Skip to content

Add authenticode_transplant script for PE signature transplantation - #261

Closed
Doug Flick (Flickdm) with Copilot wants to merge 5 commits into
mainfrom
copilot/fix-8ab6bee8-10c8-4dd7-87cb-861e16b625cf
Closed

Doug Flick (Flickdm) with Copilot wants to merge 5 commits into
mainfrom
copilot/fix-8ab6bee8-10c8-4dd7-87cb-861e16b625cf

Conversation

Copilot AI commented Sep 26, 2025 •

Copy link
Copy Markdown
Contributor

This PR implements the authenticode_transplant script requested in issue #XXX, which enables copying Authenticode signatures from one signed PE file to another compatible PE file.

Overview

The script provides a robust solution for transplanting Authenticode signatures between PE files (EFI applications) with comprehensive validation and error handling.

Usage

python scripts/authenticode_transplant.py source.exe target.exe output.exe

Optional flags:

  • --force: Bypass compatibility checks when PE files have different content
  • --debug: Enable detailed logging for troubleshooting

Key Features

PE File Validation: Uses the pefile library to validate that input files are properly formatted PE files before processing.

Binary Compatibility Checking: Compares SHA256 hashes of PE file content (excluding signatures) to ensure the files are compatible for signature transplantation. This prevents invalid transplantations that could result in non-functional binaries.

Signature Extraction: Safely extracts Authenticode signatures from the security directory of source PE files, handling various edge cases like unsigned files or malformed security directories.

Signature Transplantation: Properly updates the PE header's security directory entry and appends the signature data to create a valid signed PE file.

Verification: Confirms successful transplantation by validating the output file structure and signature presence.

Implementation Details

The script follows the existing codebase patterns and standards:

  • Comprehensive error handling with meaningful error messages
  • Structured logging at appropriate levels (INFO, WARNING, ERROR)
  • Full type annotations and docstrings following Google style
  • Passes all linting checks with ruff

Testing

Includes a comprehensive test suite (test_authenticode_transplant.py) covering:

  • Argument parsing validation
  • Error handling for non-existent files
  • Invalid PE file handling
  • Debug flag functionality
  • Help message generation

All existing repository tests continue to pass, ensuring no regressions were introduced.

Security

The implementation has been analyzed with CodeQL and shows 0 security vulnerabilities. The script includes proper input validation and safe file handling practices.

Warning

Firewall rules blocked me from connecting to one or more addresses (expand for details)

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://api.github.com/repos/microsoft/microsoft%2Fsecureboot_objects/languages
    • Triggering command: /home/REDACTED/work/_temp/ghcca-node/node/bin/node --enable-source-maps /home/REDACTED/work/_temp/copilot-developer-action-main/dist/index.js (http block)

If you need me to access, download, or install something from one of these locations, you can either:

Original prompt

This section details on the original issue you should resolve

<issue_title>[Feature]: Script to transplant signature from one signed PE to another signed PE</issue_title>
<issue_description>### Feature Overview

Ideally we would have a script called "authenticode_transplant" that copies the authenticode signature in a PE to another signed PE if the PE's are compatible.

Solution Overview

the script written in python should

  1. take as arguments two signed PEs (EFI applications)
  2. compare the binaries and confirm that they are valid (other than the signature they should be binary compatible)
  3. extract the signature from the first binary
  4. append that signature to the second binary
  5. confirm that the transplant was successful

Alternatives Considered

No response

Urgency

Low

Are you going to implement the feature request?

I will implement the feature

Do you need maintainer feedback?

No maintainer feedback needed

Anything else?

No response</issue_description>

Comments on the Issue (you are Copilot in this section)

Fixes #260

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Co-authored-by: Flickdm <8979761+Flickdm@users.noreply.github.com>
Copilot AI changed the title [WIP] [Feature]: Script to transplant signature from one signed PE to another signed PE Add authenticode_transplant script for PE signature transplantation Sep 26, 2025
@Flickdm
Doug Flick (Flickdm) deleted the copilot/fix-8ab6bee8-10c8-4dd7-87cb-861e16b625cf branch November 14, 2025 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: Script to transplant signature from one signed PE to another signed PE

2 participants