# Proteus Mythic Payload Type service.
#
# Layout once mythic-cli has installed the folder:
#   /Mythic/main.py
#   /Mythic/proteus/                       <-- Python package
#       __init__.py
#       mythic/                            <-- Mythic SDK glue
#           agent_functions/...
#           builders/...
#       agent_code/                        <-- Rust crates (Docker-only compilation)
#           proteus-agent/                 <-- agent payload
#           loaders/                       <-- self-injecting EXE wrappers
#           layout-manifest/               <-- pre-link COFF analyzer
#           proteus-obf/, proteus-obf-macros/   <-- ChaCha20 obf system
#
# Everything lives inside the `proteus/` package directory, so a single
# `COPY proteus proteus` brings both the Python service code and the Rust
# crates into the image. No external build paths, no cross-repo references.

FROM python:3.11-slim-bookworm

ENV DEBIAN_FRONTEND=noninteractive \
    RUSTUP_HOME=/usr/local/rustup \
    CARGO_HOME=/usr/local/cargo \
    PATH=/usr/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin

# System deps:
#   - mingw-w64 + binutils-mingw-w64 give us x86_64-w64-mingw32-{gcc,ld} that the
#     proteus-agent / loaders linkers shell out to.
#   - python3 is needed at build-time by tools/gen-shuffled-linker.py.
#   - build-essential / curl / ca-certificates are rustup boilerplate.
RUN apt-get update && apt-get install -y --no-install-recommends \
        build-essential \
        ca-certificates \
        curl \
        binutils-mingw-w64 \
        mingw-w64 \
        python3 \
    && rm -rf /var/lib/apt/lists/*

# Pinned nightly so a Mythic redeploy is reproducible — the floating
# `nightly` channel will keep moving as upstream rolls forward.
ARG RUST_NIGHTLY=nightly
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
    | sh -s -- -y --profile minimal --default-toolchain ${RUST_NIGHTLY} \
        -t x86_64-pc-windows-gnu \
    && cargo --version && rustc --version

# cargo-make orchestrates the shuffle pipeline. `--locked` pins to the
# Cargo.lock that ships in the crate; `--no-default-features` drops the
# unused `tls` feature (saves ~1m of build time).
RUN cargo install --locked --no-default-features cargo-make

WORKDIR /Mythic

COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

COPY main.py main.py
COPY proteus proteus

CMD ["python3", "main.py"]
