Absent Authenticode timestamp counter-signature
ID PE176 Level WARNING Category Security
Description
Authenticode timestamp counter-signature is absent. The signature will become invalid if the signing certificate is revoked or when it expires.
Mitigation
- Consider counter-signing the executable with the timestamp signature to avoid signature expiration.
- If using
signtoolto sign the image, use thesigntool timestampcommand to add the timestamp counter-signature. Alternatively, usesigntool signwith the/tor/troptions to sign and timestamp the image at the same time. See thesigntooldescription page for more details.
Arguments
This rule has the following output arguments:
-
signature_info- Readable affected signature name (e.g. "root signature", "timestamp root signature", "nested signature (index 1)")
Loading...
Unable to load this documentation page.