Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Process hiding driver

A Windows driver to hide processes by unlinking them from the ActiveProcessLinks list.


Features

  • Hide any process with its Process ID
  • Show any process with its Process ID

How it works

Driver gets the processes EPROCESS handle and then adds OFFSET_ActiveProcessLinks to cast it to LIST_ENTRY.
It "deletes" or empties the list entry to hide the process and on restoration it uses the stored original entry to return it back to existence.

About

A minimal Windows driver that hides processes from enumeration by unlinking their ActiveProcessLinks entries.

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages