Go Interface (ndisapi-go)

Windows Packet Filter provides official, idiomatic Go bindings via the github.com/wiresock/ndisapi-go module. The Go library provides a safe, high-performance user-mode interface to the Windows Packet Filter driver for low-level packet capture, inspection, modification, and injection at the NDIS layer, communicating directly via Windows syscalls without cgo runtime dependencies.

Installation

Install the package into your Go module using go get:

go get github.com/wiresock/ndisapi-go

Key Features

  • Direct Windows Syscalls: Interacts directly with the WinpkFilter driver using Windows IOCTL system calls without requiring cgo or external C toolchains.
  • Multi-Adapter Support: Simultaneously configure and capture packets from physical Ethernet, Wi-Fi, and virtual network interfaces.
  • Flexible Filtering Modes: Put adapters into packet snooping (Listen) or transparent inline diversion (Tunnel) modes.
  • Raw Packet Injection: Inject forged or modified Ethernet frames bidirectionally to the network adapter or up the TCP/IP stack.
  • Thread-Safe Concurrency: Safe for concurrent execution across Go routines.

Getting Started Example

package main

import (
	"fmt"
	"log"

	"github.com/wiresock/ndisapi-go"
)

func main() {
	// Initialize the NDIS API driver handle
	api, err := ndisapi.NewNdisApi()
	if err != nil {
		log.Fatalf("Failed to initialize NDIS API: %v", err)
	}
	defer api.Close()

	if !api.IsDriverLoaded() {
		log.Fatal("Windows Packet Filter driver is not loaded. Please ensure WinpkFilter runtime is installed.")
	}

	fmt.Println("Windows Packet Filter driver is loaded and ready.")

	// Query network interfaces bound to the TCP/IP stack
	adapters, err := api.GetTcpipBoundAdaptersInfo()
	if err != nil {
		log.Fatalf("Failed to query network adapters: %v", err)
	}

	if len(adapters) == 0 {
		fmt.Println("No TCP/IP bound network adapters found.")
		return
	}

	fmt.Printf("Found %d network adapter(s):\n", len(adapters))
	for i, adapter := range adapters {
		fmt.Printf("  [%d] %s (%s)\n", i, adapter.FriendlyName(), adapter.InternalName())
	}
}

Authoritative Resources