Introduction - If you have any usage issues, please Google them yourself
HOOK / NtDeviceIoControlFile function
Ws2_32.dll / send, recv will call to the data transmitting function in mswsock.dll
/ / mswsock.dll will call the NtDeviceIoControlFile to the TDI Client driver sends the Send Recv command
Here we do / / intercept, can filter all receive TCP packets (like UDP but also to change the directive)
Mswsock.dll / / Hook export table Ntdll! NtDeviceIoControlFile
And the request of TDI / / Cilent filter to filter packets
/ / stability, concealment, packet filtering at the bottom of the RING3.