[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTaoe7f_JoOZuqz44lvaPzkKNt5ovG4mk30r0z3eVK8E":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1051,"What are some ways to defend against process hiding via global API hooks?","On Windows 7 and earlier systems, check the registry keys `AppInit_DLLs` under both the standard and Wow6432Node paths for any suspicious DLL paths. Also use Process Explorer (with administrator privileges) to inspect loaded DLLs in all processes. Enabling `RequireSignedAppInit_DLLs` can also block unsigned hook DLLs. These defensive measures are outlined in [Using global API hooks to hide processes on Windows 7 systems](\u002Fnews\u002Fusing-global-api-hooks-to-hide-processes-on-windows-7-systems).","\u003Cp>On Windows 7 and earlier systems, check the registry keys `AppInit_DLLs` under both the standard and Wow6432Node paths for any suspicious DLL paths. Also use Process Explorer (with administrator privileges) to inspect loaded DLLs in all processes. Enabling `RequireSignedAppInit_DLLs` can also block unsigned hook DLLs. These defensive measures are outlined in [Using global API hooks to hide processes on Windows 7 systems](\u002Fnews\u002Fusing-global-api-hooks-to-hide-processes-on-windows-7-systems).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fusing-global-api-hooks-to-hide-processes-on-windows-7-systems\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-some-ways-to-defend-against-process-hiding-via-global-api-hooks-1777480800943","defense, Process Explorer, registry audit, signed DLLs, AppInit_DLLs detection",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},256,"Using global API hooks to hide processes on Windows 7 systems","using-global-api-hooks-to-hide-processes-on-windows-7-systems","Learn to hide processes on Windows 7 using global API hooks via AppInit_DLLs registry tweaks. Works instantly on x64\u002Fx86 without reboots.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Powershell tricks::Hide Process by kd.exe', the technique of hiding processes via kd.exe was introduced, with the main drawback being the need to enable Local kernel debugging mode and wait for a system restart to take effect.\u003C\u002Fp>\u003Cp>This time, another method for hiding processes is introduced—using global API hooks.\u003C\u002Fp>\u003Cp>The advantage is that it takes effect immediately without waiting for a system restart.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will refer to Sergey Podobry's work to introduce this method, analyze the details to note in practical testing, and supplement the specific parameter settings for 64-bit systems.\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference links:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002Farticles\u002F49319\u002Feasy-way-to-set-up-global-api-hooks?display=print\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u003C\u002Fp>\u003Ch2>0x02 Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>At the user level, the test DLL is injected into all system processes via global API hooks to achieve the hiding of specified processes.\u003C\u002Fp>\u003Ch3>hook method\u003C\u002Fh3>\u003Cp>modify registry key AppInit_DLLs\u003C\u002Fp>\u003Cp>\u003Cstrong>location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\u003C\u002Fp>\u003Cp>\u003Cstrong>parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>LoadAppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_DWORD)\tValue that globally enables or disables AppInit_DLLs.\u003C\u002Fp>\u003Cul>\u003Cli>0x0 – AppInit_DLLs are disabled.\u003C\u002Fli>\u003Cli>0x1 – AppInit_DLLs are enabled.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>AppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_SZ)\u003C\u002Fp>\u003Cp>Space - or comma -separated list of DLLs to load. The complete path to the DLL should be specified using short file names.\tC:\\PROGRA~1\\Test\\Test.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>RequireSignedAppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_DWORD)\tRequire code-signed DLLs.\u003C\u002Fp>\u003Cul>\u003Cli>0x0 – Load any DLLs.\u003C\u002Fli>\u003Cli>0x1 – Load only code-signed DLLs.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Code Implementation\u003C\u002Fh3>\u003Cp>Implement API hooking via Mhook library\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Open source\u003C\u002Fli>\u003Cli>Supports x86 and x64\u003C\u002Fli>\u003Cli>Easy to use\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcodefromthe70s.org\u002Fmhook22.aspx\u003C\u002Fp>\u003Ch2>0x03 Practical Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Testing Environment:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7x86\u003C\u002Fp>\u003Ch3>1. Set registry key AppInit_DLLs\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u002Fblob\u002Fmaster\u002FAppInit.reg\u003C\u002Fp>\u003Cp>The .reg file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003Cbr>\"AppInit_DLLs\"=\"C:\\\\Tools\\\\AppInitHookx64.dll,C:\\\\Tools\\\\AppInitHook.dll\"\u003Cbr>\"LoadAppInit_DLLs\"=dword:00000001\u003Cbr>\"RequireSignedAppInit_DLLs\"=dword:00000000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates\u003C\u002Fp>\u003Cul>\u003Cli>AppInit_DLLs are enabled\u003C\u002Fli>\u003Cli>Load any DLLs, do not need code-signed DLLs\u003C\u002Fli>\u003Cli>DLL path: C:\\\\Tools\\\\AppInitHookx64.dll,C:\\\\Tools\\\\AppInitHook.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The set path must not contain spaces, otherwise it will be invalid\u003C\u002Fp>\u003Ch3>2. Compile and generate AppInitHook.dll and place it under C:\\Tools\u003C\u002Fh3>\u003Cp>Reference project:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u003C\u002Fp>\u003Ch3>3. Run mimikatz.exe\u003C\u002Fh3>\u003Cp>Task Manager process list does not contain mimikatz.exe\u003C\u002Fp>\u003Cp>Process Explorer does not show mimikatz.exe\u003C\u002Fp>\u003Cp>Tasklist.exe does not display mimikatz.