[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3Rey44FXCobbk-sp_mXFp74GIo3wCyy3CEvTxUF1BoY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},427,"Which tools can verify CAT file digital signatures, and why might Get-AuthenticodeSignature fail?","`signtool.exe` and `sigcheck.exe` can verify CAT signatures, while PowerShell’s `Get-AuthenticodeSignature` may fail on Windows 7 because it does not natively support catalog queries. On Windows 10, `Get-AuthenticodeSignature` retrieves CAT signatures. For example, using `signtool.exe verify \u002Fpa \u002Fa C:\\Windows\\System32\\xwizard.exe` shows the catalog-signed status, whereas `Get-AuthenticodeSignature` might return an unsigned result on older systems.","\u003Cp>`signtool.exe` and `sigcheck.exe` can verify CAT signatures, while PowerShell’s `Get-AuthenticodeSignature` may fail on Windows 7 because it does not natively support catalog queries. On Windows 10, `Get-AuthenticodeSignature` retrieves CAT signatures. For example, using `signtool.exe verify \u002Fpa \u002Fa C:\\Windows\\System32\\xwizard.exe` shows the catalog-signed status, whereas `Get-AuthenticodeSignature` might return an unsigned result on older systems.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fcat-file-digital-signature-usage-techniques\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","which-tools-can-verify-cat-file-digital-signatures-and-why-might-get-authenticod-1777483931330","signtool, sigcheck, Get-AuthenticodeSignature, CAT signature verification, Windows 7, Windows 10",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},107,"CAT File Digital Signature Usage Techniques","cat-file-digital-signature-usage-techniques","Learn CAT file digital signature techniques, Authenticode methods, and how to prevent file tampering in Windows systems with step-by-step guides.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Important files in Windows systems are often digitally signed to prevent tampering, and some whitelist rule determinations are also based on digital signatures.\u003C\u002Fp>\u003Cp>As foundational content for the digital signature research series, this article introduces two methods for adding digital signatures, analyzes the characteristics of CAT file digital signatures, and corrects a reader's response to my article, available at:\u003C\u002Fp>\u003Cp>\"Loading DLLs Using xwizard.exe\"\u003C\u002Fp>\u003Cp>Based on my testing, I believe: After moving locations, the digital signature of a CAT file does not become invalid.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for generating certificates\u003C\u002Fli>\u003Cli>Method for appending digital signatures to the end of files (Authenticode)\u003C\u002Fli>\u003Cli>Method for storing digital signatures in CAT files (catalog)\u003C\u002Fli>\u003Cli>Characteristics of files using CAT digital signatures\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method for Appending Digital Signatures to the End of Files (Authenticode)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the series of articles on steganography techniques, methods for hiding payloads in digital signatures have been studied. The address is as follows:\u003C\u002Fp>\u003Cp>\"Steganography Techniques - Hiding Payloads in Digital Certificates of PE Files\"\u003C\u002Fp>\u003Cp>The certificate format was introduced in the article and will not be repeated here.\u003C\u002Fp>\u003Cp>After adding a digital signature to the end of a file, it can be viewed through the file properties.\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003Cp>Comes with a Microsoft digital signature, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017370747_0_5808101f75.jpeg\">\u003C\u002Fp>\u003Cp>Digital signatures can be verified via PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Tools can also be used to view digital signatures via the command line.\u003C\u002Fp>\u003Cp>Using signtool.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017393260_1_543086a2c7.jpeg\">\u003C\u002Fp>\u003Cp>Using sigcheck.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q C:\\Windows\\System32\\consent.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017430785_2_0521d3f7a7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>signtool.exe:\u003C\u002Fp>\u003Cp>Can be used to view digital signatures of files\u003C\u002Fp>\u003Cp>After installing Visual Studio, the SDK includes signtool.exe, located at C:\\Program Files\\Microsoft SDKs\\Windows\\\u003C\u002Fp>\u003Cp>Entering the developer tools command prompt allows direct invocation of signtool.exe\u003C\u002Fp>\u003Cp>Windows 7 SDK download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=8279\u003C\u002Fp>\u003Cp>sigcheck.exe:\u003C\u002Fp>\u003Cp>Can be used to view digital signatures of files\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fsigcheck\u003C\u002Fp>\u003Cp>The relevant files for this article have been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The command to generate a test certificate is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecert -n \"CN=Microsoft Windows Test\" -r -sv Root.pvk Root.cer\u003Cbr>cert2spc Root.cer Root.spc\u003Cbr>pvk2pfx -pvk Root.pvk -pi 123456 -spc Root.spc -pfx Root.pfx -f\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Certificate registration:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certmgr.exe -add -c Root.cer -s -r localmachine root\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'A dirty way of tricking users to bypass UAC'\u003C\u002Fp>\u003Cp>Sign mimikatz.