Skip to content

Glossary

Authenticode

Microsoft's code-signing format for PE files: a PKCS #7 signature over a hash of the file, stored in the certificate table.

Authenticode signs a hash of the PE file that excludes the CheckSum field, the certificate-table directory entry and the certificate table itself. The signature, the signer's certificate chain and usually a timestamp from a timestamp authority are stored as PKCS #7 SignedData in the certificate table, which the loader does not map into memory.

From the file alone you can verify integrity — the hash matches and the signature is valid — but not trust, which depends on the machine's root store and on revocation. See Authenticode signatures offline.