A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #3312  by Mehdi
 Thu Nov 04, 2010 8:02 am
Hi
As title says, I want to be able to watch what IOCTLs are sent to a specific kernel driver.
I use IRP Tracker, but it's closed automatically after sniffing (about 3 to 10 seconds after capture starts)
There was once a utility named "WDM Sniffer" by Numega.
Does someone know of any utility that can help me ?
Thanks in advance
 #3315  by Mehdi
 Thu Nov 04, 2010 8:24 am
Thank you very much
I'd heard of this utility, but didn't know it lists the IOCTLs (the "fuzzer" in name is somewhat misnomer)
 #3316  by EP_X0FF
 Thu Nov 04, 2010 8:27 am
Well, it's not exactly what you want, but I've used it in past for listing data send to driver from user mode app.