Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Limelighter - A Tool For Generating Fake Code Signing Certificates Or Signing Real Ones
http://www.kitploit.com/2021/10/limelighter-tool-for-generating-fake.html
A tool which creates a spoof code signing certificates (https://www.kitploit.com/search/label/Certificates) and sign (https://www.kitploit.com/search/label/Sign) binaries and DLL (https://www.kitploit.com/search/label/DLL) files to help evade EDR (https://www.kitploit.com/search/label/EDR) products and avoid MSS and sock scruitney. LimeLighter can also use valid code signing certificates to sign files. Limelighter can use a fully qualified domain name such as acme.com.
Contributing
LimeLighter was developed in golang.Make sure that the following are installed on your OSopenssl
osslsigncode
The first step as always is to clone the repo. Before you compile LimeLighter you'll need to install the dependencies. To install them, run following commands:go get github.com/fatih/color
Then build itgo build Limelighter.go

Usage
Y \ | \ ___/| | \/ |_______ \__|__|_| /\___ >_______ \__\___ /|___| /__| \___ >__| \/ \/ \/ \/ /_____/ \/ \/ @Tyl0us [*] A Tool for Code Signing... Real and fake Usage of ./LimeLighter: -Domain string Domain you want to create a fake code sign for -I string Unsiged file name to be signed -O string Signed file name -Password string Password for real certificate -Real string Path to a valid .pfx certificate file -Verify string Verifies a file's code sign certificate -debug Print debug statements ">./LimeLighter -h

.____ .__ .____ .__ .__ __
| | |__| _____ ____ | | |__| ____ | |___/ |_ ___________
| | | |/ \_/ __ \| | | |/ ___\| | \ __\/ __ \_ __ \
| |___| | Y Y \ ___/| |___| / /_/ > Y \ | \ ___/| | \/
|_______ \__|__|_| /\___ >_______ \__\___ /|___| /__| \___ >__|
\/ \/ \/ \/ /_____/ \/ \/
@Tyl0us


[*] A Tool for Code Signing... Real and fake
Usage of ./LimeLighter:
-Domain string
Domain you want to create a fake code sign for
-I string
Unsiged file name to be signed
-O string
Signed file name
-Password string
Password for real certificate
-Real string
Path to a valid .pfx certificate file
-Verify string
Verifies a file's code sign certificate
-debug
Print debug statements

To sign a file you can use the command option Domain to generate a fake code signing certificate.
 to sign a file with a valid code signing certificate use the Real and Password to sign a file with a valid code signing certificate.To verify a signed file use the verify command.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Limelighter - A Tool For Generating Fake Code Signing Certificates Or Signing Real Ones

https://blogger.googleusercontent.com/img/a/AVvXsEjZj9xeUnx46TGfKrmMQjeqc1CsFDbPT7g9XnhXw5NdUAtj3kk3-0Yz8mWOxpzmQXcbyp4Y7jUPCQXdhb4a82Gc7DJbhHgnj8c9Dp8p5y-f-7BdJuoEq4pJuroraGwD89f9xdb8PxTPRipw7XfnpD4Gvt6nXokj06FfxU3gg-5mGZHV96COi0VQ_ORV2Q=w640-h284 A tool which creates a spoof code signing certificates and sign binaries and DLL files to help evade EDR products and avoid MSS and sock scruitney. LimeLighter can also use valid code signing certificates to sign files. Limelighter can use a fully qualified domain name such as acme.com. ContributingLimeLighter was developed in golang.

Make sure that the following are installed on your OS openssl
osslsigncode
The first step as always is to clone the repo. Before you compile LimeLighter you'll need to install the dependencies. To install them, run following commands: go get github.com/fatih/color Then build it go build Limelighter.go Usage./LimeLighter -h

.____ .__ .____ .__ .__ __
| | |__| _____ ____ | | |__| ____ | |___/ |_ ___________
| | | |/ \_/ __ \| | | |/ ___\| | \ __\/ __ \_ __ \
| |___| | Y Y \ ___/| |___| / /_/ > Y \ | \ ___/| | \/
|_______ \__|__|_| /\___ >_______ \__\___ /|___| /__| \___ >__|
\/ \/ \/ \/ /_____/ \/ \/
@Tyl0us
[*] A Tool for Code Signing... Real and fake
Usage of ./LimeLighter:
-Domain string
Domain you want to create a fake code sign for
-I string
Unsiged file name to be signed
-O string
Signed file name
-Password string
Password for real certificate
-Real string
Path to a valid .pfx certificate file
-Verify string
Verifies a file's code sign certificate
-debug
Print debug statements
To sign a file you can use the command option Domainto generate a fake code signing certificate. https://blogger.googleusercontent.com/img/a/AVvXsEjZj9xeUnx46TGfKrmMQjeqc1CsFDbPT7g9XnhXw5NdUAtj3kk3-0Yz8mWOxpzmQXcbyp4Y7jUPCQXdhb4a82Gc7DJbhHgnj8c9Dp8p5y-f-7BdJuoEq4pJuroraGwD89f9xdb8PxTPRipw7XfnpD4Gvt6nXokj06FfxU3gg-5mGZHV96COi0VQ_ORV2Q=w640-h284 to sign a file with a valid code signing certificate use the Realand Passwordto sign a file with a valid code signing certificate.

To verify a signed file use the verifycommand. https://blogger.googleusercontent.com/img/a/AVvXsEh0HJyn7Z_AX48HYyMfR-0tudMiW2Cw1EGRgYH8GSOKtEB68nBjgxPDIttgHaTtNDUHOTIpvXWfo2FZsHl9lpMzqfvefZbvltn3ayYISFDeGnblIeEOgyT0h4qRd2KWXJjiMFVw759X96cE2b4Fqt5gnLJaw6Dahs9RGfgViS_UAB1Zd6CHfwA3YGOR5A=w640-h604 https://blogger.googleusercontent.com/img/a/AVvXsEhYlVHZrvL7TfxT1GLOxuRqsd-t5oHiRgtvQtdjw3XFMK1E-r3N8jtltsAByZ64NDxH_7A-Q0lqIwI8hP3uP4c6S7yTEqOYvnGhh_fUi-vwuRyTkLnL5D9nG8BqUxwEwnFfE6nYxZe-AD_bStdcmnAHa-szyaT4T8Xs--5qPSNj9Wc-Vm3Y7FIOpdpiVg=w510-h640 Download Limelighter
Warp V2 Bug Bounty Program with Immunefi

Warp Finance is ensuring the security of its V2 test launch through a bug bounty. This bug bounty program will be hosted by Immunefi, and…Continue reading on Medium »
Read more...