[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feZY8kjYnaJRGsWEgpejnoO9GqfJgT1w1D1952_hWgAI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},984,"How does ProcessHider hide processes from monitoring tools like Task Manager?","ProcessHider achieves process hiding by injecting a payload DLL into target processes, which hooks the Windows API NtQuerySystemInformation(). This API is used by tools like Task Manager and Process Explorer to enumerate processes; the hook filters out specified processes from the returned list, making them invisible. For full technical details, see the [ProcessHider Utilization Analysis](\u002Fnews\u002Fprocesshider-utilization-analysis).","\u003Cp>ProcessHider achieves process hiding by injecting a payload DLL into target processes, which hooks the Windows API NtQuerySystemInformation(). This API is used by tools like Task Manager and Process Explorer to enumerate processes; the hook filters out specified processes from the returned list, making them invisible. For full technical details, see the [ProcessHider Utilization Analysis](\u002Fnews\u002Fprocesshider-utilization-analysis).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fprocesshider-utilization-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-processhider-hide-processes-from-monitoring-tools-like-task-manager-1777481011441","ProcessHider, NtQuerySystemInformation, API hooking, process hiding",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},241,"ProcessHider Utilization Analysis","processhider-utilization-analysis","Analyze ProcessHider's implementation, code details, and detection methods for hiding processes in monitoring tools like Task Manager and Process Explorer.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ProcessHider can hide specified processes in monitoring tools such as Task Manager and Process Explorer. This article will introduce its implementation principles and analyze code details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>ProcessHider Testing\u003C\u002Fli>\u003Cli>Implementation Principles of ProcessHider\u003C\u002Fli>\u003Cli>Code Analysis of ProcessHider\u003C\u002Fli>\u003Cli>Detection of ProcessHider\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ProcessHider can hide specified processes in monitoring tools such as Task Manager and Process Explorer\u003C\u002Fp>\u003Cp>The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FM00nRise\u002FProcessHider\u003C\u002Fp>\u003Cp>Supports the following parameters:\u003C\u002Fp>\u003Cul>\u003Cli>pid\u003C\u002Fli>\u003Cli>process name\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Two startup forms:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003C\u002Ful>\u003Cp>ProcessHider can automatically identify the operating system version and process bitness, inject Payload.dll into 32-bit and 64-bit processes respectively, and achieve process hiding by hooking the API NtQuerySystemInformation()\u003C\u002Fp>\u003Cp>The injected code uses DLL reflection, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstephenfewer\u002FReflectiveDLLInjection\u003C\u002Fp>\u003Cp>The hook code uses NtHookEngine, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F21414\u002FPowerful-x86-x64-Mini-Hook-Engine\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ProcessHider.exe -n \"putty.exe\" -x \"procexp.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can hide the process named putty.exe in procexp.exe, and by default hides the following processes:\u003C\u002Fp>\u003Cul>\u003Cli>Taskmgr.exe\u003C\u002Fli>\u003Cli>powershell.exe\u003C\u002Fli>\u003Cli>procexp.exe\u003C\u002Fli>\u003Cli>procexp64.exe\u003C\u002Fli>\u003Cli>perfmon.