[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsutalayjFy9QmdToacdrsNy7EfZ8U69x5HKVN7rHaOk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},987,"What methods can be used to detect ProcessHider activity?","Detection focuses on identifying DLL injection and API hooking. Monitoring for unexpected DLLs loaded into processes and checking for hooks on NtQuerySystemInformation() are key. Security tools can also look for reflective DLL injection artifacts and unusual process creation, such as the appearance of x64Hider.exe. The [ProcessHider Utilization Analysis](\u002Fnews\u002Fprocesshider-utilization-analysis) provides additional detection recommendations.","\u003Cp>Detection focuses on identifying DLL injection and API hooking. Monitoring for unexpected DLLs loaded into processes and checking for hooks on NtQuerySystemInformation() are key. Security tools can also look for reflective DLL injection artifacts and unusual process creation, such as the appearance of x64Hider.exe. The [ProcessHider Utilization Analysis](\u002Fnews\u002Fprocesshider-utilization-analysis) provides additional detection recommendations.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fprocesshider-utilization-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-methods-can-be-used-to-detect-processhider-activity-1777481011636","detection, DLL injection, NtQuerySystemInformation hook, reflective DLL injection, monitoring",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},241,"ProcessHider Utilization Analysis","processhider-utilization-analysis","Analyze ProcessHider's implementation, code details, and detection methods for hiding processes in monitoring tools like Task Manager and Process Explorer.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ProcessHider can hide specified processes in monitoring tools such as Task Manager and Process Explorer. This article will introduce its implementation principles and analyze code details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>ProcessHider Testing\u003C\u002Fli>\u003Cli>Implementation Principles of ProcessHider\u003C\u002Fli>\u003Cli>Code Analysis of ProcessHider\u003C\u002Fli>\u003Cli>Detection of ProcessHider\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ProcessHider can hide specified processes in monitoring tools such as Task Manager and Process Explorer\u003C\u002Fp>\u003Cp>The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FM00nRise\u002FProcessHider\u003C\u002Fp>\u003Cp>Supports the following parameters:\u003C\u002Fp>\u003Cul>\u003Cli>pid\u003C\u002Fli>\u003Cli>process name\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Two startup forms:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003C\u002Ful>\u003Cp>ProcessHider can automatically identify the operating system version and process bitness, inject Payload.dll into 32-bit and 64-bit processes respectively, and achieve process hiding by hooking the API NtQuerySystemInformation()\u003C\u002Fp>\u003Cp>The injected code uses DLL reflection, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstephenfewer\u002FReflectiveDLLInjection\u003C\u002Fp>\u003Cp>The hook code uses NtHookEngine, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F21414\u002FPowerful-x86-x64-Mini-Hook-Engine\u003C\u002Fp>\u003Cp>Parameter example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ProcessHider.exe -n \"putty.exe\" -x \"procexp.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can hide the process named putty.exe in procexp.exe, and by default hides the following processes:\u003C\u002Fp>\u003Cul>\u003Cli>Taskmgr.exe\u003C\u002Fli>\u003Cli>powershell.exe\u003C\u002Fli>\u003Cli>procexp.exe\u003C\u002Fli>\u003Cli>procexp64.exe\u003C\u002Fli>\u003Cli>perfmon.