mirror of
https://github.com/JKornev/hidden
synced 2024-06-25 00:18:04 +00:00
![]() - Fixed BSOD on driver deinitialization step - Fixed resources leak in the reg filter - Fixed path normalization function - Added support for inherit type in predefined process monitor configs - Added support for opening protected processes by subsystem - Added tests for protected processes and other little fixes |
||
---|---|---|
Hidden | ||
Hidden Package | ||
HiddenCLI | ||
HiddenLib | ||
HiddenTests | ||
.gitignore | ||
Hidden.sln | ||
README.md |
Hidden
This toolset developed like a solution for my reverse engineering and researching tasks. This is a very simple windows driver with a usermode interface which uses for hidding specific environment on VMs, like installed rce programs (ex. procmon, wireshark), vm infrastracture (ex. vmware tools) and etc.
Features:
- hide registry keys and values
- hide files and directories
- protect specific processes using ObRegisterCallbacks
- exclude specific processes from hidding and protection features
- usermode interface (lib and cli) for working with driver
and so on