<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Tool_Hiding_Tools/feed?recursive=1&amp;feed_type=atom</id>
		<title>Collaborative RCE Tool Library - Tool Hiding Tools (including sub-categories)</title>
		<link rel="self" type="application/atom+xml" href="http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Tool_Hiding_Tools/feed?recursive=1&amp;feed_type=atom"/>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Tool_Hiding_Tools/feed?recursive=1&amp;feed_type=atom"/>
		<updated>2009-11-21T09:38:40Z</updated>
		<subtitle>Update Notification Feed for Category: Tool Hiding Tools (and its sub-categories)</subtitle>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/IDA_Stealth</id>
		<title>Tool Updated: IDA Stealth</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/IDA_Stealth"/>
				<updated>2009-11-15T23:45:08Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:IDA_Extensions&quot;&gt;IDA Extensions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tool_Hiding_Tools&quot;&gt;Tool Hiding Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.1&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;November 15, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;IDA Stealth is a plugin which aims to hide the IDA debugger from most common anti-debugging techniques. The plugin is composed of two files, the plugin itself and a dll which is injected into the debuggee as soon as the debugger attaches to the process. The injected dll is actually responsible for implementing most of the stealth techniques either by hooking syscalls or by patching some flags in the remote process.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/HideToolz</id>
		<title>Tool Updated: HideToolz</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/HideToolz"/>
				<updated>2009-10-03T23:38:21Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tool_Hiding_Tools&quot;&gt;Tool Hiding Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;2.2&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;October 3, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;This is version 2.2 of HideToolz.  Version 2.1 did not work on Windows Vista SP1 or higher.  I have modified the device driver so HideToolz now works on Vista SP1 through Windows 7 RTM.&lt;br /&gt;&lt;br /&gt;-Fyyre&lt;br /&gt;&lt;br /&gt;- - -&lt;br /&gt;&lt;br /&gt;HideToolz is a configurable GUI based utilility that allows hiding of RCE tools from annoying detection (such as Themida). It does so by kernel mode driver which hooks functions such as NtQueryInformationProcess, NtSetContextThread, NtQuerySystemInformation, NtOpenProcess, NtOpenThread, etc... allowing you to debug 'protected' applications easily.&lt;br /&gt;&lt;br /&gt;Features include:&lt;br /&gt;&lt;br /&gt;Hide Processes&lt;br /&gt;Protect Processes&lt;br /&gt;Hide Windows&lt;br /&gt;Protection from Windows hooks&lt;br /&gt;Emulation of partent process (sets parent pid of target PID to explorer.exe).&lt;br /&gt;Anti-Anti debug features.&lt;br /&gt;&lt;br /&gt;Runs very stable under Windows XP through Windows 7 (x86 only). Please be aware some anti-virus detections HideToolz driver as a rootkit - this is basically correct, except HideToolz contains no payload, does not access any network api, etc... if you doubt, disasm the driver yourself.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/IceStealth</id>
		<title>Tool Updated: IceStealth</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/IceStealth"/>
				<updated>2009-08-28T01:41:26Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:SoftICE_Extensions&quot;&gt;SoftICE Extensions&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tool_Hiding_Tools&quot;&gt;Tool Hiding Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.69&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;August  28, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;IceStealth is a SoftICE hiding tool, that should protect from:&lt;br /&gt;&lt;br /&gt;CreateFileA, CreateFileW, NtCreateFile, also nmtrans.dll wont find SoftICE with these methods&lt;br /&gt;NtQueryDirectoryObject&lt;br /&gt;NtQueryObject&lt;br /&gt;OpenServiceA, OpenServiceW, EnumServicesStatusA,EnumServicesStatusW,EnumServicesStatusExA, EnumServicesStatusExW&lt;br /&gt;UnhandledExceptionFilter (2 Options)&lt;br /&gt;SEH BPM Protection&lt;br /&gt;BPM Protection&lt;br /&gt;NtQuerySystemInformation&lt;br /&gt;int 41 killed + DPL 0        &lt;br /&gt;int 1 DPL 0&lt;br /&gt;Basic Registry Protection (if ever needed)&lt;br /&gt;(RegOpenKeyExA, RegOpenKeyExW, RegOpenKeyA, RegOpenKeyW)&lt;br /&gt;SaveDisk Protection&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/XFile</id>
		<title>Tool Updated: XFile</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/XFile"/>
				<updated>2008-09-20T23:56:28Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tool_Hiding_Tools&quot;&gt;Tool Hiding Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.4.0.36&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 17, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;xFile 1.4.0.36 by anorganix&lt;br /&gt;---------------------------&lt;br /&gt;&lt;br /&gt;The File Update Module increases the size of a file to the specified value. Just enter the &amp;quot;Desired Size&amp;quot; in bytes and you're all set. Works with all file types, with compressed/packed files also, but files with integrity check are not supported. Also, backup option has been implemented.&lt;br /&gt;&lt;br /&gt;The Hide Caption Tool is ideal for hiding the caption of any application. Just build a list with the full/partial captions you want to hide and hit Enable. Changes apply in realtime and checks are made often to hide all instances of the application.&lt;br /&gt;&lt;br /&gt;The Junk Cleanup Module is useful for deleting Olly's UDD and BAK files. Also, there is an option to backup files before deletion (ZIP).&lt;br /&gt;&lt;br /&gt;NEW! The Resource Fix Module (based on DreamTheatre's engine) comes in handy after unpacking. Just rebuild the resources, so that you can edit them without crashing the program. You can also dump the resources to file.&lt;br /&gt;&lt;br /&gt;Additional features:&lt;br /&gt;* Drag and Drop support&lt;br /&gt;* file CRC Calculator&lt;br /&gt;* auto-refresh of UDD folder&lt;br /&gt;* auto-save settings&lt;br /&gt;* Hide Caption works faster (Partial Captions are now supported)&lt;br /&gt;* fixed minor UI bugs&lt;br /&gt;&lt;br /&gt;NB: this tool is compressed and some AV detects it as a malware. Do not worry, we guarantee that it is not a virus at all! If you have doubts anyway se the Arteam ESFV checker to ensure that all the files are unmodified or eventually download a fresh copy from http://arteam.accessroot.com&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	<entry>
		<id>http://www.woodmann.com/collaborative/tools/index.php/RE-Pair</id>
		<title>Tool Added: RE-Pair</title>
		<link rel="alternate" type="text/html" href="http://www.woodmann.com/collaborative/tools/index.php/RE-Pair"/>
				<updated>2007-10-19T21:44:16Z</updated>
		
		<summary type="html">&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Tool_Hiding_Tools&quot;&gt;Tool Hiding Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;0.6&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;July 1, 2005&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;RE-Pair is a tool that will make some of our (reverse engineers) tools a&lt;br /&gt;bit more difficult to detect. Why the name RE-Pair? Simple, it helps&lt;br /&gt;fix our tools, by making them somewhat more difficult to detect.&lt;br /&gt;&lt;br /&gt;Currently fixes: Any tool. Either in memory (for packed apps and one time&lt;br /&gt;changes) or on disk (for permanent patches of non-packed apps). It does this&lt;br /&gt;by changing the caption/classname to a random string (defeating FindWindow&lt;br /&gt;method). It also patches OllyDbg to fix the 'OutputDebugString' vulnerability&lt;br /&gt;(Used by Armadillo and others).&lt;br /&gt;NOTE: Using the Fix Other option may take a while to Fix on disk.&lt;/i&gt;
&lt;/p&gt;</summary>
			</entry>

	</feed>