{"adoption": {"forks": 483, "observed_at": "2026-08-28T04:06:50.300218+00:00", "stars": 2416}, "canonical_url": "https://ross.abutalabs.com/products/sigthief", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Stealing Signatures and Making One Invalid Signature at a Time", "domain": ["security", "penetration-testing", "developer-tools"], "enriched": true, "function": ["security", "penetration-testing", "cli"], "health_score": 20, "homepage": null, "language": "Python", "license": "BSD-3-Clause", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["secretsquirrel/SigThief"], "name": "secretsquirrel/SigThief", "platform": ["python", "cli", "windows", "cross-platform"], "pushed_at": "2021-08-11T19:34:42+00:00", "repo": "secretsquirrel/SigThief", "stars": 2416, "tags": ["pe-files", "code-signing", "antivirus-testing", "signature-forgery", "red-team"], "topics": ["pe", "python", "testing-antivirus", "certificates", "python3"], "urls": [], "use_cases": ["test how antivirus engines treat PE signatures", "copy a code-signing certificate table from one exe to another", "check whether a PE file is signed", "remove or truncate a signature from a Windows binary", "evaluate AV trust in certificate authorities without signature validation"], "what_it_is": "SigThief is a Python CLI tool that rips the Authenticode signature off a signed PE file and appends it to another binary, patching the certificate table. The resulting signature is intentionally invalid, making it useful for testing how antivirus engines prioritize PE signatures.", "when_to_avoid": ["you need to create genuinely valid code signatures", "you are signing binaries for production software distribution", "you need cross-platform signing formats beyond Windows PE"], "when_to_choose": ["you are a security professional testing antivirus signature handling", "you need to quickly append or strip Authenticode signatures on PE files", "you want a lightweight Python script for red-team AV evasion research"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/sigthief", "repo": "secretsquirrel/SigThief", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:50.300218+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:33:09.898598+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "bb915dcb78516fd5367c2b52f46c13dd14c704c049784077a34fc8fcbdf49172", "fetched_at": "2026-08-28T04:06:50.300218+00:00", "kind": "readme", "missing": false, "url": "https://github.com/secretsquirrel/SigThief"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3288, "days_push": 1848, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}