# tcpip-8737.sys-tcpip-8875.sys Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [FUN_1401ccede](#fun_1401ccede)
	* [FUN_1401dad8a](#fun_1401dad8a)
* [Added](#added)
	* [Feature_1204007226__private_IsEnabledDeviceUsageNoInline](#feature_1204007226__private_isenableddeviceusagenoinline)
	* [Feature_1204007226__private_IsEnabledFallback](#feature_1204007226__private_isenabledfallback)
	* [Feature_4272399675__private_IsEnabledDeviceUsageNoInline](#feature_4272399675__private_isenableddeviceusagenoinline)
	* [Feature_4272399675__private_IsEnabledFallback](#feature_4272399675__private_isenabledfallback)
	* [Feature_3999242553__private_IsEnabledDeviceUsageNoInline](#feature_3999242553__private_isenableddeviceusagenoinline)
	* [Feature_3999242553__private_IsEnabledFallback](#feature_3999242553__private_isenabledfallback)
	* [Feature_3131548987__private_IsEnabledDeviceUsageNoInline](#feature_3131548987__private_isenableddeviceusagenoinline)
	* [Feature_3131548987__private_IsEnabledFallback](#feature_3131548987__private_isenabledfallback)
	* [Feature_4005012793__private_IsEnabledDeviceUsageNoInline](#feature_4005012793__private_isenableddeviceusagenoinline)
	* [Feature_4005012793__private_IsEnabledFallback](#feature_4005012793__private_isenabledfallback)
* [Modified](#modified)
	* [InetWakeAcquirePortAf](#inetwakeacquireportaf)
	* [PktMonClientComponentUnregister](#pktmonclientcomponentunregister)
	* [Ipv6pHandleNeighborSolicitation](#ipv6phandleneighborsolicitation)
	* [RawBindEndpointInspectComplete](#rawbindendpointinspectcomplete)
	* [Fl8AddGroup](#fl8addgroup)
	* [FlpDeleteGroupUnderLock](#flpdeletegroupunderlock)
	* [AleRedirectRecordsDeserializeFromBuffer](#aleredirectrecordsdeserializefrombuffer)
	* [InetWakeReleasePortAf](#inetwakereleaseportaf)
	* [IpGetAllSortedAddressParameters](#ipgetallsortedaddressparameters)
	* [FUN_1401cd7da](#fun_1401cd7da)
	* [FUN_1401cceb6](#fun_1401cceb6)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [FlpInterfaceAcquireWriteLock](#flpinterfaceacquirewritelock)
	* [NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel](#ntoskrnlexekereleaseinstackqueuedspinlockfromdpclevel)
	* [IppReassemblyInterfaceCleanup](#ippreassemblyinterfacecleanup)
	* [__GSHandlerCheck](#__gshandlercheck)
	* [FlpInterfaceReleaseReadLock](#flpinterfacereleasereadlock)
	* [NDIS.SYS::NdisAcquireRWLockWrite](#ndissysndisacquirerwlockwrite)
	* [WfpSizeTMultiply](#wfpsizetmultiply)
	* [NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel](#ntoskrnlexekereleasespinlockfromdpclevel)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [Fl48pMapMulticastAddress](#fl48pmapmulticastaddress)
	* [memset](#memset)
	* [RtlAcquireWriteLockAtDpcLevel](#rtlacquirewritelockatdpclevel)
	* [NDIS.SYS::NdisReleaseRWLock](#ndissysndisreleaserwlock)
	* [InetSetInterfacePropertyAf](#inetsetinterfacepropertyaf)
	* [NTOSKRNL.EXE::KeReleaseSpinLock](#ntoskrnlexekereleasespinlock)
	* [IppDeleteSitePrefixes](#ippdeletesiteprefixes)

