Binary Scanner
Type: binary
Category: Binary
Access Mode: AGENT
Produces: signature, certificate, public-key
The binary scanner analyzes compiled files to find code signatures (Authenticode, JAR signatures), embedded certificates, and references to linked cryptographic libraries.
What It Discovers
Section titled “What It Discovers”- Code signatures — Authenticode (PE/DLL/EXE), JAR signatures, Mach-O code signing
- Signing certificates — the X.509 certificate used to sign binaries
- Signature algorithms — what algorithm was used (SHA256withRSA, SHA384withECDSA, etc.)
- Embedded certificates — certificates found within binary resources
- Linked crypto libraries — references to OpenSSL, BouncyCastle, NSS, etc.
Supported File Types
Section titled “Supported File Types”.dll, .exe, .so, .dylib, .jar, .war, .ear, .class, .o, .a, .lib, .sys, .node
Configuration
Section titled “Configuration”paths: - /opt/applications - /usr/local/lib - C:\Program Files\MyAppextensions: - dll - exe - jar - somaxFileSize: 100MBConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
paths | string list | Yes | — | Directories to scan for binaries |
extensions | string list | No | dll, so, dylib, exe, jar, war, ear, class, o, a, lib, sys, node | File extensions to include |
maxFileSize | string | No | 100MB | Maximum file size to process |
Example Output
Section titled “Example Output”For a signed MyApp.exe:
- Signature: “SHA256withRSA (MyApp.exe)” — algorithm SHA256withRSA, format Authenticode
- Certificate: “My Company Code Signing” — RSA-2048, issued by DigiCert
- Public Key: RSA-2048 public key (My Company Code Signing)
For a signed app.jar:
- Signature: “SHA256withRSA (app.jar)” — algorithm SHA256withRSA, format JAR
- Certificate: “My Company” — RSA-2048
- Deployment directories — Point at application deployment folders rather than system directories to avoid noise
- File size limit — Large binaries (>100MB) are skipped by default. Increase
maxFileSizeif needed. - JAR files — The scanner reads the META-INF signature files without extracting the full archive
Related
Section titled “Related”- Source Code Scanner — Scan source for crypto API usage
- Filesystem Scanners — Scan for certificate/key files