v0.8 - Network Callout
Third sensor: outbound and inbound IPv4 network connections are now captured via WFP callouts, queued, and written to disk as structured JSONL, alongside process and image load events.
Added
wfp_callout.c/wfp_callout.h:KdaMonWfpCalloutRegister/KdaMonWfpCalloutUnregister, registers two callouts (KDAMonitor Callout Outbound/Inbound) onFWPM_LAYER_ALE_AUTH_CONNECT_V4andFWPM_LAYER_ALE_AUTH_RECV_ACCEPT_V4, each with an associated filterguids.c: centralizedDEFINE_GUIDdeclarations (session + callout GUIDs), replacing the inlineDEFINE_GUID/INITGUIDpreviously inwfp_session.cevent_types.h:KDAMON_NETWORK_EVENT_DATA(PID, process path, protocol, local/remote IP and port, direction)log_writer.c:KdaMonLogWriterWriteNetworkEvent, dispatched via switch inKdaMonLogWriterWriteEvent- Registered/unregistered in
DriverEntry/DriverUnload, right after the event queue, consistent with all event producers being torn down before the queue and log writer - Reuses
event_queue.c(v0.3) and the log writer pipeline (v0.4) unchanged
Changed
wfp_session.c:g_EngineHandleno longerstatic, exposed viawfp_session.hsowfp_callout.ccan reuse the same WFP session handlewfp_session.c:subLayer.weightchanged from0to0xFFFF(highest sublayer priority)
Notes
- Filters use
FWP_ACTION_CALLOUT_INSPECTIONrather thanFWP_ACTION_CALLOUT_TERMINATING - Validated on Windows test VM:
netsh wfp show state/show filtersconfirm provider, sublayer, both callouts, and both filters registered on load, absent on unload - IPv6 not yet covered (V4-only layers,
LocalIp/RemoteIpstored as 32-bitULONG) — planned as a post-v1.0 follow-up