What is the CAT file format?
A .cat file is a Windows Security Catalog - a system file that certifies a group of files as coming from a reliable, trusted source. Instead of digitally signing each individual file, .cat files record the cryptographic hash of every file in the package inside a single signed container, letting Windows verify the whole set at once. .cat files are commonly used for distributing software updates and driver packages, and must be signed by the developer and then validated against Microsoft's trusted root store.
A driver package ships a .cat alongside an INF file; the OS checks each file's hash against the catalog to confirm the package is untampered and from a trusted publisher - a process backed by the Windows Hardware Quality Labs (WHQL) signing program.
Security prompts
Although .cat files do not prevent security prompts during software installation from being activated, they make them more focused on providing additional information rather than warning against potential risks. Users can choose to trust any content coming from a given source to prevent future security popups from being displayed.
Internally, a .cat is a binary PKCS#7 SignedData structure (ASN.1 DER-encoded) carrying a Certificate Trust List (CTL) - a table of per-file hash entries signed by an Authenticode certificate chain. Hash algorithms migrated from SHA-1 (legacy) to SHA-256 on modern Windows. Catalogs are created with MakeCat or Inf2Cat (Windows Driver Kit) and inspected with SignTool.
Security & safety
RISK: MEDIUMA legitimate .cat is passive signed metadata and safe. The real risks are operational: deleting catalogs from %SystemRoot%\System32\CatRoot can break driver/component trust and trigger repair or reinstall prompts, so don't remove system catalogs. Security-wise, catalogs are part of the trust chain - malware has historically abused stolen or mis-issued signing certificates and tampered catalogs to make malicious drivers appear trusted, so a .cat from an untrusted source should be treated with suspicion and its signature verified (signtool verify). A catalog that fails signature validation cannot be trusted.
Format details
in a nutshell- Game/engine .CAT archive - Several games (e.g. X-series, some engines) and tools use .cat as a proprietary data archive/index - unrelated to Windows signing.
- Microsoft Help Workshop catalog / dBASE .CAT - Legacy Help Workshop content files and old dBASE catalog files also used .cat; not security catalogs.
Programs that open CAT files
Technical details
deep spec| Encoding | Binary, ASN.1 DER (Distinguished Encoding Rules) |
| Container structure | PKCS#7 / CMS SignedData wrapping a Certificate Trust List (CTL) |
| Payload | Table of per-file cryptographic hash entries plus the Authenticode certificate chain |
| Hash algorithm (legacy) | SHA-1 (used through Windows 7; deprecated for new driver signing) |
| Hash algorithm (current) | SHA-256 (mandatory for Windows 8+ and all new WHQL submissions) |
| Magic bytes | 0x30 0x82 at offset 0 (ASN.1 SEQUENCE tag with long-form length encoding) |
| MIME type | application/vnd.ms-pki.seccat (official); application/pkcs7-mime (generic PKCS#7) |
| Typical file size | A few KB to a few hundred KB, depending on the number of cataloged files |
| Signature type | Detached Authenticode signature; the cataloged files themselves carry no embedded signature |
| Creation tools | MakeCat.exe and Inf2Cat.exe (Windows Driver Kit) |
| Verification command | signtool verify /pa /c <catalog.cat> <file> (Windows SDK SignTool) |
| Developer | Microsoft Corporation |
| Primary use case | Driver package signing (WHQL) and Windows Update payload integrity verification |
| Released | Late 1990s (Windows driver signing / Authenticode) |
| Latest version | Used through Windows 11 (2025); catalogs use SHA-256 thumbprints on modern Windows |
| Open standard | Yes · royalty-free |
| Specification | learn.microsoft.com |
CAT conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about CAT files.