v0.7 - WFP session setup
WFP session infrastructure: opens the WFP engine and registers the provider/sublayer that the network callout (v0.8) will attach to. No traffic filtering yet.
Added
wfp_session.c/.h:KdaMonWfpSessionInit/KdaMonWfpSessionCleanup, opens a WFP engine session, registersKDAMonitor ProviderandKDAMonitor Sublayerwith dedicated GUIDs- Registered early in
DriverEntry(right after device creation, before the event queue), unregistered symmetrically last inDriverUnload(before device deletion), consistent with treating the WFP session as infrastructure rather than an event producer