Sigverif.exe

File Signature Verification utility to verify digital signatures of files

Paths

  • C:\Windows\System32\sigverif.exe
  • C:\Windows\SysWOW64\sigverif.exe

Commands

Execute

Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.

Use case: Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.

Privileges: User

sigverif.exe

Detection

Resources