Skip to content

v0.7 - WFP session setup

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 04 Aug 19:50
· 13 commits to main since this release

WFP session infrastructure: opens the WFP engine and registers the provider/sublayer that the network callout (v0.8) will attach to. No traffic filtering yet.

Added

  • wfp_session.c/.h: KdaMonWfpSessionInit/KdaMonWfpSessionCleanup, opens a WFP engine session, registers KDAMonitor Provider and KDAMonitor Sublayer with dedicated GUIDs
  • Registered early in DriverEntry (right after device creation, before the event queue), unregistered symmetrically last in DriverUnload (before device deletion), consistent with treating the WFP session as infrastructure rather than an event producer