How to Check the Already Running Process in Socket Spy Debugging Environment. ?

by alok on February 8, 2010

 

Socket Spy is multipurpose utility initially created for trapping Winsock, SNMPAPI, ICMP calls and network TCP/UDP traffic of already active or new processes. In other words you may investigate already running process or start a new one in Socket Spy debugging environment.

Socket Spy is based on Win32 Debug functions, but if tested process wants to know if debugger present, SocketSpy may block this request and tested process will receive an answer "No". Also you may read and write to tested process memory, find binary sequences in memory of tested process, set additional break points on system function or make disassembler of executable code or specific system function.

Socket Spy can show File I/O operations (KERNEL32.DLL) and Windows Registry (ADVAPI.DLL) operations of tested process. For example, you may capture all network and/or file input/output traffic of IExplore, OutLook Express and other programs. It is possible to capture only file I/O, network I/O, Windows Registry access separately.

 

SocketSpy helps to investigate Win Socket Traffic and Algorithm.

 

The utility may be used for trojan and virus finding, high level network protocols study or software reverse engineering. In short form results are presented in as Rich Edit text in output window and the full information may be saved as log file.

Socket Spy is licensed as shareware, the cost of the registered version is $34.99 and full download size is 0.65 MB

 

Requirements:
· 256 MB RAM
· 800 * 600 screen resolution

  • Share/Bookmark

Leave a Comment

Previous post:

Next post: