Skip to content

sunatlive/HideProcess

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

HideProcess

Hide Process

How to hide

  • 修改EPROCESS.ImageFileName

  • 替换EPROCESS.FileObject.SectionObject(退出进程需要恢复,否则在删除FileObject时会蓝屏)

  • PEB64

  • 替换用户组


Reference

初探进程伪装

修改PEB伪装进程

Author-Oxygen

E-mail:304914289@qq.com 新建的群,没啥人,欢迎进入

About

Hide Process

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages

  • C++ 100.0%