GithubHelp home page GithubHelp logo

limelighter's Introduction

LimeLighter

A tool which creates a spoof code signing certificates and sign binaries and DLL files to help evade EDR products and avoid MSS and sock scruitney. LimeLighter can also use valid code signing certificates to sign files. Limelighter can use a fully qualified domain name such as acme.com.

Contributing

LimeLighter was developed in golang.

Make sure that the following are installed on your OS

openssl
osslsigncode

The first step as always is to clone the repo. Before you compile LimeLighter you'll need to install the dependencies. To install them, run following commands:

go get github.com/fatih/color

Then build it

go build Limelighter.go

Usage

./LimeLighter -h       

        .____    .__               .____    .__       .__     __                
        |    |   |__| _____   ____ |    |   |__| ____ |  |___/  |_  ___________ 
        |    |   |  |/     \_/ __ \|    |   |  |/ ___\|  |  \   __\/ __ \_  __ \
        |    |___|  |  Y Y  \  ___/|    |___|  / /_/  >   Y  \  | \  ___/|  | \/
        |_______ \__|__|_|  /\___  >_______ \__\___  /|___|  /__|  \___  >__|   
                \/        \/     \/        \/ /_____/      \/          \/         
                                                        @Tyl0us


[*] A Tool for Code Signing... Real and fake
Usage of ./LimeLighter:
  -Domain string
        Domain you want to create a fake code sign for
  -I string
        Unsiged file name to be signed
  -O string
        Signed file name
  -Password string
        Password for real  certificate
  -Real string
        Path to a valid .pfx certificate file
  -Verify string
        Verifies a file's code sign certificate
  -debug
        Print debug statements

To sign a file you can use the command option Domain to generate a fake code signing certificate.

Signing

to sign a file with a valid code signing certificate use the Real and Password to sign a file with a valid code signing certificate.

To verify a signed file use the verify command.

Verifying WindowsVerifying

limelighter's People

Contributors

tylous avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

limelighter's Issues

cant pull colors

current version of go wont "get" colors, and wont install either. go get or go install.
└─$ /usr/bin/go install github.com/faith/color
go: 'go install' requires a version when current directory is not in a module
Try 'go install github.com/faith/color@latest' to install the latest version
(doesnt work with @latest

Simple Question

Dear Tylous
"cmd.Run() failed with exec: "osslsigncode": executable file not found in %PATH%"

do you have any idea of why am i getting this error? Thanks in advance

failed with exit status 0xffffffff

Hello.
I ran Limelighter and got the following error

cmd.Run() failed with exit status 0xffffffff

I would appreciate it if you know the solution.

#1 SMP Debian 5.15.15-2kali1 (2022-01-31) hava error

└─# ./Limelighter -I 1.exe -O chrome.exe -Domain google.com

    .____    .__               .____    .__       .__     __                
    |    |   |__| _____   ____ |    |   |__| ____ |  |___/  |_  ___________ 
    |    |   |  |/     \_/ __ \|    |   |  |/ ___\|  |  \   __\/ __ \_  __ \
    |    |___|  |  Y Y  \  ___/|    |___|  / /_/  >   Y  \  | \  ___/|  | \/
    |_______ \__|__|_|  /\___  >_______ \__\___  /|___|  /__|  \___  >__|   
            \/        \/     \/        \/ /_____/      \/          \/         
                                                    @Tyl0us

[] A Tool for Code Signing... Real and fake
[
] Signing 2.exe with a fake cert
2022/12/01 02:02:58 cmd.Run() failed with exit status 255

Add release

You could add a release or binary executable file in to make an already compiled version available to all users without having to compile.
This is a suggestion to make it more available to everyone.

Fake certificate

Hello how long will less the fake certificate? will AV's not like that?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.