Skip to content

Binary Scanner

Type: binary
Category: Binary
Access Mode: AGENT
Produces: signature, certificate, public-key

The binary scanner analyzes compiled files to find code signatures (Authenticode, JAR signatures), embedded certificates, and references to linked cryptographic libraries.


  • Code signatures — Authenticode (PE/DLL/EXE), JAR signatures, Mach-O code signing
  • Signing certificates — the X.509 certificate used to sign binaries
  • Signature algorithms — what algorithm was used (SHA256withRSA, SHA384withECDSA, etc.)
  • Embedded certificates — certificates found within binary resources
  • Linked crypto libraries — references to OpenSSL, BouncyCastle, NSS, etc.

.dll, .exe, .so, .dylib, .jar, .war, .ear, .class, .o, .a, .lib, .sys, .node


paths:
- /opt/applications
- /usr/local/lib
- C:\Program Files\MyApp
extensions:
- dll
- exe
- jar
- so
maxFileSize: 100MB
FieldTypeRequiredDefaultDescription
pathsstring listYes—Directories to scan for binaries
extensionsstring listNodll, so, dylib, exe, jar, war, ear, class, o, a, lib, sys, nodeFile extensions to include
maxFileSizestringNo100MBMaximum file size to process

For a signed MyApp.exe:

  • Signature: “SHA256withRSA (MyApp.exe)” — algorithm SHA256withRSA, format Authenticode
  • Certificate: “My Company Code Signing” — RSA-2048, issued by DigiCert
  • Public Key: RSA-2048 public key (My Company Code Signing)

For a signed app.jar:

  • Signature: “SHA256withRSA (app.jar)” — algorithm SHA256withRSA, format JAR
  • Certificate: “My Company” — RSA-2048

  • Deployment directories — Point at application deployment folders rather than system directories to avoid noise
  • File size limit — Large binaries (>100MB) are skipped by default. Increase maxFileSize if needed.
  • JAR files — The scanner reads the META-INF signature files without extracting the full archive