Skip to content

Tool Map

Kriyos Arcane edited this page Jul 4, 2026 · 1 revision

Tool Map

Tool What it does When to use it Privilege
TrustMeBro.exe (C++) Signature stealing, SIP hijack, FinalPolicy bypass, PKCS#7 embed/extract, sip-exec, probe, clean On the target Windows machine. All operations except remote hijack. Admin for registry writes. None for probe, steal, embed, extract.
TrustMeBro.py (Python) Same capabilities as C++, plus remote hijack via Impacket From Linux attacking machine. Remote registry ops over SMB. Local mode with --local on Windows. Admin on target for registry writes. None for steal, embed, extract.
SigStashLoader.exe Extract payload from a carrier PE's PKCS#7 signature On target. You have a carrier PE and want to retrieve the embedded payload. None
SigStashStub.exe Self-extracting variant. Reads its own PE and dumps the payload to disk. Single-binary delivery. Sign the stub, embed payload, drop on target. No arguments needed. None
SigStashStubCamo.exe Same as stub, camouflage mode. Reads from SPC_NESTED_SIGNATURE wrapper. When the payload was embedded with --camouflage. None
FormatGhost (tools/FormatGhost/) Registers a DLL as a CryptDllFormatObject handler for a custom OID. Analyst-triggered persistence. DLL loads when certutil or cert UI parses the carrier. Admin for registry write. User interaction to trigger.
Publisher Spoof (experimental/publisher-spoof/) Generates a self-signed cert with a chosen Common Name. Research. Combine with FinalPolicy hijack to control the publisher name in UAC dialogs. Admin to enroll cert.
Dual-SignerInfo (experimental/dual-signerinfo/) Documentation on kernel vs user-mode SignerInfo parser divergence. Research only. No code. N/A
TrustMeBOF (separate repo) 8 Beacon Object Files for Cobalt Strike and Adaptix C2. In-beacon execution. Same operations as the C++ tool but runs inside the beacon process. Admin for registry writes. None for probe.

Clone this wiki locally