Limelighter is a tool which creates a spoof code signing certificates and sign binaries and DLL files to help evade EDR products and avoid MSS and sock scruitney. LimeLighter can also use valid code signing certificates to sign files. Limelighter can use a fully qualified domain name such as acme.com.
LimeLighter was developed in golang.
Make sure that the following are installed on your OS
openssl
osslsigncode
The first step as always is to clone the repo. Before you compile LimeLighter you’ll need to install the dependencies. To install them, run following commands
go get github.com/fatih/color
Then build it
go build Limelighter.go
Usage
./LimeLighter -h
._ ._ . ._ ._ _ | | || | | || _ | |/ |_ _
| | | |/ _/ _ | | | |/ | | \ \/ _ _ \
| || | Y Y \ /| || / // > Y \ | \ /| | \/ |_ __||| /__ > ____ /|| /| _ >| \/ \/ \/ \/ // \/ \/
@Tyl0us
[*] A Tool for Code Signing… Real and fake
Usage of ./LimeLighter:
-Domain string
Domain you want to create a fake code sign for
-I string
Unsiged file name to be signed
-O string
Signed file name
-Password string
Password for real certificate
-Real string
Path to a valid .pfx certificate file
-Verify string
Verifies a file’s code sign certificate
-debug
Print debug statements
To sign a file you can use the command option Domain to generate a fake code signing certificate
to sign a file with a valid code signing certificate use the Real and Password to sign a file with a valid code signing certificate.
To verify a signed file use the verify command.
Apache is one of the most widely used open-source web servers in the world. It is…
Swap space is an area on disk that Linux uses when it runs out of physical…
Zoom is one of the most widely used video conferencing platforms. Zoom works on Windows, macOS,…
Webmin is an open-source web-based control panel for Linux servers. It gives you a browser interface…
MariaDB is an open-source relational database management system. It was created by the original MySQL developers…
Corruption investigations need accuracy, patience, and strong evidence. In 2026, OSINT tools can help researchers,…