Port to PID map

Home Forums Discussions General Discussion Port to PID map

This topic contains 3 replies, has 2 voices, and was last updated by  Vadim Smirnov 9 years, 8 months ago.

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #5187

    Hajoe
    Participant

    Hello,
    i tried to map a given TCP Local Port on a Win2K machine to a process ID by IOCTL_TCP_QUERY_INFORMATION_EX
    This works, but i only get established connections. I need the PID if only the sync packet was sended. Any ideas to solve this problem?

    #6584

    Vadim Smirnov
    Moderator

    TDI filter, LSP, AFD filter are the most common options.

    #6585

    Hajoe
    Participant

    >> TDI filter, LSP, AFD filter are the most common options.
    Thanks, do you have any links (sourcecode) for me?
    What’s about your WinpkFilter – Framework?
    I just saw your Local Network Monitor API, that seems to be the right stuff?

    #6586

    Vadim Smirnov
    Moderator

    What’s about your WinpkFilter – Framework?

    WinpkFilter operates at the NDIS level and can’t associate packet with PID without any additional information.

    I just saw your Local Network Monitor API, that seems to be the right stuff?

    You are right, Local Network Monitor API can be used for this.

Viewing 4 posts - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.