Getting Process ID of process that sent packet

Home Forums Discussions Support Portal Getting Process ID of process that sent packet

This topic contains 1 reply, has 2 voices, and was last updated by  Vadim Smirnov 2 years, 7 months ago.

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #5415

    stsf
    Participant

    Hey guys, I was wondering – is it possible to get the process ID of the process that sent out the packet when we process the packet in user mode (similar to how we get the MAC address, IP’s, ports, etc )?

    I’m using the NdisApiWrapper in a C# project, and I can see that the NdisApiWrapper itself uses the Win32 API, which seems like the type of thing that would be used for that.

    Thanks in advance.

    #7194

    Vadim Smirnov
    Moderator

    You can use IP Helper API to retrieve current connections table and starting Windows XP this table also contains process ID. You can use IP/Port information from the packet to find the corresponding connection in that table and thus identify the process.

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.