Skip to content
Windows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc
C C++
Branch: master
Clone or download
Latest commit 58e8f35 Sep 11, 2019
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
Hidden Package Removed unused project settings Jun 2, 2017
Hidden Registry filter fix Jun 9, 2019
HiddenCLI Fix for protection PID parsing Dec 18, 2018
HiddenLib Removed useless readme Feb 18, 2017
HiddenTests Multiple changes Oct 18, 2016
.gitignore Memory leak fixes #2 (Verifier tests) Jan 30, 2017
Hidden.sln HiddenCLI first steps Dec 4, 2016
README.md

README.md

Hidden

This toolset is developed like a solution for my reverse engineering and researching tasks. This is a windows driver with a usermode interface which is used for hidding specific environment on VMs, like installed rce programs (ex. procmon, wireshark), vm infrastracture (ex. vmware tools) and etc.

Features

  • hide registry keys and values
  • hide files and directories
  • protect specific processes using ObRegisterCallbacks
  • exclude specific processes from hidding and protection features
  • usermode interface (lib and cli) for working with driver

and so on

Recommended build environment

  • Visual Studio 2013 and above
  • Windows Driver Kit 8.1

Building

Following guide explains how to make a release win32 build

  1. Open Hidden.sln using Visual Studio 2013
  2. Build Hidden Package project with configurations Release, Win32
  3. Open build results folder <ProjectDir>\Release

Installing

  1. Disable a digital signature enforcement on a test machine (bcdedit /set TESTSIGNING ON)
  2. Copy files from <ProjectDir>\Release\Hidden Package to a test machine
  3. Right mouse click on Hidden.inf and choose Install
  4. Start a driver (sc start hidden)

Hiding

A command line tool hiddencli is used for managing a driver. You are able to use it for hiding and unhiding objects, changing a driver state and so on.

To hide a calc.exe try this one

hiddencli /hide file c:\Windows\calc.exe

Want to hide directory? No problems

hiddencli /hide dir "c:\Program Files\VMWare"

Registry key?

hiddencli /hide regkey "HKCU\Software\VMware, Inc."

To get a full help just type

hiddencli /help
You can’t perform that action at this time.