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Currently, hiding the tasklist.exe process is not supported\u003C\u002Fp>\u003Cp>Issues to note during compilation:\u003C\u002Fp>\u003Cp>The ProcessHider project must be compiled as 32-bit, not 64-bit\u003C\u002Fp>\u003Cp>This is because the ProcessHider project includes code for identifying and exploiting 64-bit processes\u003C\u002Fp>\u003Ch2>0x02 Implementation Principle of ProcessHider\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implementation flow of the ProcessHider project is as follows:\u003C\u002Fp>\u003Ch3>1. Determine the current operating system version\u003C\u002Fh3>\u003Cp>Corresponding code isSystem64BitWow()\u003C\u002Fp>\u003Cp>For 32-bit systems:\u003C\u002Fp>\u003Ch4>(1) Monitor process list\u003C\u002Fh4>\u003Cp>Corresponding code: LaunchDaemon(InjectAll);\u003C\u002Fp>\u003Ch4>(2) Inject Payload.dll into eligible processes\u003C\u002Fh4>\u003Cp>Corresponding code: reactToProcess((DWORD) pCurrent-&gt;ProcessId, pCurrent-&gt;ImageName.Buffer);\u003C\u002Fp>\u003Cp>The injection code uses code from ReflectiveDLLInjection\u003C\u002Fp>\u003Cp>For 64-bit systems:\u003C\u002Fp>\u003Ch4>(1) Release file x64Hider.exe in the same directory, used as a 64-bit daemon process\u003C\u002Fh4>\u003Cp>Corresponding code: CopyResourceIntoFile(x64filesList[i], MAKEINTRESOURCE(x64resourceIDint[i])\u003C\u002Fp>\u003Ch4>(2) Parse command line parameters\u003C\u002Fh4>\u003Cp>Corresponding code: createCommandLine(argc, argv, buffer, MAX_COMMANDLINE_LEN);\u003C\u002Fp>\u003Ch4>(3) Start the 64-bit daemon process x64Hider.exe\u003C\u002Fh4>\u003Cp>Corresponding code: CreateProcessFromLine(buffer,false);\u003C\u002Fp>\u003Cp>Pass startup parameters\u003C\u002Fp>\u003Cp>Example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"c:\\test\\x64Hider.exe\" \"-n\" \"putty.exe\" \"-x\" \"cmd.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Write Payload.dll into the process space of x64Hider.exe\u003C\u002Fh4>\u003Cp>This process does not write files to the hard disk, increasing stealth\u003C\u002Fp>\u003Cp>Corresponding code: WriteDLLsToProcess(pi)\u003C\u002Fp>\u003Cp>The functions of x64Hider.exe are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Monitor the 64-bit process list\u003C\u002Fli>\u003Cli>Inject 64-bit Payload.dll into eligible 64-bit processes\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>(5) Monitor the 32-bit process list\u003C\u002Fh4>\u003Cp>Corresponding code: LaunchDaemon(InjectAll);\u003C\u002Fp>\u003Ch4>(6) Inject 32-bit Payload.dll into eligible 32-bit processes\u003C\u002Fh4>\u003Cp>Corresponding code: reactToProcess((DWORD) pCurrent-&gt;ProcessId, pCurrent-&gt;ImageName.Buffer);\u003C\u002Fp>\u003Cp>Payload.dll corresponds to the projects x64Payload and x86Payload respectively\u003C\u002Fp>\u003Cp>This is based on ReflectiveDLLInjection for DLL reflection\u003C\u002Fp>\u003Cp>The advantage is that after successful injection, the DLL name does not exist in the process space\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Ch4>1. Create mutex\u003C\u002Fh4>\u003Cp>Corresponding code: hMutex = CreateMutex(0, TRUE, NULL);\u003C\u002Fp>\u003Ch4>2. Read parameters\u003C\u002Fh4>\u003Cp>If parameters are empty, read parameters from the fixed file \"C:\\Program Files\\Internet Explorer\\mdsint.isf\"\u003C\u002Fp>\u003Ch4>3. Hook API NtQuerySystemInformation()\u003C\u002Fh4>\u003Cp>Code for hiding processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NTSTATUS WINAPI HookedNtQuerySystemInformation(\u003Cbr>\t__in       SYSTEM_INFORMATION_CLASS