Endpoint DataProtector.sys Minifilter transparent protection Process, credential, web-shell, lateral, file, static-scan sensors WFP network filter and SMTP auditing ThreatEngine correlation and response Kernel policy port: \DataProtectorPolicyPort DataProtectorPolicyApi.dll Stable native C ABI Policy, query, drain, and verdict submission APIs DataProtectorWebBridge agent mode Central heartbeat Policy apply Static scan request draining DLP service Removable device inventory Sandbox sample upload Remote task execution Central DataProtectorWebBridge server mode HTTP API on port 17643 Device inventory and health Central policy versions Audit and attack-flow views Network awareness Sandbox and static-analysis sample centers USB Crypt runtime packages Remote task queue Operations DataProtectorWebAdmin DataProtectorAdmin DataProtectorAgentClient
仓库结构
DataProtector/ DataProtector/ Kernel minifilter, sensors, WFP, ThreatEngine DataProtectorPolicyApi/ Native C ABI over the driver policy port DataProtectorWebBridge/ Local bridge, central server, endpoint agent DataProtectorWebAdmin/ Web operator console based on SoybeanAdmin DataProtectorAdmin/ WPF local admin console DataProtectorAgentClient/ WPF endpoint agent client DataProtectorUsbCrypt/ Secure USB runtime driver DataProtectorUsbTool/ USB unlock, mount, and initialization tool DataProtectorUserHookRuntime/ User-mode runtime hook component DataProtectorSandboxTelemetry/ Windows Sandbox telemetry runner DataProtectorStaticAnalyzer/ Ghidra/static-analysis tooling external/ghidra-release/ Bundled Ghidra distribution assets third_party/minhook/ MinHook source used by the hook runtime third_party/yara-bin/ Bundled libyara.dll runtime artifact third_party/yara-rules/ Bundled third-party YARA rule assets UserHookTriggerTest/ Runtime hook test utility
Minifilter、WFP、Filter Manager IPC、Win32 加密、网络、安装、Shell 和 UI API
Microsoft SDK/WDK 条款。原生项目链接 fltmgr.lib、fwpkclnt.lib、ndis.lib、FltLib.lib、Advapi32.lib、Bcrypt.lib、Comctl32.lib、Setupapi.lib、Shell32.lib、User32.lib、Gdi32.lib、Ws2_32.lib、Wintrust.lib、Crypt32.lib 等平台库。