Commit Graph

  • 4c60797d4b
    Merge pull request #42 from cha147/patch-1 master Jora Kornev 2022-07-14 00:48:44 +0300
  • 337643e3b7 fix typos in readme #42 cha147 2022-07-13 14:45:03 -0700
  • aa7704d9b7
    Update README.md Jora Kornev 2022-02-26 23:42:40 +0300
  • 331952e7fc Improved looking for EPROCESS::ActiveProcessLinks algo JKornev 2021-08-28 02:08:47 +0300
  • 59439bae79 Added a test that validates hiding processes JKornev 2021-08-25 02:10:13 +0300
  • a5382ce955
    Update README.md Jora Kornev 2021-08-25 00:33:22 +0300
  • f47f5439da Fixed an issue where Zydis breaks a project language determination algo on github JKornev 2021-08-24 23:53:10 +0300
  • 5a678ce3c4 Fixed a bug with a process initialization flag in PsMonitor JKornev 2021-08-24 23:25:12 +0300
  • 108db10892
    Update README.md Jora Kornev 2021-08-24 04:29:22 +0300
  • a8970b5269
    Update README.md Jora Kornev 2021-08-24 04:26:30 +0300
  • 536a3ec3e8 Hiding a process from PspCidTable on Windows Vista and 7 JKornev 2021-08-24 03:45:25 +0300
  • 0c01afa4e1 Improved hiding from PspCidTable, works for new processes (win 8+) JKornev 2021-08-23 02:28:53 +0300
  • 42644b71f5 The first working implementation of the hiding PspCidTable stuff (Win8+) JKornev 2021-08-21 23:21:18 +0300
  • 1b76e90ada Optimized process table access JKornev 2021-08-15 03:18:23 +0300
  • 328b318794 Added a kernel analyzer module that looks for non-exported objects in the ntoskrnl JKornev 2021-08-12 01:39:01 +0300
  • 0f7caba5fe A small refactoring in a driver source structure JKornev 2021-08-11 23:46:48 +0300
  • 69ac0d0aaf Added Zydis disassembler to a driver JKornev 2021-08-11 03:33:27 +0300
  • 1424bee8ee Added a test for a process hiding JKornev 2021-07-31 02:52:57 +0300
  • 206258a6fe Added a cache to routine that looks for ActiveProcessLinks offset JKornev 2021-07-30 22:44:18 +0300
  • 9e89ad1da0 Added an ability to configure hiding processes over a registry JKornev 2021-07-30 13:36:00 +0300
  • a2e5e8e901 Process table optimization for hidden processes JKornev 2021-07-30 03:06:02 +0300
  • 2ec973a008 Improvements for /query request JKornev 2021-07-29 16:53:08 +0300
  • 05bf7b55b8
    Update README.md Jora Kornev 2021-07-29 03:31:56 +0300
  • 9d3db08314 Implemented /unhide support for processes JKornev 2021-07-29 03:25:01 +0300
  • 2b07e3274f
    Update README.md Jora Kornev 2021-07-29 01:23:12 +0300
  • b60ae93f45
    Update README.md Jora Kornev 2021-07-29 01:15:46 +0300
  • ae1a9a7906
    Update README.md Jora Kornev 2021-07-29 01:09:37 +0300
  • bf270aa771 Merge branch 'master' of https://github.com/JKornev/hidden JKornev 2021-07-29 01:01:16 +0300
  • 0628ceb520 Fix for reference leak and output in a driver JKornev 2021-07-29 01:00:14 +0300
  • 8ec864c23f
    Update README.md Jora Kornev 2021-07-28 22:35:22 +0300
  • 3f5350a750 Kernel mode hiding process implementation JKornev 2021-07-28 21:54:03 +0300
  • 8a9f37e8f2 Kernel level configuration for hidden processes JKornev 2021-07-25 23:15:08 +0300
  • 9767366010 Added a usermode interface for hiding processes JKornev 2021-07-25 21:32:03 +0300