SystemInformationClass,\u003Cbr>\t__inout    PVOID                    SystemInformation,\u003Cbr>\t__in       ULONG                    SystemInformationLength,\u003Cbr>\t__out_opt  PULONG                   ReturnLength\u003Cbr>)\u003Cbr>{\u003Cbr>\tNTSTATUS status = RealNTQueryFunc(SystemInformationClass,\u003Cbr>\t\tSystemInformation,\u003Cbr>\t\tSystemInformationLength,\u003Cbr>\t\tReturnLength);\u003Cbr>\u003Cbr>\tif (SystemProcessInformation == SystemInformationClass &amp;&amp; NT_SUCCESS(status))\u003Cbr>\t{\u003Cbr>\t\t\u002F\u002F\u003Cbr>\t\t\u002F\u002F Loop through the list of processes\u003Cbr>\t\t\u002F\u002F\u003Cbr>\u003Cbr>\t\tPSYSTEM_PROCESS_INFO pCurrent = NULL;\u003Cbr>\t\tPSYSTEM_PROCESS_INFO pNext = (PSYSTEM_PROCESS_INFO)SystemInformation;\u003Cbr>\u003Cbr>\t\tdo\u003Cbr>\t\t{\u003Cbr>\t\t\tpCurrent = pNext;\u003Cbr>\t\t\tpNext = (PSYSTEM_PROCESS_INFO)((PUCHAR)pCurrent + pCurrent-&gt;NextEntryOffset);\u003Cbr>\u003Cbr>\t\t\tif (isHiddenProcess((int)pNext-&gt;ProcessId,pNext-&gt;ImageName.Buffer))\u003Cbr>\t\t\t{\u003Cbr>\t\t\t\tif (0 == pNext-&gt;NextEntryOffset)\u003Cbr>\t\t\t\t{\u003Cbr>\t\t\t\t\tpCurrent-&gt;NextEntryOffset = 0;\u003Cbr>\t\t\t\t}\u003Cbr>\t\t\t\telse\u003Cbr>\t\t\t\t{\u003Cbr>\t\t\t\t\tpCurrent-&gt;NextEntryOffset += pNext-&gt;NextEntryOffset;\u003Cbr>\t\t\t\t}\u003Cbr>\u003Cbr>\t\t\t\tpNext = pCurrent;\u003Cbr>\t\t\t}\u003Cbr>\t\t} while (pCurrent-&gt;NextEntryOffset != 0);\u003Cbr>\t}\u003Cbr>\u003Cbr>\treturn status;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This code is essentially identical to the previously open-sourced AppInitGlobalHooks-Mimikatz code from SubTee.\u003C\u002Fp>\u003Cp>I introduced in a previous article 'Hiding Processes on Windows 7 Using Global API Hooks'\u003C\u002Fp>\u003Cp>SubTee's GitHub is currently inaccessible, but I forked his code at the time, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Therefore, we can achieve the same functionality using the previous code\u003C\u002Fp>\u003Ch4>1. Compile the DLL\u003C\u002Fh4>\u003Cp>Using the code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Compile to generate the DLL\u003C\u002Fp>\u003Ch4>2. Inject the DLL\u003C\u002Fh4>\u003Cp>Here you can use the DLL injection code I wrote earlier, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>But the functionality of FreeDll() needs to be removed\u003C\u002Fp>\u003Cp>In summary, the implementation principle of ProcessHider is as follows:\u003C\u002Fp>\u003Cp>By injecting a DLL to hook the API NtQuerySystemInformation(), process hiding is achieved\u003C\u002Fp>\u003Ch2>0x03 Detection of ProcessHider\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The detection primarily identifies the following behaviors:\u003C\u002Fp>\u003Cul>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Hook API NtQuerySystemInformation()\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0.04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation principles and code details of ProcessHider, analyzes exploitation approaches, and provides detection recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.986Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"ProcessHider Analysis: Hide Processes in Task Manager & Process Explorer","ProcessHider, process hiding, Task Manager, Process Explorer, NtQuerySystemInformation, DLL injection, ReflectiveDLLInjection, NtHookEngine, malware analysis, Windows security",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4],987,986,985,{"title":30,"description":30,"image":30},"2026-07-24T02:07:15.937Z","2026-07-23T16:02:22.081Z","draft","2026-07-23T16:15:55.376Z"]