credit to https://twitter.com/R00tkitSMM ([email protected]) telegram username : https://telegram.me/firozi
need block process with its file's hash ? you can use this WFP library , to do it just call User-Mode C++ functions it will do it in Kernel-Mode
- block TCP/UDP/ICMP based on process file hash
- use SHA1 for hashing
- Log process Network Activity ( process hash , network info : remote and local port-ip address )
- real time rule setting
- rule can act as white or black list