$npx skillfedfor your agent

signify

Module to generate and verify PE signatures

With conditionsPyPI UtilitiesReleased Dec 2025111.6K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — signify-0.9.2-py3-none-any.whl
v0.9.2 · released 2025-12-31 · Python >=3.9 · 5 runtime deps: certvalidator, asn1crypto, oscrypto, mscerts, typing_extensions

Yes, if you need to validate Windows Authenticode signatures outside the Windows ecosystem or in automated security workflows. The low install friction, MIT license, and active maintenance make it a practical choice for security professionals and malware analysts. The aging status (226 days since release) suggests slower development pace but not abandonment; verify that its cryptographic dependencies remain current for your threat model.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later.
  • MSI file support requires the full installation variant (pip install signify[full]).
  • Low friction installation with a pure-Python wheel.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial security tooling.

last release 2025-12-31 (226 days) · last repo commit 2025-12-31 · 87 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 111,575 downloads/mo, #12,410 on PyPI

Verify before relying

pip install signify

from signify.pe import SignedPE

pe = SignedPE('path/to/executable.exe')
pe.verify()
  • Whether the package can validate signatures against current Windows certificate chains or requires manual chain setup.
  • Performance characteristics when processing large executables or batch-validating many files.
  • Extent of support for non-standard or legacy Authenticode implementations.
Same gist for agents: .md · .json

What it is and what it does

Signify is a Python module for validating and inspecting Windows Authenticode signatures—the digital certificates embedded in or attached to Windows executables, MSI installers, and catalog files. It parses and verifies these signatures to confirm software authenticity and detect tampering, making it a tool for security professionals and malware analysts who need to inspect code signatures outside their normal Windows ecosystem.

The library depends on cryptographic and certificate validation packages (certvalidator, asn1crypto, oscrypto, mscerts, typing_extensions) to handle the low-level signature verification. It supports PE executables (.exe, .dll), MSI files, catalog files (.stl, .cat), and any file signed through a catalog. Installation is straightforward via pip, with optional full support for additional file types.

Use it for

  • Verify that a downloaded Windows executable is legitimately signed by its publisher before execution.
  • Analyze malware samples to determine whether they carry valid or forged Authenticode signatures.
  • Batch-validate software distributions in enterprise environments to detect unsigned or tampered binaries.
  • Extract and inspect certificate chains and signature metadata from Windows PE files for forensic analysis.
  • Validate MSI installer integrity as part of automated security scanning pipelines.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need to validate Windows Authenticode signatures outside the Windows ecosystem or in automated security workflows.

The low install friction, MIT license, and active maintenance make it a practical choice for security professionals and malware analysts. The aging status (226 days since release) suggests slower development pace but not abandonment; verify that its cryptographic dependencies remain current for your threat model.

Install

signify on PyPI

Before you install

Low friction installation with a pure-Python wheel. The package is in beta status and aging (226 days since last release), but the repository remains active with recent commits and no archived status.

Requires Python 3.9 or later. MSI file support requires the full installation variant (pip install signify[full]).

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial security tooling.

Quickstart

pip install signify

from signify.pe import SignedPE

pe = SignedPE('path/to/executable.exe')
pe.verify()

Verify before relying

  • Whether the package can validate signatures against current Windows certificate chains or requires manual chain setup.
  • Performance characteristics when processing large executables or batch-validating many files.
  • Extent of support for non-standard or legacy Authenticode implementations.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
certvalidatorasn1cryptooscryptomscertstyping_extensions
MaintenanceAging 226 days since the last release
Last repo commit
First released
Downloads111,575 / month, #12,410 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Legal IndustryIntended Audience :: System AdministratorsProgramming Language :: PythonTopic :: Scientific/Engineering :: Information AnalysisTopic :: Security :: CryptographyTopic :: System :: Software DistributionTopic :: Utilities

Evidence: signify-0.9.2-py3-none-any.whl

Tags

Capabilities
authenticode signature verificationpe executable signature validationwindows code signing verificationdigital signature inspectionmalware analysis signature checkingauthenticode catalog validationexecutable integrity verification
Topics
code-signingmalware-analysiswindows-security
PyPI keywords
authenticodeauthentihashfingerprinterpe

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “authenticode signature verification”

  • signifyValidates and inspects Windows Authenticode digital signatures…
  • cursiveCursive validates digital signatures using OpenStack-specific logic,…
  • securesystemslibSecuresystemslib provides a cryptography interface for creating and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also ansible-sign · cursive · truelayer-signing · c2pa-python · python-flirt · signxml · ciris-verify · endesive · securesystemslib · pefile