Search found 2 matches

by Shinji
Fri Apr 13, 2018 12:05 pm
Forum: Kernel-Mode Development
Topic: Is possible to hide a connection using windows filtering platform (WFP) ?
Replies: 2
Views: 3780

Re: Is possible to hide a connection using windows filtering platform (WFP) ?

Thanks for your reply Vrtule, I appreciate your help. I think is possible( I have not checked it on news windows ) intercept IOCTL_TCP_QUERY_INFORMATION_EX but it would be necessary use VT-X/EPT to avoid Patchguard. Another solution could be write entireTCP stack using NDIS.... I would really apprec...
by Shinji
Wed Apr 11, 2018 1:14 pm
Forum: Kernel-Mode Development
Topic: Is possible to hide a connection using windows filtering platform (WFP) ?
Replies: 2
Views: 3780

Is possible to hide a connection using windows filtering platform (WFP) ?

Hi,

I'm using WFP to monitor network activity but reading de documentation I think is not possible to hide a connection using it. I've been
reviewing several rootkits capabilities and turla for example use WFP and Ndis driver....


Does anyone know if hide a connection using WFP is possible?

Thx