Flag: Tornado! Hurricane!

Other: ADHD - Another Debugger Hiding Driver

File Information
Category Open Source # Downloads Version
Other Yes 5,145 0.0.8

Download from OpenRCE
MD5 Sum: 1B6DFB7882C12A92910D8288D5199138

Last updated on Oct 5, 2006.

Author Information
Username Name E-Mail URL
 AlanBradley Alan Bradley abradleyfastmailfm http://

Description ADHD - Another Debugger Hiding Driver

This is a kernel driver that obscures some of the ways a debugger can be detected in Userland.

1. Resets PEB->BeingDebugged flag
2. Hooks ZwQueryInformationProcess to zero DebugPort
3. Protects DbgUiRemoteBreakin and DbgBreakpoint from modifications
4. Resets parent PID to explorer.exe
5. Blocks ZwSetInformationProcess(ThreadHideFromDebugger)

Stuff you still need to do:

1. Exception re-delivery. This is handled by good userland debuggers.
2. Hide your debugger process with FUTo.
3. Obfuscate your debugger's title with an injected DLL (Use CLU+Tron)
4. Software breakpoint scanning (Use CLU+Tron)
5. Wall clock time (script your debugger or use tracing)

There are 31,038 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit