Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Limelighter — A tool for generating fake code signing certificates or signing real ones | Kitploit
Tools/GitHubGitHub/tylous/limelighter
Payload GenerationCode AnalysisExploitationRed Teaming
GitHubtylous/limelighter

Limelighter

A tool for generating fake code signing certificates or signing real ones

View Repository
9751415 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LimeLighter

A tool which creates a spoof code signing certificates and sign binaries and DLL files to help evade EDR products and avoid MSS and sock scruitney. LimeLighter can also use valid code signing certificates to sign files. Limelighter can use a fully qualified domain name such as acme.com.

Contributing

LimeLighter was developed in golang.

Make sure that the following are installed on your OS

root@kitploit:~
openssl
osslsigncode

The first step as always is to clone the repo. Before you compile LimeLighter you'll need to install the dependencies. To install them, run following commands:

root@kitploit:~
go get github.com/fatih/color

Then build it

root@kitploit:~
go build Limelighter.go

Usage

root@kitploit:~
./LimeLighter -h       

        .____    .__               .____    .__       .__     __                
        |    |   |__| _____   ____ |    |   |__| ____ |  |___/  |_  ___________ 
        |    |   |  |/     \_/ __ \|    |   |  |/ ___\|  |  \   __\/ __ \_  __ \
        |    |___|  |  Y Y  \  ___/|    |___|  / /_/  >   Y  \  | \  ___/|  | \/
        |_______ \__|__|_|  /\___  >_______ \__\___  /|___|  /__|  \___  >__|   
                \/        \/     \/        \/ /_____/      \/          \/         
                                                        @Tyl0us


[*] A Tool for Code Signing... Real and fake
Usage of ./LimeLighter:
  -Domain string
        Domain you want to create a fake code sign for
  -I string
        Unsiged file name to be signed
  -O string
        Signed file name
  -Password string
        Password for real  certificate
  -Real string
        Path to a valid .pfx certificate file
  -Verify string
        Verifies a file's code sign certificate
  -debug
        Print debug statements

To sign a file you can use the command option Domain to generate a fake code signing certificate.

Signing

to sign a file with a valid code signing certificate use the Real and Password to sign a file with a valid code signing certificate.

To verify a signed file use the verify command.

Verifying WindowsVerifying

Download Tool