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool sign \u002Ff Root.pfx \u002Fp 123456 mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The digital signature appears normal, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017464777_3_f775727060.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for Storing Digital Signatures in CAT Files (catalog)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, some files cannot obtain digital signature information through file properties, but these files also contain digital signatures. The digital signatures here refer to CAT (security catalog) file digital signatures (catalog signing)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Finstall\u002Fcatalog-files\u003C\u002Fp>\u003Cp>Intuitive understanding of the signing process:\u003C\u002Fp>\u003Cul>\u003Cli>Save the hash value obtained by SHA1 encryption of the file in a CAT file (one CAT file can store multiple file hashes)\u003C\u002Fli>\u003Cli>Add a digital signature to this CAT file\u003C\u002Fli>\u003Cli>Add the CAT file to the system's security catalog database\u003C\u002Fli>\u003Cli>These files then have digital signatures\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntph.cat\u003C\u002Fp>\u003Cp>Properties - Security Catalog - Item Details - File, you can find the file corresponding to the Hash value\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017479871_4_3d2c311ef9.jpeg\">\u003C\u002Fp>\u003Cp>CAT digital signatures cannot be viewed through file properties\u003C\u002Fp>\u003Cp>.cat files are saved in ASN.1 format and cannot be viewed directly via Notepad; decryption is required. The online website is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flapo.it\u002Fasn1js\u002F\u003C\u002Fp>\u003Cp>After selecting the .cat file, it can be decrypted to display the complete format\u003C\u002Fp>\u003Cp>For format parsing, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F287547\u002Fobject-ids-associated-with-microsoft-cryptography\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003Cp>Includes a CAT format digital signature, which cannot be viewed through file properties\u003C\u002Fp>\u003Cp>Using PowerShell cannot retrieve the CAT file digital signature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017488645_5_f2164b6eb5.jpeg\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Windows 10 can obtain CAT file digital signatures, while Windows 7 cannot.\u003C\u002Fp>\u003Cp>However, you can use signtool.exe and sigcheck.exe to view digital signatures.\u003C\u002Fp>\u003Cp>Using signtool.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fpa \u002Fa \u002Fv C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017499273_6_fff715e105.jpeg\">\u003C\u002Fp>\u003Cp>Using sigcheck.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q C:\\Windows\\System32\\xwizard.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017506417_7_6a9b17c55b.jpeg\">\u003C\u002Fp>\u003Cp>The following describes how to use CAT file digital signatures\u003C\u002Fp>\u003Ch3>1. Generate a CAT file\u003C\u002Fh3>\u003Cp>Create a new text document cat.txt with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[CatalogHeader]\u003Cbr>Name=makecat1.cat\u003Cbr>[CatalogFiles]\u003Cbr>\u003Chash>ExeFile1=mimikatz.exe\u003Cbr>\u003C\u002Fhash>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A blank line is required at the end of the txt file; otherwise, subsequent operations will report an error indicating the file cannot be found.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017511985_8_a58bdf02d4.jpeg\">\u003C\u002Fp>\u003Cp>Generate a cat file using makecat.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecat -v cat.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Sign the CAT file with a certificate\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool sign \u002Ff Root.pfx \u002Fp 123456 makecat1.cat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The certificate used here is Root.pfx generated in step 0x02.\u003C\u002Fp>\u003Ch3>3. Add the cat file to the system's security catalog database\u003C\u002Fh3>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool catdb -v makecat1.cat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete using the -r parameter: signtool catdb -r makecat1.cat\u003C\u002Fp>\u003Cp>If not added to the system's security catalog database, the signature status is unsigned, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017517476_9_e13bd821b2.jpeg\">\u003C\u002Fp>\u003Cp>Adding to the system's security catalog database is equivalent to adding the file makecat1.cat to the directory C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\u003C\u002Fp>\u003Cp>Deletion is equivalent to removing the corresponding CAT file makecat1.cat from the directory C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\u003C\u002Fp>\u003Cp>Using signtool.exe to obtain digital signatures:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fpa \u002Fa mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using sigcheck.exe to obtain digital signatures:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q mimikatz.