6
0
mirror of https://github.com/JKornev/hidden synced 2024-06-16 12:08:05 +00:00
Go to file
2019-08-22 19:10:14 +03:00
Hidden Registry filter fix 2019-06-09 23:26:37 +03:00
Hidden Package Removed unused project settings 2017-06-02 21:02:21 +03:00
HiddenCLI Fix for protection PID parsing 2018-12-18 11:21:43 +03:00
HiddenLib Removed useless readme 2017-02-18 16:44:53 +03:00
HiddenTests Multiple changes 2016-10-19 00:35:52 +03:00
.gitignore Memory leak fixes #2 (Verifier tests) 2017-01-30 22:41:24 +03:00
Hidden.sln HiddenCLI first steps 2016-12-04 22:27:46 +03:00
README.md Update README.md 2019-08-22 19:10:14 +03:00

Hidden

This toolset is developed like a solution for my reverse engineering and researching tasks. This is a windows driver with a usermode interface which is used for hidding specific environment on VMs, like installed rce programs (ex. procmon, wireshark), vm infrastracture (ex. vmware tools) and etc.

Features

  • hide registry keys and values
  • hide files and directories
  • protect specific processes using ObRegisterCallbacks
  • exclude specific processes from hidding and protection features
  • usermode interface (lib and cli) for working with driver

and so on

Recommended build environment

  • Visual Studio 2013 and above
  • Windows Driver Kit 8.1

Building

Following guide explains how to make a release win32 build

  1. Open Hidden.sln using Visual Studio 2013
  2. Build Hidden Package project with configurations Release, Win32
  3. Open build results folder %ProjectDir%\Release

Installing

  1. Disable a digital signature enforcement on a test machine (bcdedit /set TESTSIGNING ON)
  2. Copy files from %ProjectDir%\Release\Hidden Package to a test machine
  3. Right mouse click on Hidden.inf and choose Install
  4. Start a driver (sc start hidden)