Authenticode (PE)
For .exe, .dll and .sys the Authenticode hash is recomputed excluding what the specification excludes, then signer, chain and countersignature timestamp. Dual signatures (SHA-1 plus nested SHA-256) are both verified.
Native tools don't cross the border: signtool exists only on Windows, codesign and spctl only on macOS. The Code signing module reads the bytes and verifies the signatures of executables and installers in both directions: who signed, whether the file was modified, with which timestamp.
For .exe, .dll and .sys the Authenticode hash is recomputed excluding what the specification excludes, then signer, chain and countersignature timestamp. Dual signatures (SHA-1 plus nested SHA-256) are both verified.
Signature in the installer container, signer, chain and timestamp.
CodeDirectory (identifier, Team ID, cdhash, flags) and recomputed page hashes. A universal binary has one signature per architecture: Probatio verifies all of them and takes the worst verdict.
Image signature, content integrity and the notarisation ticket stapled with stapler: “is this DMG notarised?” gets an answer even from Windows, offline.
RFC 3161 timestamps and OCSP revocation with the same verification engine used for CAdES and PAdES signatures.
Verification record (when the check was made, not when it is printed), hash of the examined file, signatures one by one, chain, findings and scope of the check.
.exe, a .dll, an .msi, a Mac binary or a .dmg: the format is recognised from its bytes.signtool.stapler lives inside the image's signature: Probatio reads it without spctl and offline. It checks that it is there; it doesn't ask Apple about its validity today.