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After moving the location, the signature remains valid\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017521951_10_fb1f453c83.jpeg\">\u003C\u002Fp>\u003Cp>Verification conclusion:\u003Cstrong>After moving the location, the CAT file digital signature does not become invalid\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, using xwizard.exe with a CAT file digital signature to load a DLL can, to some extent, bypass application whitelist blocking.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for adding digital signatures, analyzes the characteristics of CAT file digital signatures, and for executable files, verifies two different digital signatures using Process Explorer.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017524869_11_a8c05a824b.jpeg\">\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Important files in Windows systems are often digitally signed to prevent tampering, and some whitelist rule determinations are also based on digital signatures.\u003C\u002Fp>\u003Cp>As foundational content for the digital signature research series, this article introduces two methods for adding digital signatures, analyzes the characteristics of CAT file digital signatures, and corrects a reader's response to my article, available at:\u003C\u002Fp>\u003Cp>\"Loading DLLs Using xwizard.exe\"\u003C\u002Fp>\u003Cp>Based on my testing, I believe: After moving locations, the digital signature of a CAT file does not become invalid.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for generating certificates\u003C\u002Fli>\u003Cli>Method for appending digital signatures to the end of files (Authenticode)\u003C\u002Fli>\u003Cli>Method for storing digital signatures in CAT files (catalog)\u003C\u002Fli>\u003Cli>Characteristics of files using CAT digital signatures\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method for Appending Digital Signatures to the End of Files (Authenticode)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the series of articles on steganography techniques, methods for hiding payloads in digital signatures have been studied. The address is as follows:\u003C\u002Fp>\u003Cp>\"Steganography Techniques - Hiding Payloads in Digital Certificates of PE Files\"\u003C\u002Fp>\u003Cp>The certificate format was introduced in the article and will not be repeated here.\u003C\u002Fp>\u003Cp>After adding a digital signature to the end of a file, it can be viewed through the file properties.\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003Cp>Comes with a Microsoft digital signature, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017370747_0_5808101f75-1.jpeg\">\u003C\u002Fp>\u003Cp>Digital signatures can be verified via PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Tools can also be used to view digital signatures via the command line.\u003C\u002Fp>\u003Cp>Using signtool.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017393260_1_543086a2c7-1.jpeg\">\u003C\u002Fp>\u003Cp>Using sigcheck.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q C:\\Windows\\System32\\consent.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017430785_2_0521d3f7a7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>signtool.exe:\u003C\u002Fp>\u003Cp>Can be used to view digital signatures of files\u003C\u002Fp>\u003Cp>After installing Visual Studio, the SDK includes signtool.exe, located at C:\\Program Files\\Microsoft SDKs\\Windows\\\u003C\u002Fp>\u003Cp>Entering the developer tools command prompt allows direct invocation of signtool.exe\u003C\u002Fp>\u003Cp>Windows 7 SDK download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=8279\u003C\u002Fp>\u003Cp>sigcheck.exe:\u003C\u002Fp>\u003Cp>Can be used to view digital signatures of files\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fsigcheck\u003C\u002Fp>\u003Cp>The relevant files for this article have been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The command to generate a test certificate is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecert -n \"CN=Microsoft Windows Test\" -r -sv Root.pvk Root.cer\u003Cbr>cert2spc Root.cer Root.spc\u003Cbr>pvk2pfx -pvk Root.pvk -pi 123456 -spc Root.spc -pfx Root.pfx -f\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Certificate registration:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certmgr.exe -add -c Root.cer -s -r localmachine root\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'A dirty way of tricking users to bypass UAC'\u003C\u002Fp>\u003Cp>Sign mimikatz.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool sign \u002Ff Root.pfx \u002Fp 123456 mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The digital signature appears normal, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017464777_3_f775727060-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for Storing Digital Signatures in CAT Files (catalog)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, some files cannot obtain digital signature information through file properties, but these files also contain digital signatures. The digital signatures here refer to CAT (security catalog) file digital signatures (catalog signing)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Finstall\u002Fcatalog-files\u003C\u002Fp>\u003Cp>Intuitive understanding of the signing process:\u003C\u002Fp>\u003Cul>\u003Cli>Save the hash value obtained by SHA1 encryption of the file in a CAT file (one CAT file can store multiple file hashes)\u003C\u002Fli>\u003Cli>Add a digital signature to this CAT file\u003C\u002Fli>\u003Cli>Add the CAT file to the system's security catalog database\u003C\u002Fli>\u003Cli>These files then have digital