ASSET InterTech – SourcePoint JTAG Debug & Trace Tools

ASSET InterTech is a US-based provider of embedded system validation and debug solutions, serving aerospace & defense, medical device, telecom, enterprise PCB and manufacturing companies since the 1990s. Its SourcePoint™ debugger gives firmware and BIOS engineers JTAG hardware-assisted, source-level visibility into Intel, AMD and Arm-based systems — starting from cold reset, before an operating system or even working RAM exists — and was the first tool on the market to offer Intel® UEFI debug.

What Is ASSET InterTech?

ASSET InterTech builds two complementary product lines for hardware bring-up and production test: ScanWorks®, a JTAG/boundary-scan structural test platform used in R&D, repair and manufacturing, and SourcePoint™, a source-level processor debugger built around Arium run-control probes and trace port analyzers. Pertech supplies and supports the SourcePoint line for customers in Israel.

SourcePoint — JTAG Source-Level Debug for Intel, AMD & Arm

SourcePoint connects to the target over JTAG (including Intel's Direct Connect Interface) and gives developers a real-time, source-level debug interface that works straight out of reset — before BIOS, a bootloader or an OS has initialized anything. It covers the processors most embedded and platform teams actually ship on:

  • Intel Core, Xeon and Atom SoC processors, including current generations with Intel Processor Trace (IPT) and Trace Hub support
  • AMD EPYC server CPUs, with run-control and UEFI source-level debug
  • Arm multi-core, multi-thread SoCs, with CoreSight trace macrocell integration

On the host side, SourcePoint reads C/C++ source, symbol and mixed (source+assembly) views, and understands .elf, .hex, .sym and .bin images as well as Windows .exe/.dll/.efi (PE format) binaries. It is Linux OS-aware, with kernel and insmod debug, supports multi-processor and multi-cluster targets, and is scriptable through both a C-like command language and Python — so routine bring-up sequences, register checks or regression scenarios can be automated instead of clicked through by hand.

UEFI & BIOS Debug at the Source Level

SourcePoint was the first tool to offer Intel UEFI debug, and it still leads on depth of platform-firmware support. It debugs Framework-for-UEFI platforms natively — PEI, DXE and later EFI phases — with breakpoints, single-step, variable inspection and call-stack views available throughout, plus UEFI-aware code navigation with macro support. That makes it equally useful for:

  • BIOS/UEFI bring-up on new silicon or new board designs
  • Board support package and low-level device driver debug
  • RTOS and diagnostics debug below the operating-system layer
  • Windows kernel driver and hypervisor-managed debug over JTAG, including modern hardware security features such as VT-rp and HLAT

SourcePoint also supports Intel Customer Scripts (CScripts) — Python-based scripts, provided directly by Intel under NDA, that exercise silicon-specific and platform debug, error-analysis and error-injection features from inside SourcePoint's own Python command-line interface. ASSET maintains a dedicated resource to verify each new Intel CScript release against the current SourcePoint build.

Why SourcePoint Matters for Firmware & Hardware Security Gap Analysis

Security gap analysis means comparing what a system is supposed to enforce — a requirement, a compliance control, a threat-model assumption — against what it actually does at runtime. For platform firmware, that comparison usually breaks down exactly where conventional software-security tooling stops working: before the OS boots, inside System Management Mode, or inside a hypervisor's protected state. SourcePoint's JTAG hardware debug and real-time trace let an engineer observe that runtime behavior directly, silicon-side, which is what turns a paper security review into evidence-based gap analysis. Engineers use it to identify:

  • Root-of-trust / secure boot gaps — stepping through the boot chain from cold reset (PEI → DXE → OS loader) to confirm each stage actually validates the signature of the next before executing it, rather than assuming the documentation is accurate. A missing or bypassable check at any one stage breaks the whole chain of trust.
  • Unauthorized or unaudited SMM code — System Management Mode runs invisibly to the OS and any OS-resident security agent, making it a favored target for firmware rootkits. SourcePoint's dedicated SMM entry/exit breakpoints let an engineer catch and inspect every transition into SMM, confirming only expected handlers run there.
  • Debug-interface exposure left in production — an unlocked or unfused JTAG/DCI port is itself a well-documented attack surface, used for cold-boot key extraction, memory dumping or bypassing secure boot. Because SourcePoint connects over that same JTAG/DCI path, it is also the most direct way to confirm the path is actually disabled or access-controlled before a unit ships.
  • Memory-protection and mitigation gaps — verifying that hardware security features such as VT-rp and HLAT are actually enforced at runtime rather than merely enabled in a configuration register, by triggering the fault conditions they are meant to catch and confirming the processor traps as designed.
  • Out-of-bounds and memory-corruption conditions below the OS — bootloader, BSP and early-driver code rarely has the memory-safety tooling application code gets; SourcePoint's breakpoint-on-data-value and watch capabilities let an engineer catch an out-of-bounds write or use of uninitialized memory at the exact instruction that caused it, in code with no OS underneath yet to catch the fault another way.
  • Divergence between documented and actual platform behavior — execution trace (including Intel Processor Trace / AET) gives a complete, cycle-accurate record of what the firmware actually executed on a given run, which is the evidence a compliance or certification gap analysis needs when a design review's assumptions have to be checked against silicon, not just against source.

In short: SourcePoint doesn't replace static analysis, code review or fuzzing — it fills the gap those methods can't reach, because it observes the platform at the one layer (JTAG, pre-OS, SMM, hardware trace) where a firmware security assumption either holds up against real hardware or it doesn't.