# Visual Chart Diff



```mermaid

flowchart LR

InetWakeAcquirePortAf-0-old<--Match 35%-->InetWakeAcquirePortAf-0-new
PktMonClientComponentUnregister-0-old<--Match 21%-->PktMonClientComponentUnregister-0-new
Ipv6pHandleNeighborSolicitation-0-old<--Match 30%-->Ipv6pHandleNeighborSolicitation-0-new
RawBindEndpointInspectComplete-0-old<--Match 74%-->RawBindEndpointInspectComplete-0-new
Fl8AddGroup-0-old<--Match 33%-->Fl8AddGroup-0-new
FlpDeleteGroupUnderLock-0-old<--Match 64%-->FlpDeleteGroupUnderLock-0-new
AleRedirectRecordsDeserializeFromBuffer-0-old<--Match 63%-->AleRedirectRecordsDeserializeFromBuffer-0-new
InetWakeReleasePortAf-0-old<--Match 74%-->InetWakeReleasePortAf-0-new
IpGetAllSortedAddressParameters-0-old<--Match 64%-->IpGetAllSortedAddressParameters-0-new
FUN_1401cd7da-0-old<--Match 70%-->FUN_1401cb93a-0-new
FUN_1401cceb6-0-old<--Match 32%-->InetWakeRemovePortEntryIfPresent-0-new

subgraph tcpip-8875.sys
    InetWakeAcquirePortAf-0-new
PktMonClientComponentUnregister-0-new
Ipv6pHandleNeighborSolicitation-0-new
RawBindEndpointInspectComplete-0-new
Fl8AddGroup-0-new
FlpDeleteGroupUnderLock-0-new
AleRedirectRecordsDeserializeFromBuffer-0-new
InetWakeReleasePortAf-0-new
IpGetAllSortedAddressParameters-0-new
FUN_1401cb93a-0-new
InetWakeRemovePortEntryIfPresent-0-new
    subgraph Added
direction LR
Feature_1204007226__private_IsEnabledDeviceUsageNoInline
    Feature_1204007226__private_IsEnabledFallback
    Feature_4272399675__private_IsEnabledDeviceUsageNoInline
    Feature_4272399675__private_IsEnabledFallback
    Feature_3999242553__private_IsEnabledDeviceUsageNoInline
    Feature_3999242553__private_IsEnabledFallback
    Feature_3131548987__private_IsEnabledDeviceUsageNoInline
    Feature_3131548987__private_IsEnabledFallback
    Feature_4005012793__private_IsEnabledDeviceUsageNoInline
    Feature_4005012793__private_IsEnabledFallback
end
end

subgraph tcpip-8737.sys
    InetWakeAcquirePortAf-0-old
PktMonClientComponentUnregister-0-old
Ipv6pHandleNeighborSolicitation-0-old
RawBindEndpointInspectComplete-0-old
Fl8AddGroup-0-old
FlpDeleteGroupUnderLock-0-old
AleRedirectRecordsDeserializeFromBuffer-0-old
InetWakeReleasePortAf-0-old
IpGetAllSortedAddressParameters-0-old
FUN_1401cd7da-0-old
FUN_1401cceb6-0-old
    subgraph Deleted
direction LR
FUN_1401ccede
    FUN_1401dad8a
end
end

```


```mermaid
pie showData
    title Function Matches - 99.9185%
"unmatched_funcs_len" : 12
"matched_funcs_len" : 14710
```



```mermaid
pie showData
    title Matched Function Similarity - 99.8165%
"matched_funcs_with_code_changes_len" : 11
"matched_funcs_with_non_code_changes_len" : 16
"matched_funcs_no_changes_len" : 14683
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ./proj --project-name tcpip-49177 --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 tcpip-8737.sys tcpip-8875.sys
```


#### Verbose Args


<details>

```
--old ['tcpip-8737.sys'] --new [['tcpip-8875.sys']] --engine VersionTrackingDiff --output-path ./out --summary False --project-location ./proj --project-name tcpip-49177 --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/tcpip.sys/F74AE133359000/tcpip.sys -O tcpip.sys.x64.10.0.26100.8737
wget https://msdl.microsoft.com/download/symbols/tcpip.sys/319D847235A000/tcpip.sys -O tcpip.sys.x64.10.0.26100.8875
```