  • 1e965bbe2d Different small fixed JKornev 2021-07-24 15:30:01 +0300
  • 7e1d00c2dd Fixed compilation errors on x64 arch v1.1 JKornev 2021-07-05 01:30:08 +0300
  • d9f2e018ca
    Update README.md Jora Kornev 2021-01-21 02:49:19 +0300
  • 8d6a72c644 Updated to WDK 10 and Windows 10 SDK JKornev 2021-01-21 02:45:57 +0300
  • 331d2d306d
    Update README.md Jora Kornev 2020-06-10 00:57:23 +0300
  • 84694348e6
    Update README.md Jora Kornev 2020-06-10 00:55:00 +0300
  • c4a4325b12
    Merge pull request #23 from Pernat1y/patch-1 Jora Kornev 2020-05-22 22:12:37 +0300
  • b311074eaf
    Update README.md #23 Pernat1y 2020-05-21 15:26:10 +0300
  • a8dc93e7b5
    Fix for /ignore command Jora Kornev 2019-11-17 23:41:34 +0300
  • af750492ae
    Update README.md Jora Kornev 2019-09-27 13:12:52 +0300
  • e248fcdc68
    Update README.md Jora Kornev 2019-09-27 13:12:42 +0300
  • 91c3ac6500
    Update README.md Jora Kornev 2019-09-17 10:32:56 +0300
  • 9247016ccb
    Update README.md Jora Kornev 2019-09-17 10:32:50 +0300
  • 58e8f353e3
    Update README.md Jora Kornev 2019-09-11 10:10:23 +0300
  • ca740b5598
    Update README.md Jora Kornev 2019-08-23 15:39:29 +0300
  • 783289d56e
    Update README.md Jora Kornev 2019-08-23 10:07:27 +0300
  • 6e4774f9d2
    Update README.md Jora Kornev 2019-08-22 20:20:25 +0300
  • 02a3468798
    Update README.md v1.0 Jora Kornev 2019-08-22 19:10:14 +0300
  • 4fbc0c633e
    Update README.md Jora Kornev 2019-08-22 19:09:28 +0300
  • c2ac4b3d61 Registry filter fix JKornev 2019-06-09 23:26:16 +0300
  • 8e4dd95562
    Update PsMonitor.c Jora Kornev 2019-04-19 12:08:50 +0300
  • 7ad8dcaad3 Windows 10 path normalization fix JKornev 2018-12-20 02:54:24 +0300
  • 0e9e814c28 Threads protection fix JKornev 2018-12-20 02:53:28 +0300
  • a780193b7c
    Fix for protection PID parsing Jora Kornev 2018-12-18 11:21:43 +0300
  • f031fc221a Fix for invalid argument parsing logic JKornev 2018-12-18 11:19:06 +0300
  • 01bba71d6d Logging improvements JKornev 2018-12-03 00:56:39 +0300
  • 8494048e63 Update PsTable.c Jora Kornev 2017-10-04 11:32:51 +0300
  • a2899e37e8 Merge pull request #7 from YHVHvx/patch-1 Jora Kornev 2017-10-04 07:38:09 +0300
  • 3dcbc53707 Err VS2015: Redeclaration proc info size #7 LEON 2017-10-03 22:03:56 +0300
  • 8e2e30d069 Removed unused project settings JKornev 2017-06-02 21:02:19 +0300
  • 5b3cf5932f Improved support of the HKLM\System\CurrentControlSet tree JKornev 2017-04-02 03:06:55 +0300
  • fe8bd1ed45 Removed useless readme JKornev 2017-02-18 16:44:45 +0300
  • 2852b933d9 Merge branch 'master' of https://github.com/JKornev/hidden JKornev 2017-02-18 16:40:06 +0300
  • aed77ac670 Hardcoded exclusion for the system process JKornev 2017-02-18 16:39:08 +0300
  • 4a8d02b391 Update README.md Jora Kornev 2017-02-03 02:17:24 +0300
  • 278d76428b Update README.md Jora Kornev 2017-02-03 02:01:37 +0300
  • 5261490ec5 Merge branch 'master' of https://github.com/JKornev/hidden JKornev 2017-02-03 01:56:24 +0300
  • d2af2c51e0 Fixes for Code Analysis artifacts JKornev 2017-02-03 01:55:19 +0300
