├── LICENSE
├── README.md
├── main.go
└── process_protection
└── lib.go
/LICENSE:
--------------------------------------------------------------------------------
1 | MIT License
2 |
3 | Copyright (c) 2017 Adam
4 |
5 | Permission is hereby granted, free of charge, to any person obtaining a copy
6 | of this software and associated documentation files (the "Software"), to deal
7 | in the Software without restriction, including without limitation the rights
8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
9 | copies of the Software, and to permit persons to whom the Software is
10 | furnished to do so, subject to the following conditions:
11 |
12 | The above copyright notice and this permission notice shall be included in all
13 | copies or substantial portions of the Software.
14 |
15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21 | SOFTWARE.
22 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # Process-Protection
2 | Basic windows process protection written in Go, using the NtSetInformationProcess API
3 |
4 | Read more about how i did it here; https://msdn.microsoft.com/en-us/library/windows/desktop/ms684280(v=vs.85).aspx
5 |
6 | # Compiling
7 | go build main.go
8 |
9 | # Other
10 | Go is a amazing and powerful programming language. If you already haven't, check it out; https://golang.org/
11 |
12 | # Donations
13 |
14 |
Please Donate To Bitcoin Address: 1AEbR1utjaYu3SGtBKZCLJMRR5RS7Bp7eE
15 | -------------------------------------------------------------------------------- /main.go: -------------------------------------------------------------------------------- 1 | // Process Protection project main.go 2 | package main 3 | 4 | import ( 5 | "fmt" 6 | 7 | "github.com/SaturnsVoid/Process-Protection/process_protection" 8 | ) 9 | 10 | func main() { 11 | fmt.Println("This program will protect its-self.") 12 | process_protection.Protect() 13 | fmt.Println("Try killing me with a unelevated tool.") 14 | for { 15 | } 16 | } 17 | -------------------------------------------------------------------------------- /process_protection/lib.go: -------------------------------------------------------------------------------- 1 | package process_protection 2 | 3 | import ( 4 | "syscall" 5 | ) 6 | 7 | var ( 8 | ntdll = syscall.MustLoadDLL("ntdll.dll") 9 | NtSetInformationProcess = ntdll.MustFindProc("NtSetInformationProcess") 10 | ) 11 | 12 | func setInformationProcess(hProcess uintptr, processInformationClass int, processInformation int, processInformationLength int) { 13 | _, _, _ = NtSetInformationProcess.Call(hProcess, uintptr(processInformationClass), uintptr(processInformation), uintptr(processInformationLength)) 14 | } 15 | 16 | func Protect() { 17 | me, _ := syscall.GetCurrentProcess() 18 | SetInformationProcess(uintptr(me), 29, 1, 4) 19 | } 20 | --------------------------------------------------------------------------------