!unhide (disable transparent-mode)
Description of '!unhide' command in HyperDbg.

Command

!unhide

Syntax

!unhide

Description

Disables the transparent-mode of HyperDbg.

Parameters

None

Examples

1
HyperDbg> !unhide
Copied!

IOCTL

You should send the IOCTL_DEBUGGER_HIDE_AND_UNHIDE_TO_TRANSPARENT_THE_DEBUGGER IOCTL to enable or disable transparent-mode.
The following structure shows whether enable or disable it.
IsHide = TRUE : Enable transparent-mode.
IsHide = FALSE: Disable transparent-mode.
You should not fill anything else if you want to disable transparent-mode, just set the IsHide.
1
typedef struct _DEBUGGER_HIDE_AND_TRANSPARENT_DEBUGGER_MODE {
2
3
BOOLEAN IsHide;
4
5
UINT64 CpuidAverage;
6
UINT64 CpuidStandardDeviation;
7
UINT64 CpuidMedian;
8
UINT64 RdtscAverage;
9
UINT64 RdtscStandardDeviation;
10
UINT64 RdtscMedian;
11
BOOLEAN TrueIfProcessIdAndFalseIfProcessName;
12
UINT32 ProcId;
13
UINT32 LengthOfProcessName; // in the case of !hide name xxx, this parameter
14
// shows the length of xxx
15
16
UINT64 KernelStatus; /* DEBUGEER_OPERATION_WAS_SUCCESSFULL ,
17
DEBUGEER_ERROR_UNABLE_TO_HIDE_OR_UNHIDE_DEBUGGER
18
*/
19
20
} DEBUGGER_HIDE_AND_TRANSPARENT_DEBUGGER_MODE,
21
*PDEBUGGER_HIDE_AND_TRANSPARENT_DEBUGGER_MODE;
Copied!
If the results were successful, then the kernel sends DEBUGEER_OPERATION_WAS_SUCCESSFULL to user-mode (as KernelStatus to the above structure), and if it was unsuccessful, then DEBUGEER_ERROR_DEBUGGER_ALREADY_UHIDE which is an indicator that HyperDbg was not already in transparent-mode.

Remarks

This command will continue the debuggee for some time (in Debugger Mode). This means that you lose the current context (registers & memory) after executing this command.

Requirements

None
Last modified 2d ago