  • 08307732b9 Update README.md Jora Kornev 2017-02-01 17:15:06 +0300
  • df20b38b7e Update README.md Jora Kornev 2017-02-01 17:13:07 +0300
  • da777eb050 Memory leak fixes #3 (Verifier tests) JKornev 2017-01-31 23:03:37 +0300
  • 1db58b922c Memory leak fixes #2 (Verifier tests) JKornev 2017-01-30 22:40:32 +0300
  • ca63ce3d31 Memory leak fixes (Verifier tests) JKornev 2017-01-29 18:43:20 +0300
  • d5db2383e7 Registry utils improvements JKornev 2017-01-07 23:28:39 +0300
  • c3705478b1 Stealth mode first steps JKornev 2016-12-30 19:57:52 +0300
  • fbae5ffa57 Fix for possible IRQL violations JKornev 2016-12-29 22:48:37 +0300
  • 67355c72c4 Fix for BSOD and vmware.conf JKornev 2016-12-28 00:31:00 +0300
  • 8a9ba43e23 Added valid error codes JKornev 2016-12-27 00:52:27 +0300
  • 32f2da5145 Fix for status output JKornev 2016-12-27 00:33:16 +0300
  • 1b643e5e84 Configs installation to registry JKornev 2016-12-25 23:56:18 +0300
  • 432a731aac hiddencli supports install\uninstall stuff JKornev 2016-12-23 23:31:26 +0300
  • 4f3e364d72 /install and /uninstall commands JKornev 2016-12-23 03:05:09 +0300
  • 93ea859610 Load configs improvements JKornev 2016-12-22 00:04:55 +0300
  • a2a8cb9ad1 Merge branch 'master' of https://github.com/JKornev/hidden JKornev 2016-12-21 23:45:05 +0300
  • f24aca20ec Comments update JKornev 2016-12-21 23:44:32 +0300
  • 3f74cccf7b Update README.md Jora Kornev 2016-12-19 15:15:23 +0300
  • 79cec65cf2 Driver loads configs from registry JKornev 2016-12-18 21:11:10 +0300
  • 1c2c7dc3e4 Added /config command JKornev 2016-12-16 00:09:42 +0300
  • 7c522d760f Added new cli mode /multi JKornev 2016-12-15 02:29:27 +0300
  • 5d611535e7 Added 'state' command JKornev 2016-12-12 23:40:35 +0300
  • 146af98691 Fixed issue with avoiding parent process checking and etc JKornev 2016-12-10 14:22:49 +0300
  • fbbb57c346 Multiple fixes - Fixed issue with RuleId - Added loading of the new commands - Fixed issue with inherit\apply flags - Fixed invalid type issue for Protect\Ignore commands etc JKornev 2016-12-10 00:34:07 +0300
  • 0959938a6a Added 'query' command JKornev 2016-12-09 23:27:27 +0300
  • 84947c69aa Added 'protect', 'unprotect', 'unignore' JKornev 2016-12-08 23:06:17 +0300
  • eceaaf829f Added 'ignore' command to hiddencli JKornev 2016-12-07 02:19:49 +0300
  • 93a78b2680 Added hiddencli commands 'hide' and 'unhide' JKornev 2016-12-07 00:15:08 +0300
  • 1358effe89 Design for the commands JKornev 2016-12-06 01:37:18 +0300
  • 96c5e6eb40 HiddenCLI first steps JKornev 2016-12-04 22:27:46 +0300
  • 241e8bb296 Update todo.txt Jora Kornev 2016-11-10 11:20:37 +0300
  • 86458caf5d VMware tests JKornev 2016-10-27 23:08:56 +0300
  • 3851dcd17d Multiple changes JKornev 2016-10-19 00:28:55 +0300
  • 3e5e5e8679 Fixes for API and x64 compilation JKornev 2016-10-15 18:10:35 +0300
  • 0332732253 Removed unused code JKornev 2016-10-15 13:28:19 +0300
  • 3c19ea50d6 Removed unused project settings JKornev 2016-10-15 03:16:28 +0300
  • e0d700635b Added x64 support JKornev 2016-10-15 02:47:00 +0300