Real-Time Trace & Run-Control

Being able to step through code is only half the picture — SourcePoint's trace window adds cycle-accurate, time-stamped execution history, and its trace search tool turns that raw trace into a call tree with inclusive/exclusive timing per function, so a performance or intermittent-failure investigation starts from "where is the time actually going" rather than a blind single-step session.

Run-control is built around familiar go/halt/step semantics, extended by SourcePoint's own C-like command language (loops, data and array variables, file I/O) so multi-step debug sequences can be scripted rather than repeated by hand. Breakpoints — hardware (up to 32 debug registers, depending on processor) and unlimited software — can be set from the Code window or the command line, alongside:

  • SMM entry/exit, reset and interrupt-acknowledge breaks
  • External trigger in/out pins
  • Special transition breaks (shutdown, flush)
  • Three-level complex events, including breaking on specific data values

Symbols, Registers, Memory, PCI Devices and user-defined Watch windows expose live processor state, with independent views per core in multi-processor targets — plus a user-defined window for grouping memory-mapped I/O devices and their registers, so a chip's control-plane state stays in one place instead of scattered across several windows.

Arium Probes & Trace Port Analyzers

Arium ECM-XDP3e JTAG debug probe by ASSET InterTech

The Arium ECM-XDP3e — the JTAG run-control probe SourcePoint connects through via the Intel XDP interface.

SourcePoint for Intel is designed around ASSET's own Arium run-control probes and trace port analyzers:

  • ECM-XDP3 — full run-control via the Intel XDP connector, USB 1.1/2.0 and 10/100/GbE host connections, target power-state change detection, and a built-in self-diagnostic test suite (does not support AET trace)
  • LX-1000 for Intel — records AET (Architectural Event Trace) data over the XDP-OBS pins into a 2GB trace buffer, over USB 1.1/2.0 or 10/100/GbE

Together the probes cover real, virtual-86, big-real, protected and system-management-mode (SMM) address translation, and a full register set — 386, system, control, debug, MSRs, floating point, MMX and SSE. Source and symbolic debug formats include boot-loadable OMF-386, DWARF2, Intel Textsym, CodeView and a.out/Stabs, and downloadable image formats span BIN, OMF-386, ELF32, DOS EXE, Intel Hex and PE32/PE32+.

Key Specifications

Target processorsIntel Core / Xeon / Atom SoC, AMD EPYC, Arm multi-core/multi-thread SoCs
ConnectionJTAG via Arium ECM-XDP3 or LX-1000 probes; Intel Direct Connect Interface (DCI)
UEFI/BIOS debugSource-level debug of PEI, DXE and EFI phases; Intel CScripts (Python CLI) support
TraceCycle-accurate execution trace, Intel Processor Trace (IPT), AET (LX-1000), Arm CoreSight
Command languagesC-like scripting language, Python
Host OSWindows 7/8+ (32/64-bit), Linux (Ubuntu, CentOS and other modern distributions)
File formatsELF32, OMF-386, BIN, Intel Hex, DOS EXE, PE32/PE32+, DWARF2, CodeView, a.out/Stabs

Who Uses SourcePoint

  • Aerospace & defense teams needing certifiable, reproducible low-level debug and documentation
  • Medical device manufacturers debugging firmware and BSPs under regulatory scrutiny
  • Telecom equipment vendors bringing up new Intel/AMD/Arm-based platforms
  • Enterprise PCB and systems teams doing board bring-up, BIOS/UEFI porting and driver debug
  • Manufacturing and production-test engineers isolating faults on the line

Why Get SourcePoint Through Pertech

Pertech supplies and supports ASSET InterTech's SourcePoint debug tools for customers in Israel — evaluation, licensing, onboarding and ongoing local technical support, alongside the rest of Pertech's embedded development and test-and-measurement lines. Contact us to scope which SourcePoint configuration and Arium probe fit your target processor and debug workflow.

Frequently Asked Questions

What's the difference between SourcePoint and a plain JTAG debugger?

Most JTAG debuggers only support run control (halt, step, breakpoints) at the register/assembly level once an OS or simple monitor is running. SourcePoint adds source-level C/C++ debug, native UEFI/BIOS debug from cold reset before any OS exists, cycle-accurate execution trace, and a scriptable C-like/Python command interface — so it covers platform bring-up as well as later-stage software debug.

Does SourcePoint support UEFI and BIOS debug, or only OS-level debug?

UEFI/BIOS debug is one of SourcePoint's core strengths — it was the first tool to offer Intel UEFI debug and provides native source-level debug of the PEI, DXE and EFI phases of Framework-for-UEFI platforms, including breakpoints, single-step, variable inspection and call-stack views during boot.

Which processor architectures does SourcePoint support?

SourcePoint for Intel covers Intel Core, Xeon and Atom SoC processors; SourcePoint also supports AMD EPYC server CPUs and Arm multi-core/multi-thread SoCs with CoreSight trace, connecting over JTAG through ASSET's Arium ECM-XDP3 or LX-1000 probes.

© 2025 Pertech Embedded Solutions Ltd. All rights reserved. By using this website you acknowledge and agree to our data practices. Personal information collected is used solely for providing sales, licensing, and technical support services. We do not sell personal data to third parties. View our full Privacy Policy.

upbtn
Skip to content