Skip to content

v0.8 - Network Callout

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 08 Aug 22:44
· 8 commits to main since this release

Third sensor: outbound and inbound IPv4 network connections are now captured via WFP callouts, queued, and written to disk as structured JSONL, alongside process and image load events.

Added

  • wfp_callout.c/wfp_callout.h: KdaMonWfpCalloutRegister/KdaMonWfpCalloutUnregister, registers two callouts (KDAMonitor Callout Outbound/Inbound) on FWPM_LAYER_ALE_AUTH_CONNECT_V4 and FWPM_LAYER_ALE_AUTH_RECV_ACCEPT_V4, each with an associated filter
  • guids.c: centralized DEFINE_GUID declarations (session + callout GUIDs), replacing the inline DEFINE_GUID/INITGUID previously in wfp_session.c
  • event_types.h: KDAMON_NETWORK_EVENT_DATA (PID, process path, protocol, local/remote IP and port, direction)
  • log_writer.c: KdaMonLogWriterWriteNetworkEvent, dispatched via switch in KdaMonLogWriterWriteEvent
  • Registered/unregistered in DriverEntry/DriverUnload, right after the event queue, consistent with all event producers being torn down before the queue and log writer
  • Reuses event_queue.c (v0.3) and the log writer pipeline (v0.4) unchanged

Changed

  • wfp_session.c: g_EngineHandle no longer static, exposed via wfp_session.h so wfp_callout.c can reuse the same WFP session handle
  • wfp_session.c: subLayer.weight changed from 0 to 0xFFFF (highest sublayer priority)

Notes

  • Filters use FWP_ACTION_CALLOUT_INSPECTION rather than FWP_ACTION_CALLOUT_TERMINATING
  • Validated on Windows test VM: netsh wfp show state/show filters confirm provider, sublayer, both callouts, and both filters registered on load, absent on unload
  • IPv6 not yet covered (V4-only layers, LocalIp/RemoteIp stored as 32-bit ULONG) — planned as a post-v1.0 follow-up