Hi, I’m currently using WinpkFilter for capture packets, and it works fine with filters and so on. But I decided to implement some kind of packets filtering by a specific process. And after 3 days of researching and trying different approaches, like WFP Calluots, ETW (Windows Event Tracing), also WinAPI (GetExtendedTcpTable) and others… – I’m here, again 🙂
And I found, in the socksify project you are actually using the GetExtendedTcpTable() approach. So, is it actually the best one for that needs or maybe there is some better? For example, WFP Callouts look nice but it requires kernel-mode for events like Connect and others, which is not really good for a such trivial task like just save process info for the IP connection…
So I would like to hear from the real expert, what is the best approach to filter traffic by a process with using WinpkFilter.