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The process is not completely hidden here; the process name is set to conhost.exe because mimikatz is a console application\u003C\u002Fp>\u003Cp>If replaced with a Win32 project like putty.exe or calc.exe, this issue does not exist, and the process can be completely hidden\u003C\u002Fp>\u003Cp>Using Process Explorer to view the newly created processes, all have loaded AppInitHook.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015588827_0_9c6235fa50.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Run Process Explorer with administrator privileges to view DLLs loaded by high-privilege processes\u003C\u002Fp>\u003Ch3>4. Win7x64 Testing\u003C\u002Fh3>\u003Cp>The difference between 64-bit and 32-bit systems is also reflected in the registry\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'Notes on Redirection Issues When Running 32-bit Programs on 64-bit Systems'.\u003C\u002Fp>\u003Cp>Registry location for 64-bit programs:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\\u003C\u002Fp>\u003Cp>Registry location for 32-bit programs:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\\u003C\u002Fp>\u003Cp>Therefore, to hook all processes (both 32-bit and 64-bit) on a 64-bit system, two registry key values need to be modified.\u003C\u002Fp>\u003Cp>Registry key location for 64-bit:\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>Registry key location for 32-bit:\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>The specific modification code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>After modification, view using Process Explorer as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015594286_1_289a9f26c7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015597795_2_44dc1e3bb3.jpeg\">\u003C\u002Fp>\u003Cp>Successfully injected into 32-bit and 64-bit processes\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method only supports Windows 7 and Windows Server 2008 R2, and does not support higher versions such as Windows 8 or Server 2012\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015600331_3_cfb83f0316.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure above, on Windows 8 systems, although AppInitHook.dll is successfully loaded, the process cannot be hidden\u003C\u002Fp>\u003Cp>\u003Cstrong>Reasons are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Starting from Windows 8, Microsoft imposed restrictions on AppInit_DLLs: the secure boot enabled by default in the BIOS will disable AppInit_DLLs, rendering it ineffective\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdn280412(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Only applicable to Windows 7, Windows Server 2008 R2, and earlier systems\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Check the registry key value\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WindowsNT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>Check AppInit_DLLs for suspicious DLL paths\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Use Process Explorer to check if processes have loaded suspicious DLLs\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of hiding processes using global API hooks in Windows 7 systems. Combined with exploitation concepts, it helps everyone better defend against this type of attack.\u003C\u002Fp>\u003Cp>Of course, global API hooks can be used for much more than this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Powershell tricks::Hide Process by kd.exe', the technique of hiding processes via kd.exe was introduced, with the main drawback being the need to enable Local kernel debugging mode and wait for a system restart to take effect.\u003C\u002Fp>\u003Cp>This time, another method for hiding processes is introduced—using global API hooks.\u003C\u002Fp>\u003Cp>The advantage is that it takes effect immediately without waiting for a system restart.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will refer to Sergey Podobry's work to introduce this method, analyze the details to note in practical testing, and supplement the specific parameter settings for 64-bit systems.\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference links:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002Farticles\u002F49319\u002Feasy-way-to-set-up-global-api-hooks?display=print\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u003C\u002Fp>\u003Ch2>0x02 Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>At the user level, the test DLL is injected into all system processes via global API hooks to achieve the hiding of specified processes.\u003C\u002Fp>\u003Ch3>hook method\u003C\u002Fh3>\u003Cp>modify registry key AppInit_DLLs\u003C\u002Fp>\u003Cp>\u003Cstrong>location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\u003C\u002Fp>\u003Cp>\u003Cstrong>parameter description:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>LoadAppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_DWORD)\tValue that globally enables or disables AppInit_DLLs.\u003C\u002Fp>\u003Cul>\u003Cli>0x0 – AppInit_DLLs are disabled.\u003C\u002Fli>\u003Cli>0x1 – AppInit_DLLs are enabled.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>AppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_SZ)\u003C\u002Fp>\u003Cp>Space - or comma -separated list of DLLs to load. The complete path to the DLL should be specified using short file names.\tC:\\PROGRA~1\\Test\\Test.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>RequireSignedAppInit_DLLs:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(REG_DWORD)\tRequire code-signed DLLs.\u003C\u002Fp>\u003Cul>\u003Cli>0x0 – Load any DLLs.\u003C\u002Fli>\u003Cli>0x1 – Load only code-signed DLLs.