## Binary Metadata Diff


```diff
--- tcpip-8737.sys Meta
+++ tcpip-8875.sys Meta
@@ -1,44 +1,44 @@
-Program Name: tcpip-8737.sys
+Program Name: tcpip-8875.sys
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 140000000
 Maximum Address: ff0000184f
-# of Bytes: 3514840
+# of Bytes: 3519008
 # of Memory Blocks: 19
-# of Instructions: 508114
-# of Defined Data: 22854
-# of Functions: 7357
-# of Symbols: 56883
+# of Instructions: 508404
+# of Defined Data: 22886
+# of Functions: 7365
+# of Symbols: 56911
 # of Data Types: 420
 # of Data Type Categories: 31
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Sun Aug 16 10:14:54 SGT 2026
+Date Created: Sun Aug 16 10:14:59 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/tcpip-49177/tcpip-8737.sys
-Executable MD5: 111ed71e92207922216edace777e072d
-Executable SHA256: 9b09022f6e0387547b385be35075049f8fef199a07daf81541d8cf30e072e3e4
-FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/tcpip-49177/tcpip-8737.sys?MD5=111ed71e92207922216edace777e072d
+Executable Location: /sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/tcpip-49177/tcpip-8875.sys
+Executable MD5: 8a970b94197987787c59655397035d59
+Executable SHA256: 45c1b98901dbad8a6f24e5f1ea542c63cedf2f64be18b37e43944f4e1a3a7ae3
+FSRL: file:///sessions/fervent-laughing-brahmagupta/mnt/patchpalooza/ghidriff/tcpip-49177/tcpip-8875.sys?MD5=8a970b94197987787c59655397035d59
 PDB Age: 1
 PDB File: tcpip.pdb
-PDB GUID: 41720cc5-39e6-ecf2-f314-3da99b7e2c15
+PDB GUID: 1593d4a3-e3b7-0331-7cc2-415d689c9c7a
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: TCP/IP Driver
-PE Property[FileVersion]: 10.0.26100.8737 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.8875 (WinBuild.160101.0800)
 PE Property[InternalName]: tcpip.sys
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: tcpip.sys
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.8737
+PE Property[ProductVersion]: 10.0.26100.8875
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra tcpip-8737.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra tcpip-8737.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra tcpip-8737.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|false|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra tcpip-8875.sys Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra tcpip-8875.sys Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra tcpip-8875.sys Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|false|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|10|
|deleted_funcs_len|2|
|modified_funcs_len|27|
|added_symbols_len|28|
|deleted_symbols_len|13|
|diff_time|20.759143590927124|
|deleted_strings_len|0|
|added_strings_len|1|
|match_types|Counter({'SymbolsHash': 6852, 'ExternalsName': 803, 'ExactInstructionsFunctionHasher': 368, 'StructuralGraphHash': 222, 'BSIM': 27, 'ExactBytesFunctionHasher': 20, 'SigCallingCalledHasher': 2, 'StringsRefsHasher': 1})|
|items_to_process|80|
|diff_types|Counter({'address': 21, 'refcount': 18, 'length': 13, 'calling': 12, 'called': 12, 'code': 11, 'name': 2, 'fullname': 2, 'sig': 2})|
|unmatched_funcs_len|12|
|total_funcs_len|14722|
|matched_funcs_len|14710|
|matched_funcs_with_code_changes_len|11|
|matched_funcs_with_non_code_changes_len|16|
|matched_funcs_no_changes_len|14683|
|match_func_similarity_percent|99.8165%|
|func_match_overall_percent|99.9185%|
|first_matches|Counter({'SymbolsHash': 6852, 'ExactInstructionsFunctionHasher': 368, 'StructuralGraphHash': 222, 'BSIM': 27, 'ExactBytesFunctionHasher': 20, 'SigCallingCalledHasher': 2, 'StringsRefsHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 6852
"ExternalsName" : 803
"ExactBytesFunctionHasher" : 20
"ExactInstructionsFunctionHasher" : 368
"BSIM" : 27
"SigCallingCalledHasher" : 2
"StringsRefsHasher" : 1
"StructuralGraphHash" : 222
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 6852
"ExactBytesFunctionHasher" : 20
"ExactInstructionsFunctionHasher" : 368
"BSIM" : 27
"SigCallingCalledHasher" : 2
"StringsRefsHasher" : 1
"StructuralGraphHash" : 222
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 10
"deleted_funcs_len" : 2
"modified_funcs_len" : 27
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 28
"deleted_symbols_len" : 13
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 1
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1 @@
+g_HttpsPrefixString_buffer

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|g_HttpsPrefixString_buffer|1||

# Deleted

## FUN_1401ccede

### Function Meta



|Key|tcpip-8737.sys|
| :---: | :---: |
|name|FUN_1401ccede|
|fullname|FUN_1401ccede|
|refcount|2|
|length|169|
|called|CarAcquireCacheAwareReference<br>IppTimerUpdateNextExpirationTick<br>TtInitializeTimer<br>TtStartTimerEx|
|calling|Ipv6pHandleNeighborSolicitation|
|paramcount|0|
|address|1401ccede|
|sig|undefined FUN_1401ccede(void)|
|sym_type|Function|
|sym_source|DEFAULT|
|external|False|


