-
Notifications
You must be signed in to change notification settings - Fork 17
Further Reading
Primary sources and inspirations for TrustMeBro.
RFC 5652, Section 5.3 (UnsignedAttributes) https://datatracker.ietf.org/doc/html/rfc5652#section-5.3 Defines unauthenticated attributes in CMS/PKCS#7. These attributes are explicitly not covered by the signer's signature. This is the foundational specification that makes SigStash payload embedding possible.
Matt Graeber, "Subverting Trust in Windows" (SpecterOps) https://specterops.io/wp-content/uploads/sites/3/2022/06/SpecterOps_Subverting_Trust_in_Windows.pdf The original research documenting SIP and Trust Provider hijacking. Maps the full WinVerifyTrust dispatch chain, identifies all registry-controllable function pointers, and demonstrates the DbgUiContinue gadget. TrustMeBro's SIP hijack, FinalPolicy bypass, and sip-exec are direct implementations of concepts from this paper.
CVE-2013-3900 (WinVerifyTrust Signature Validation) https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900 The vulnerability that SigFlip exploits. Windows did not validate content after the PKCS#7 DER blob in the WIN_CERTIFICATE structure. EnableCertPaddingCheck was introduced as an opt-in mitigation. SigStash avoids this by embedding data inside the DER structure, not after it.
SigFlip by med0x2e https://github.com/med0x2e/SigFlip Payload embedding in Authenticode signatures via certificate table padding. Includes SigInject (encrypted shellcode injection) and SigLoader (extraction + execution). TrustMeBro's PKCS#7 approach was directly inspired by SigFlip but operates at a different layer (inside the DER structure vs padding after it).
SignatureKid by David Lee https://github.com/dslee2022/SignatureKid Signature stealing research. The original code that TrustMeBro's signature theft component builds on.
MetaTwin by ThreatExpress https://github.com/threatexpress/metatwin Binary metadata cloning. The concept of transplanting version info, icons, and manifests from a donor PE to a target.
GTSIPProvider by PSBits https://github.com/gtworek/PSBits/tree/master/SIP A reference implementation of a custom SIP provider that logs WinVerifyTrust calls. Demonstrates the CryptSIPDllIsMyFileType2 registration pattern that TrustMeBro's sip-exec feature uses for the execution surface.
Cobalt Strike BOF Documentation https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/beacon-object-files_main.htm Official documentation for Beacon Object Files. The TrustMeBOF implementation follows these conventions.
Adaptix Framework AxScript https://adaptix-framework.gitbook.io/adaptix-framework/development/axscript Scripting documentation for Adaptix C2 extensions. TrustMeBOF includes an AxScript extension for Adaptix.