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Code Implementation\u003C\u002Fh3>\u003Cp>Implement API hooking via Mhook library\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Open source\u003C\u002Fli>\u003Cli>Supports x86 and x64\u003C\u002Fli>\u003Cli>Easy to use\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Reference URL:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcodefromthe70s.org\u002Fmhook22.aspx\u003C\u002Fp>\u003Ch2>0x03 Practical Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Testing Environment:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7x86\u003C\u002Fp>\u003Ch3>1. Set registry key AppInit_DLLs\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u002Fblob\u002Fmaster\u002FAppInit.reg\u003C\u002Fp>\u003Cp>The .reg file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>\u003Cbr>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003Cbr>\"AppInit_DLLs\"=\"C:\\\\Tools\\\\AppInitHookx64.dll,C:\\\\Tools\\\\AppInitHook.dll\"\u003Cbr>\"LoadAppInit_DLLs\"=dword:00000001\u003Cbr>\"RequireSignedAppInit_DLLs\"=dword:00000000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates\u003C\u002Fp>\u003Cul>\u003Cli>AppInit_DLLs are enabled\u003C\u002Fli>\u003Cli>Load any DLLs, do not need code-signed DLLs\u003C\u002Fli>\u003Cli>DLL path: C:\\\\Tools\\\\AppInitHookx64.dll,C:\\\\Tools\\\\AppInitHook.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The set path must not contain spaces, otherwise it will be invalid\u003C\u002Fp>\u003Ch3>2. Compile and generate AppInitHook.dll and place it under C:\\Tools\u003C\u002Fh3>\u003Cp>Reference project:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FsubTee\u002FAppInitGlobalHooks-Mimikatz\u003C\u002Fp>\u003Ch3>3. Run mimikatz.exe\u003C\u002Fh3>\u003Cp>Task Manager process list does not contain mimikatz.exe\u003C\u002Fp>\u003Cp>Process Explorer does not show mimikatz.exe\u003C\u002Fp>\u003Cp>Tasklist.exe does not display mimikatz.exe\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The process is not completely hidden here; the process name is set to conhost.exe because mimikatz is a console application\u003C\u002Fp>\u003Cp>If replaced with a Win32 project like putty.exe or calc.exe, this issue does not exist, and the process can be completely hidden\u003C\u002Fp>\u003Cp>Using Process Explorer to view the newly created processes, all have loaded AppInitHook.dll, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015588827_0_9c6235fa50-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Run Process Explorer with administrator privileges to view DLLs loaded by high-privilege processes\u003C\u002Fp>\u003Ch3>4. Win7x64 Testing\u003C\u002Fh3>\u003Cp>The difference between 64-bit and 32-bit systems is also reflected in the registry\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'Notes on Redirection Issues When Running 32-bit Programs on 64-bit Systems'.\u003C\u002Fp>\u003Cp>Registry location for 64-bit programs:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\\u003C\u002Fp>\u003Cp>Registry location for 32-bit programs:\u003C\u002Fp>\u003Cp>HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\\u003C\u002Fp>\u003Cp>Therefore, to hook all processes (both 32-bit and 64-bit) on a 64-bit system, two registry key values need to be modified.\u003C\u002Fp>\u003Cp>Registry key location for 64-bit:\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>Registry key location for 32-bit:\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>The specific modification code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>After modification, view using Process Explorer as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015594286_1_289a9f26c7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015597795_2_44dc1e3bb3-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully injected into 32-bit and 64-bit processes\u003C\u002Fp>\u003Ch2>0x04 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method only supports Windows 7 and Windows Server 2008 R2, and does not support higher versions such as Windows 8 or Server 2012\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015600331_3_cfb83f0316-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure above, on Windows 8 systems, although AppInitHook.dll is successfully loaded, the process cannot be hidden\u003C\u002Fp>\u003Cp>\u003Cstrong>Reasons are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Starting from Windows 8, Microsoft imposed restrictions on AppInit_DLLs: the secure boot enabled by default in the BIOS will disable AppInit_DLLs, rendering it ineffective\u003C\u002Fp>\u003Cp>For details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdn280412(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Only applicable to Windows 7, Windows Server 2008 R2, and earlier systems\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Check the registry key value\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WindowsNT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows]\u003C\u002Fp>\u003Cp>Check AppInit_DLLs for suspicious DLL paths\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Use Process Explorer to check if processes have loaded suspicious DLLs\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of hiding processes using global API hooks in Windows 7 systems. Combined with exploitation concepts, it helps everyone better defend against this type of attack.\u003C\u002Fp>\u003Cp>Of course, global API hooks can be used for much more than this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",346,"Onedaysec",3,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Hide Windows Processes with Global API Hooks on Win7","Windows 7 process hiding, global API hooks, AppInit_DLLs, registry modification, stealth techniques, x64 x86 systems, Mhook library, mimikatz, DLL injection",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],1050,1049,1048,1047,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.990Z","2026-07-23T16:02:28.582Z","draft","2026-07-23T16:16:20.216Z"]