Jump to content
Tuts 4 You

TitanHide


mrexodia

Recommended Posts

  • Replies 154
  • Created
  • Last Reply

Top Posters In This Topic

  • mrexodia

    60

  • GIV

    13

  • LCF-AT

    11

  • Insid3Code

    9

Top Posters In This Topic

Popular Posts

Overview:TitanHide is a driver intended to hide debuggers from certain processes.The driver hooks various Nt* kernel functions (using inline hooks at themoment) and modifies the return values of the o

I, After some talking with deepzero, I realized that the hooking model is completely unreliable. It is therefore not recommended to use this driver outside of a VM, because you eventually WILl get

Updated to V0013! Changelog: - MIT license - crappy win10 support - fixed some exploits kao found - hopefully now the .sys works on win7 (target = win7 instead of win8.1) Download: https://

Posted Images

mrexodia

It looks to me like TESTSIGNING doesn't work. If I use a clean kernel without patches and enable TESTSIGNING it will not load TitanHide.sys, which is weird because it should.

  • Like 1
Link to post
  • 2 months later...

Win 7 x64, c:\Windows\System32\drivers\TitanHide.sys - cmd->sc start TitanHide -- File not found. After replacing with x32 TitanHide.sys -- error loading driver. Have not idea what kind of file not found.

Link to post
Insid3Code

Link to download TitanHide package recompiled (msvc 2015 U1) and flash demo...
Tested on Windows 7.1 64bit and Windows 8.1 64bit...

http://www.mediafire.com/download/o52b5ptm1lz3qu6/titanhide.rar

 

  • Like 3
Link to post
mrexodia
10 hours ago, Insid3Code said:

Link to download TitanHide package recompiled (msvc 2015 U1) and flash demo...
Tested on Windows 7.1 64bit and Windows 8.1 64bit...


http://www.mediafire.com/download/o52b5ptm1lz3qu6/titanhide.rar

 

Mirror: https://mega.nz/#!m5AmlLrZ!EFpzM1uvilbOwYVCYtf4V_HV5mJcitPWpmJ0EdCLszA

Did you change anything worth mentioning to the code?

Greetings

Link to post
  • 4 weeks later...
On 15.03.2016 at 11:34 AM, Insid3Code said:

Link to download TitanHide package recompiled (msvc 2015 U1) and flash demo...
Tested on Windows 7.1 64bit and Windows 8.1 64bit...


http://www.mediafire.com/download/o52b5ptm1lz3qu6/titanhide.rar

 

Hi.

After using your package in Win7X64 SP1 i get the same "Windows require a digitally signed driver" error (in fact is the same thing i did many times before). 

Can you share your ISO file for your Windows7 X64 you used in this demo?

I suspect i use a "wrong" OS build.

:)

Link to post

In other order of ideas.

I have try on some Win7X64SP1 builds and the driver install failed.

Could anyone post a link to a build of Win 7 that this driver works?

Link to post
mrexodia
On 4/18/2016 at 7:34 AM, GIV said:

In other order of ideas.

I have try on some Win7X64SP1 builds and the driver install failed.

Could anyone post a link to a build of Win 7 that this driver works?

You might want to recompile the driver on Windows 7 yourself. The video that @Insid3Code made probably has the driver compiled for 7.1 (you can check the MinVersion thing in the PE header).

Link to post

I guess that the driver is not the problem.

The problem is that the patches shown for driver signature does not work in my build of Win7.

I am wrong?

Link to post
Insid3Code

Hi,

Quote

Can you share your ISO file for your Windows7 X64 you used in this demo?

http://176.99.4.36/Windows%207/Eng/en_windows_7_ultimate_with_sp1_x64_dvd_u_677332.iso
http://176.99.4.36/Windows%207/Eng/

Another iso from the net, you can download and test it, it works with KPP Destroyer...

Before patching:

W1B0icz.gif?1

U4EJqy4.gif?1

 

After Patching (with KPP Destroyer ):

FHCKHCZ.gif?1

wXtVsp7.gif?1

 

So, if you get the following warning message, is just a notification, the patch work fine and the driver is loaded successfully...

3MYoQK6.gif?1

  • Like 3
Link to post
  • 4 months later...
  • 11 months later...
On 4/22/2016 at 3:42 PM, Insid3Code said:

Hi,


http://176.99.4.36/Windows%207/Eng/en_windows_7_ultimate_with_sp1_x64_dvd_u_677332.iso
http://176.99.4.36/Windows%207/Eng/

Another iso from the net, you can download and test it, it works with KPP Destroyer...

Before patching:

W1B0icz.gif?1

U4EJqy4.gif?1

 

After Patching (with KPP Destroyer ):

FHCKHCZ.gif?1

wXtVsp7.gif?1

 

So, if you get the following warning message, is just a notification, the patch work fine and the driver is loaded successfully...

3MYoQK6.gif?1

win 10 64

i patched the kernel(not sure if correctly)

i create service but when starting it, i get " a device attached to the system is not functioning"

also got that warning msg.the one you say is not a problem

in past i remember i could start it but blue crash afterwards

Edited by abbas (see edit history)
Link to post
1 hour ago, mrexodia said:

Don't forget to actually select the patched kernel on boot...

i do

but still signature error.

a couple months ago i could disable SE but win crashed due to kpp.now i cannot enter test mode.i dont know if the patch is correclty done.how can i test is kpp is disabled?

https://ibb.co/cwnAzv

Edited by abbas (see edit history)
Link to post
10 hours ago, mrexodia said:

Just install a fresh vm :D You shouldn't run this on your actual PC anyway...

if theres any build/version of windows working let me know.as far as i seen in this thread people had issues with even win 7 64

Link to post
40 minutes ago, mrexodia said:

I got TitanHide to work on all versions of Windows (XP-10) 

so why i cannot?!?!?

is there any way to test if kpp is disabled or not?

Edited by abbas (see edit history)
Link to post
mrexodia
On 8/11/2017 at 3:32 PM, abbas said:

so why i cannot?!?!?

If it takes too much time it means you are not ready to use TitanHide:

na7PLGo.png

 

  • Like 1
Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×
×
  • Create New...