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Currently, hiding the tasklist.exe process is not supported\u003C\u002Fp>\u003Cp>Issues to note during compilation:\u003C\u002Fp>\u003Cp>The ProcessHider project must be compiled as 32-bit, not 64-bit\u003C\u002Fp>\u003Cp>This is because the ProcessHider project includes code for identifying and exploiting 64-bit processes\u003C\u002Fp>\u003Ch2>0x02 Implementation Principle of ProcessHider\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The implementation flow of the ProcessHider project is as follows:\u003C\u002Fp>\u003Ch3>1. Determine the current operating system version\u003C\u002Fh3>\u003Cp>Corresponding code isSystem64BitWow()\u003C\u002Fp>\u003Cp>For 32-bit systems:\u003C\u002Fp>\u003Ch4>(1) Monitor process list\u003C\u002Fh4>\u003Cp>Corresponding code: LaunchDaemon(InjectAll);\u003C\u002Fp>\u003Ch4>(2) Inject Payload.dll into eligible processes\u003C\u002Fh4>\u003Cp>Corresponding code: reactToProcess((DWORD) pCurrent-&gt;ProcessId, pCurrent-&gt;ImageName.Buffer);\u003C\u002Fp>\u003Cp>The injection code uses code from ReflectiveDLLInjection\u003C\u002Fp>\u003Cp>For 64-bit systems:\u003C\u002Fp>\u003Ch4>(1) Release file x64Hider.exe in the same directory, used as a 64-bit daemon process\u003C\u002Fh4>\u003Cp>Corresponding code: CopyResourceIntoFile(x64filesList[i], MAKEINTRESOURCE(x64resourceIDint[i])\u003C\u002Fp>\u003Ch4>(2) Parse command line parameters\u003C\u002Fh4>\u003Cp>Corresponding code: createCommandLine(argc, argv, buffer, MAX_COMMANDLINE_LEN);\u003C\u002Fp>\u003Ch4>(3) Start the 64-bit daemon process x64Hider.exe\u003C\u002Fh4>\u003Cp>Corresponding code: CreateProcessFromLine(buffer,false);\u003C\u002Fp>\u003Cp>Pass startup parameters\u003C\u002Fp>\u003Cp>Example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"c:\\test\\x64Hider.exe\" \"-n\" \"putty.exe\" \"-x\" \"cmd.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Write Payload.dll into the process space of x64Hider.exe\u003C\u002Fh4>\u003Cp>This process does not write files to the hard disk, increasing stealth\u003C\u002Fp>\u003Cp>Corresponding code: WriteDLLsToProcess(pi)\u003C\u002Fp>\u003Cp>The functions of x64Hider.exe are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Monitor the 64-bit process list\u003C\u002Fli>\u003Cli>Inject 64-bit Payload.dll into eligible 64-bit processes\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>(5) Monitor the 32-bit process list\u003C\u002Fh4>\u003Cp>Corresponding code: LaunchDaemon(InjectAll);\u003C\u002Fp>\u003Ch4>(6) Inject 32-bit Payload.dll into eligible 32-bit processes\u003C\u002Fh4>\u003Cp>Corresponding code: reactToProcess((DWORD) pCurrent-&gt;ProcessId, pCurrent-&gt;ImageName.Buffer);\u003C\u002Fp>\u003Cp>Payload.dll corresponds to the projects x64Payload and x86Payload respectively\u003C\u002Fp>\u003Cp>This is based on ReflectiveDLLInjection for DLL reflection\u003C\u002Fp>\u003Cp>The advantage is that after successful injection, the DLL name does not exist in the process space\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Ch4>1. Create mutex\u003C\u002Fh4>\u003Cp>Corresponding code: hMutex = CreateMutex(0, TRUE, NULL);\u003C\u002Fp>\u003Ch4>2. Read parameters\u003C\u002Fh4>\u003Cp>If parameters are empty, read parameters from the fixed file \"C:\\Program Files\\Internet Explorer\\mdsint.isf\"\u003C\u002Fp>\u003Ch4>3. Hook API NtQuerySystemInformation()\u003C\u002Fh4>\u003Cp>Code for hiding processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NTSTATUS WINAPI HookedNtQuerySystemInformation(\u003Cbr>\t__in       SYSTEM_INFORMATION_CLASS SystemInformationClass,\u003Cbr>\t__inout    PVOID                    SystemInformation,\u003Cbr>\t__in       ULONG                    SystemInformationLength,\u003Cbr>\t__out_opt  PULONG                   ReturnLength\u003Cbr>)\u003Cbr>{\u003Cbr>\tNTSTATUS status = RealNTQueryFunc(SystemInformationClass,\u003Cbr>\t\tSystemInformation,\u003Cbr>\t\tSystemInformationLength,\u003Cbr>\t\tReturnLength);\u003Cbr>\u003Cbr>\tif (SystemProcessInformation == SystemInformationClass &amp;&amp; NT_SUCCESS(status))\u003Cbr>\t{\u003Cbr>\t\t\u002F\u002F\u003Cbr>\t\t\u002F\u002F Loop through the list of processes\u003Cbr>\t\t\u002F\u002F\u003Cbr>\u003Cbr>\t\tPSYSTEM_PROCESS_INFO pCurrent = NULL;\u003Cbr>\t\tPSYSTEM_PROCESS_INFO pNext = (PSYSTEM_PROCESS_INFO)SystemInformation;\u003Cbr>\u003Cbr>\t\tdo\u003Cbr>\t\t{\u003Cbr>\t\t\tpCurrent = pNext;\u003Cbr>\t\t\tpNext = (PSYSTEM_PROCESS_INFO)((PUCHAR)pCurrent + pCurrent-&gt;NextEntryOffset);\u003Cbr>\u003Cbr>\t\t\tif (isHiddenProcess((int)pNext-&gt;ProcessId,pNext-&gt;ImageName.Buffer))\u003Cbr>\t\t\t{\u003Cbr>\t\t\t\tif (0 == pNext-&gt;NextEntryOffset)\u003Cbr>\t\t\t\t{\u003Cbr>\t\t\t\t\tpCurrent-&gt;NextEntryOffset = 0;\u003Cbr>\t\t\t\t}\u003Cbr>\t\t\t\telse\u003Cbr>\t\t\t\t{\u003Cbr>\t\t\t\t\tpCurrent-&gt;NextEntryOffset += pNext-&gt;NextEntryOffset;\u003Cbr>\t\t\t\t}\u003Cbr>\u003Cbr>\t\t\t\tpNext = pCurrent;\u003Cbr>\t\t\t}\u003Cbr>\t\t} while (pCurrent-&gt;NextEntryOffset != 0);\u003Cbr>\t}\u003Cbr>\u003Cbr>\treturn status;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This code is essentially identical to the previously open-sourced AppInitGlobalHooks-Mimikatz code from SubTee.\u003C\u002Fp>\u003Cp>I introduced in a previous article 'Hiding Processes on Windows 7 Using Global API Hooks'\u003C\u002Fp>\u003Cp>SubTee's GitHub is currently inaccessible, but I forked his code at the time, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Therefore, we can achieve the same functionality using the previous code\u003C\u002Fp>\u003Ch4>1. Compile the DLL\u003C\u002Fh4>\u003Cp>Using the code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Compile to generate the DLL\u003C\u002Fp>\u003Ch4>2. Inject the DLL\u003C\u002Fh4>\u003Cp>Here you can use the DLL injection code I wrote earlier, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>But the functionality of FreeDll() needs to be removed\u003C\u002Fp>\u003Cp>In summary, the implementation principle of ProcessHider is as follows:\u003C\u002Fp>\u003Cp>By injecting a DLL to hook the API NtQuerySystemInformation(), process hiding is achieved\u003C\u002Fp>\u003Ch2>0x03 Detection of ProcessHider\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The detection primarily identifies the following behaviors:\u003C\u002Fp>\u003Cul>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Hook API NtQuerySystemInformation()\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0.04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation principles and code details of ProcessHider, analyzes exploitation approaches, and provides detection recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.986Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"ProcessHider Analysis: Hide Processes in Task Manager & Process Explorer","ProcessHider, process hiding, Task Manager, Process Explorer, NtQuerySystemInformation, DLL injection, ReflectiveDLLInjection, NtHookEngine, malware analysis, Windows security",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44],986,985,984,{"title":30,"description":30,"image":30},"2026-07-24T02:07:15.937Z","2026-07-23T16:02:22.081Z","draft","2026-07-23T16:15:56.138Z"]