Add authenticode_transplant script for PE signature transplantation - #261
Closed
Doug Flick (Flickdm) with Copilot wants to merge 5 commits into
Closed
Doug Flick (Flickdm) with Copilot wants to merge 5 commits into
Doug Flick (Flickdm) with Copilot wants to merge 5 commits into
Conversation
Co-authored-by: Flickdm <8979761+Flickdm@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] [Feature]: Script to transplant signature from one signed PE to another signed PE
Add authenticode_transplant script for PE signature transplantation
Sep 26, 2025
Doug Flick (Flickdm)
deleted the
copilot/fix-8ab6bee8-10c8-4dd7-87cb-861e16b625cf
branch
November 14, 2025 18:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR implements the
authenticode_transplantscript requested in issue #XXX, which enables copying Authenticode signatures from one signed PE file to another compatible PE file.Overview
The script provides a robust solution for transplanting Authenticode signatures between PE files (EFI applications) with comprehensive validation and error handling.
Usage
Optional flags:
--force: Bypass compatibility checks when PE files have different content--debug: Enable detailed logging for troubleshootingKey Features
PE File Validation: Uses the
pefilelibrary to validate that input files are properly formatted PE files before processing.Binary Compatibility Checking: Compares SHA256 hashes of PE file content (excluding signatures) to ensure the files are compatible for signature transplantation. This prevents invalid transplantations that could result in non-functional binaries.
Signature Extraction: Safely extracts Authenticode signatures from the security directory of source PE files, handling various edge cases like unsigned files or malformed security directories.
Signature Transplantation: Properly updates the PE header's security directory entry and appends the signature data to create a valid signed PE file.
Verification: Confirms successful transplantation by validating the output file structure and signature presence.
Implementation Details
The script follows the existing codebase patterns and standards:
Testing
Includes a comprehensive test suite (
test_authenticode_transplant.py) covering:All existing repository tests continue to pass, ensuring no regressions were introduced.
Security
The implementation has been analyzed with CodeQL and shows 0 security vulnerabilities. The script includes proper input validation and safe file handling practices.
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
https://api.github.com/repos/microsoft/microsoft%2Fsecureboot_objects/languages/home/REDACTED/work/_temp/ghcca-node/node/bin/node --enable-source-maps /home/REDACTED/work/_temp/copilot-developer-action-main/dist/index.js(http block)If you need me to access, download, or install something from one of these locations, you can either:
Original prompt
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.