IdaStealth

While the HideDebugger script discussed in the previous section is useful for demonstrating some basic programmatic interaction with the debugger and some basics of library function hooking, the total number of known anti-debugging techniques and the complexity of those techniques argue for more robust anti-anti-debugging than can be provided by a simple script. Fortunately, the IdaStealth plug-in is designed to meet our needs for a power debugger-hiding capability. Written by Jan Newger, IdaStealth was the winner of Hex-Rays’s 2009 plug-in writing contest. The plug-in is written in C++ and is available in both source and binary form.

Name

IDAStealth

Author

Jan Newger

Distribution

C++Source and binary

Price

Free

Description

Windows debugger-hiding ...

Get The IDA Pro Book, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.