Jimping for IT admins
Jimping is a signed Windows ping plotter and continuous traceroute. This page has what a security team needs to review it and allow it on managed devices. On a device you manage, allowing new software is your call; please don't bypass your own policy.
What it does
- Sends ICMP echo requests (ping, plus TTL-limited pings for traceroute) to the hosts the user enters. No other outbound connections, no listening ports. It calls
/v1/licenses/activateat lemonsqueezy.com once only when a user types a Pro license key. - Uses the Windows ICMP API as a standard user. No admin rights, service, driver, scheduled task or autostart entry.
- No telemetry, analytics or accounts. Settings live in
%APPDATA%\Jimpingand history in%LOCALAPPDATA%\Jimping\History. Nothing is uploaded. - A portable zip (single exe) is available, so it can run without an installer.
Code signing
Every release is signed and timestamped with Microsoft Azure Artifact Signing (Public Trust).
- Publisher (subject)
- CN=James Waller, O=James Waller, L=Lino Lakes, S=mn, C=US
- Issuing CA
- Microsoft ID Verified CS EOC CA 03
- Root
- Microsoft Identity Verification Root Certificate Authority 2020
- Timestamp
- Yes, on every signature
The certificates are short lived (3 days), so a rule on a certificate thumbprint will not cover future versions. Use a publisher rule (the subject and issuer above).
Allowing it, whichever fits your tooling
- App Control for Business (WDAC) or AppLocker: a publisher rule for the signer above covers Jimping and its future updates.
- Defender ASR ("Block executable files from running unless they meet a prevalence, age, or trusted list criterion"): add a file or folder exclusion for the Jimping path, or allow the publisher.
- SmartScreen / Smart App Control: newer signed apps may warn until they build reputation. The publisher above is shown under "More info".
- Hash rule (one version only): the SHA-256 of each release is published on the home page and in
SHA256SUMS.txtbeside the download.
Verify a download
In PowerShell, from the folder the file is in:
Get-AuthenticodeSignature .\Jimping-setup.exe | Format-List Get-FileHash .\Jimping-setup.exe
Status should be Valid and the signer CN=James Waller. Compare the hash with the one on the home page.
Questions or a review request: [email protected]