{"id":13640092,"url":"https://github.com/hackerschoice/zapper","last_synced_at":"2025-08-27T01:48:29.814Z","repository":{"id":193465767,"uuid":"688843912","full_name":"hackerschoice/zapper","owner":"hackerschoice","description":"Zaps arguments and environment from the process list","archived":false,"fork":false,"pushed_at":"2024-04-26T20:00:18.000Z","size":79,"stargazers_count":209,"open_issues_count":1,"forks_count":17,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-07-16T11:22:05.572Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hackerschoice.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-09-08T08:15:05.000Z","updated_at":"2025-07-02T16:20:24.000Z","dependencies_parsed_at":null,"dependency_job_id":"8b11bf69-1af1-49ac-888e-81717506db18","html_url":"https://github.com/hackerschoice/zapper","commit_stats":null,"previous_names":["hackerschoice/zapper"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/hackerschoice/zapper","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerschoice%2Fzapper","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerschoice%2Fzapper/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerschoice%2Fzapper/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerschoice%2Fzapper/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hackerschoice","download_url":"https://codeload.github.com/hackerschoice/zapper/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerschoice%2Fzapper/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":272277735,"owners_count":24905555,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-26T02:00:07.904Z","response_time":60,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:01:07.669Z","updated_at":"2025-08-27T01:48:29.771Z","avatar_url":"https://github.com/hackerschoice.png","language":"C","funding_links":[],"categories":["C"],"sub_categories":[],"readme":"\u003cH1 align=\"center\"\u003ePrivacy for your command line options\u003c/H2\u003e\n\u003cH3 align=\"center\"\u003eA Linux tool to hide from \"ps\"\u003c/H2\u003e\n\nDownload:\n```sh\ncurl -fL -o zapper https://github.com/hackerschoice/zapper/releases/latest/download/zapper-linux-$(uname -m) \u0026\u0026 \\\nchmod 755 zapper \u0026\u0026 \\\n./zapper -h\n```\n\nExample: Show only 'nmap', but without the command options:\n```sh\n./zapper nmap -sCV -F -Pn scanme.nmap.org\n              ^^^^^^^^^^^^^^^^^^^^^^^^^^^\n                     will not show\n```\n\nExample: Replace the current shell with a hidden tmux/shell. Hide all sub processes (`-f`), take on the name of some kernel process (`-a`) and hide all command line options:\n```sh\nexec ./zapper -f -a'[kworker/1:2-cgroup_destroy]' tmux\n```\n\n![Screenshot 2023-10-04 at 12 06 39](https://github.com/hackerschoice/zapper/assets/5938498/a3c91951-9866-41be-96e4-7b13454b7885)\n\u003cp align=\"center\"\u003e\u003ci\u003e\u003c/i\u003eshowing 6 hidden processes: tmux, bash, nmap, sleep, ps, grep\u003c/i\u003e\u003c/p\u003e\n\n\n---\n1. Does not require *root*\n2. Works also on static binaries (e.g. GoLang binaries)\n3. Zaps the environment (*/proc/\u0026lt;PID\u0026gt;/environ*) as well\n1. Does not rely on *LD_PRELOAD=* or libc.\n2. Uses ptrace() to manipulate the [Elf Auxiliary Table](https://iq.thc.org/how-does-linux-start-a-process)\n5. Only 00.1% overhead.\n6. Stops the admin from seeing or spying on your processes.\n7. Starts a process under _any_ process id (`-n \u003cpid\u003e`)\n\n---\nCompile:\n```sh\ngit clone https://github.com/hackerschoice/zapper.git\ncd zapper\nmake\n```\n\n![Screenshot 2023-10-04 at 08 10 19](https://github.com/hackerschoice/zapper/assets/5938498/f9946c10-914e-4715-a594-4285936bd829)\n\n---\nHow it works:\n* It uses ptrace() to [manipulates the stack's Elf-Aux-Table](https://iq.thc.org/how-does-linux-start-a-process).\n* Zapper intercepts when the Kernel passes the command-options to the program (during SYS_execve()): It moves the orignal command-options to a new memory location and then destroyes the old memory location. From the perspective of the Kernel (and procps), the command-options cease to exist. Finally, zapper fixes the pointers in the progam's Aux-Table and hands execution back to the program (PTRACE_CONTINUE). Thereafter, the program is tracked for any further calls to fork() or execve() [to do the same all over again].\n* Almost zero performance impact by using some neat ptrace-features: Tracing only execve() and fork() events (but not any other syscall).\n* The `-n \u003cpid\u003e` trick (to start a program under _any_ pid) is a gimmick: Linux assigns a new pid to every new _thread_ in sequential order, up until the largest possible pid of 4,194,304 (2^22). Thereafter, it starts again at pid 300 (or 1, depending on the environment). Zapper iterates over all 2^22 possible pids (within a few seconds) until the target pid-1 is encountered: Zapper forks 8+ processes, each calling `clone((int (*)(void *))exit, ..)`. Directly jumping into `exit()` and setting `CLONE_VM` is the fastest way to iterate through all available PIDs.\n \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhackerschoice%2Fzapper","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhackerschoice%2Fzapper","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhackerschoice%2Fzapper/lists"}