I have a program that perform changes with udp traffic. That program uses WFP for it. Also I know GUID of filter and callout, that perform changes.
1. How can I inspect changes on specified packets?
2. Is there any method to detect packets, that was marked by some filter with flag FWPS_CLASSIFY_OUT_FLAG_ABSORB before it was re-injected.
It looks like you're new here. If you want to get involved, click one of these buttons!
|Upcoming OSR Seminars|
|Writing WDF Drivers||21 Oct 2019||OSR Seminar Space & ONLINE|
|Internals & Software Drivers||18 Nov 2019||Dulles, VA|
|Kernel Debugging||30 Mar 2020||OSR Seminar Space|
|Developing Minifilters||27 Apr 2020||OSR Seminar Space & ONLINE|