSize string
The maximum size (in bytes) of task(s) and proxy data that can be transferred through a communication channel at a check in
-TasksProxyMaxSize string
The maximum size (in bytes) of proxy data to transfer via the communication channel at a check in
-ThreadSpoof
Sets post-ex DLLs to spawn threads with a spoofed start address. These are generated randomly (default true)
-RdllUseDriploading
Enable driploading for RDLL stage (gradually loads beacon in smaller chunks to evade memory scanners) (default true)
-RdllDriploadDelay string
Delay in milliseconds between loading chunks for RDLL driploading (default: random 100-200ms)
-UseDriploading
Enable driploading for process injection (gradually writes payload in smaller chunks to evade EDR) (default true)
-DriploadDelay string
Delay in milliseconds between writing chunks for process injection driploading (default: random 100-200ms)
-CopyPEHeader
Copy PE Header to match cloned DLL characteristics (default false)
-EafBypass
Enable Export Address Filtering (EAF) bypass (default false)
-RdllLoader string
Rdll Loader Options:
[*] PrependLoader (default)
[*] StompLoader (Older method)
-RdllUseSyscalls
Use Syscalls for Rdll operations (default false)
-SmartInject
Enable Smart Inject - uses embedded function pointer hints to bootstrap without walking kernel32 EAT (default false)
-SleepMask
Enable Sleep Mask - obfuscates beacon in memory while sleeping (default true)
-TransformObfuscate string
Transform obfuscate options (comma-separated list):
[*] lznt1
[*] rc4 "64"
[*] xor "32"
[*] base64
Example: "lznt1,rc4 \"64\",xor \"32\",base64"
-CheckinDelay string
Delay in milliseconds before Beacon's initial check-in (CS 4.13+ - breaks event correlation on reflective load)
-ClientMaxPostPostSize string
Maximum size in bytes of POST body (CS 4.13+ - bypass DLP solutions)