  • aed101fa17 Added Wow64 redirection support JKornev 2016-10-15 02:39:29 +0300
  • 6b0777c4de Added new process exclusion tests JKornev 2016-10-15 00:36:32 +0300
  • 127c0b9c86 Added tests for ps protection\exclusion JKornev 2016-10-14 00:29:53 +0300
  • 98014e750e Major changes - Fixed BSOD on driver deinitialization step - Fixed resources leak in the reg filter - Fixed path normalization function - Added support for inherit type in predefined process monitor configs - Added support for opening protected processes by subsystem - Added tests for protected processes and other little fixes JKornev 2016-10-11 00:37:28 +0300
  • 8a7929b310 Added Get\Set ps state ability Fixed issue with DeviceIOControl output Fixed issues in the PsRule & PsTable JKornev 2016-09-22 23:17:12 +0300
  • b9e7f2c015 Added ps path normalization to the hiddenlib JKornev 2016-09-19 23:21:47 +0300
  • 4c3047c669 Added path normalization to the ps monitor JKornev 2016-09-19 23:20:30 +0300
  • 22fdb1d00b Added tests for Reg filter JKornev 2016-09-18 17:26:31 +0300
  • d325a8d91a Added reg key\value path normalization JKornev 2016-09-18 17:25:58 +0300
  • 59b989dcc5 Added new types of operations to Reg filter (set,query,delete value) JKornev 2016-09-18 17:22:49 +0300
  • 935ffa787f Added the HiddenTests project that contain different tests for this solution JKornev 2016-09-11 14:42:37 +0300
  • 184312875d Added path conversion to NT path to the FS filter interface JKornev 2016-09-11 14:39:12 +0300
  • 1fdfa70156 Fix for issue with file\dir name duplication JKornev 2016-09-07 02:22:03 +0300
  • 5d1787ffbc Added exclude\protect list loading from HiddenCLI to driver Fixed memory leak on the CreateProcessNotifyCallback JKornev 2016-09-05 22:30:18 +0300
  • a25458a4c8 Added usermode implementation of the PsMonitor interface and etc JKornev 2016-09-04 22:00:48 +0300
  • 80b89c2f28 Added Get\Set process exclude\protect state Fixed issue with the hidden.inf and etc JKornev 2016-09-04 20:17:21 +0300
  • 9ba217714e Added IOCTLs for the part of Ps API JKornev 2016-09-01 01:28:18 +0300
  • b93f05e6cd test JKornev 2016-08-30 22:41:23 +0300
  • f65a2301c6 PS monitor internal API implementation JKornev 2016-08-30 22:40:25 +0300
  • 220d7cf07e Update ExcludeList.c Jora Kornev 2016-08-30 19:24:15 +0300
  • 1e53188c4e HiddenLib include path fix JKornev 2016-08-29 22:45:56 +0300
  • 5e1450971c Merge branch 'master' of https://github.com/JKornev/hidden JKornev 2016-08-28 19:54:08 +0300
  • 07d0e4d747 PsTable raise condition fix and etc JKornev 2016-08-28 19:52:50 +0300
  • 86bf4627e7 Update README.md Jora Kornev 2016-08-28 00:04:49 +0300
  • cfe416a472 Update README.md Jora Kornev 2016-08-28 00:04:21 +0300
  • e3f90905a4 TODO update JKornev 2016-08-27 23:38:43 +0300
  • 480b0ef15f Added protected & excluded process lists JKornev 2016-08-27 23:18:54 +0300
  • 384bc8dd40 update for symlink path-resolver JKornev 2016-07-23 17:02:16 +0300
  • 228b3fb1fc initial commit JKornev 2016-07-22 02:02:31 +0300
  • 1c857ec226 Initial commit Jora Kornev 2016-06-16 22:40:32 +0300