Is there any way to filter TCP connect requests at the context of the original thread that called WSAConnect()? As far as I know you cannot (from kernel mode, in a documented way) do it - are all the networking callbacks run asynchronously / at DISPATCH_LEVEL?
Moreover, How would you recommend to learn about network filtering? I can just read the MSDN documentation but are there any other sources you think may be useful?
Thank you in advance!:)
It looks like you're new here. If you want to get involved, click one of these buttons!
|Upcoming OSR Seminars|
|OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!||Kernel Debugging||30 Mar 2020||OSR Seminar Space|
|Developing Minifilters||20 Apr 2020||LIVE ONLINE|
|Writing WDF Drivers||11 May 2020||LIVE ONLINE|
|Internals & Software Drivers||28 Sept 2020||Dulles, VA|