signatures\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\ntph.cat\u003C\u002Fp>\u003Cp>Properties - Security Catalog - Item Details - File, you can find the file corresponding to the Hash value\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017479871_4_3d2c311ef9-1.jpeg\">\u003C\u002Fp>\u003Cp>CAT digital signatures cannot be viewed through file properties\u003C\u002Fp>\u003Cp>.cat files are saved in ASN.1 format and cannot be viewed directly via Notepad; decryption is required. The online website is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flapo.it\u002Fasn1js\u002F\u003C\u002Fp>\u003Cp>After selecting the .cat file, it can be decrypted to display the complete format\u003C\u002Fp>\u003Cp>For format parsing, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F287547\u002Fobject-ids-associated-with-microsoft-cryptography\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003Cp>Includes a CAT format digital signature, which cannot be viewed through file properties\u003C\u002Fp>\u003Cp>Using PowerShell cannot retrieve the CAT file digital signature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017488645_5_f2164b6eb5-1.jpeg\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Windows 10 can obtain CAT file digital signatures, while Windows 7 cannot.\u003C\u002Fp>\u003Cp>However, you can use signtool.exe and sigcheck.exe to view digital signatures.\u003C\u002Fp>\u003Cp>Using signtool.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fpa \u002Fa \u002Fv C:\\Windows\\System32\\xwizard.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017499273_6_fff715e105-1.jpeg\">\u003C\u002Fp>\u003Cp>Using sigcheck.exe to view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q C:\\Windows\\System32\\xwizard.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017506417_7_6a9b17c55b-1.jpeg\">\u003C\u002Fp>\u003Cp>The following describes how to use CAT file digital signatures\u003C\u002Fp>\u003Ch3>1. Generate a CAT file\u003C\u002Fh3>\u003Cp>Create a new text document cat.txt with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[CatalogHeader]\u003Cbr>Name=makecat1.cat\u003Cbr>[CatalogFiles]\u003Cbr>\u003Chash>ExeFile1=mimikatz.exe\u003Cbr>\u003C\u002Fhash>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A blank line is required at the end of the txt file; otherwise, subsequent operations will report an error indicating the file cannot be found.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017511985_8_a58bdf02d4-1.jpeg\">\u003C\u002Fp>\u003Cp>Generate a cat file using makecat.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecat -v cat.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Sign the CAT file with a certificate\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool sign \u002Ff Root.pfx \u002Fp 123456 makecat1.cat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The certificate used here is Root.pfx generated in step 0x02.\u003C\u002Fp>\u003Ch3>3. Add the cat file to the system's security catalog database\u003C\u002Fh3>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool catdb -v makecat1.cat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete using the -r parameter: signtool catdb -r makecat1.cat\u003C\u002Fp>\u003Cp>If not added to the system's security catalog database, the signature status is unsigned, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017517476_9_e13bd821b2-1.jpeg\">\u003C\u002Fp>\u003Cp>Adding to the system's security catalog database is equivalent to adding the file makecat1.cat to the directory C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\u003C\u002Fp>\u003Cp>Deletion is equivalent to removing the corresponding CAT file makecat1.cat from the directory C:\\Windows\\System32\\catroot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\u003C\u002Fp>\u003Cp>Using signtool.exe to obtain digital signatures:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fpa \u002Fa mimikatz.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using sigcheck.exe to obtain digital signatures:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q mimikatz.exe \u002Faccepteula\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After moving the location, the signature remains valid\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017521951_10_fb1f453c83-1.jpeg\">\u003C\u002Fp>\u003Cp>Verification conclusion:\u003Cstrong>After moving the location, the CAT file digital signature does not become invalid\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Of course, using xwizard.exe with a CAT file digital signature to load a DLL can, to some extent, bypass application whitelist blocking.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two methods for adding digital signatures, analyzes the characteristics of CAT file digital signatures, and for executable files, verifies two different digital signatures using Process Explorer.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017524869_11_a8c05a824b-1.jpeg\">\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1188,"Onedaysec",5,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"CAT File Digital Signatures: Techniques & Authenticode Methods","CAT file digital signature, Authenticode, Windows security, digital signature techniques, catalog signing, file tampering prevention",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],426,425,424,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.434Z","2026-07-23T16:01:33.899Z","draft","2026-07-23T16:06:09.753Z"]