```diff
--- FUN_1401ccede
+++ FUN_1401ccede
@@ -1,49 +0,0 @@
-
-/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* WARNING: Removing unreachable block (ram,0x0001401ccf4c) */
-/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
-
-void FUN_1401ccede(void)
-
-{
-  undefined1 auVar1 [16];
-  undefined4 uVar2;
-  undefined4 uVar3;
-  undefined4 uVar4;
-  int iVar5;
-  longlong in_RAX;
-  longlong lVar6;
-  ulonglong uVar7;
-  longlong unaff_RBP;
-  longlong unaff_RSI;
-  longlong unaff_RDI;
-  undefined4 unaff_R14D;
-  undefined4 *unaff_R15;
-  longlong in_stack_00000050;
-  
-  *(longlong *)(in_RAX + 0x30) = unaff_RDI;
-  CarAcquireCacheAwareReference(*(undefined8 *)(unaff_RDI + 0x20),unaff_R14D);
-  uVar2 = unaff_R15[1];
-  uVar3 = unaff_R15[2];
-  uVar4 = unaff_R15[3];
-  *(undefined4 *)(unaff_RBP + 0x38) = *unaff_R15;
-  *(undefined4 *)(unaff_RBP + 0x3c) = uVar2;
-  *(undefined4 *)(unaff_RBP + 0x40) = uVar3;
-  *(undefined4 *)(unaff_RBP + 0x44) = uVar4;
-  TtInitializeTimer();
-  uVar7 = _DAT_fffff78000000008 / 10000;
-  auVar1._8_8_ = 0;
-  auVar1._0_8_ = uVar7;
-  lVar6 = SUB168(ZEXT816(0x624dd2f1a9fbe77) * auVar1,8);
-  IppRandomValue = IppRandomValue * 0x19660d + 0x3c6ef35f;
-  LOCK();
-  UNLOCK();
-  iVar5 = TtStartTimerEx(*(undefined8 *)(in_stack_00000050 + 0x2c8));
-  if (iVar5 != 0) {
-    IppTimerUpdateNextExpirationTick((uVar7 - lVar6 >> 1) + lVar6 >> 8 & 0xffffffff,iVar5);
-  }
-  IppDereferenceLocalAddress();
-  *(undefined4 *)(*(longlong *)(unaff_RSI + 8) + 0x8c) = 0;
-  return;
-}
-

```


## FUN_1401dad8a

### Function Meta



|Key|tcpip-8737.sys|
| :---: | :---: |
|name|FUN_1401dad8a|
|fullname|FUN_1401dad8a|
|refcount|3|
|length|30|
|called|WfpReportError|
|calling|AleRedirectRecordsDeserializeFromBuffer|
|paramcount|0|
|address|1401dad8a|
|sig|undefined FUN_1401dad8a(void)|
|sym_type|Function|
|sym_source|DEFAULT|
|external|False|


```diff
--- FUN_1401dad8a
+++ FUN_1401dad8a
@@ -1,14 +0,0 @@
-
-/* PDB: Separated code (from the compiler): 1401dad8a - 1401dada7 for parent address: 14011eff4 */
-
-void FUN_1401dad8a(void)
-
-{
-  longlong unaff_RDI;
-  
-  if (unaff_RDI != 0) {
-    WfpReportError();
-  }
-  return;
-}
-

```


# Added

## Feature_1204007226__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_1204007226__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_1204007226__private_IsEnabledDeviceUsageNoInline|
|refcount|3|
|length|49|
|called|Feature_1204007226__private_IsEnabledFallback|
|calling|AleRedirectRecordsDeserializeFromBuffer|
|paramcount|0|
|address|14016cf8c|
|sig|undefined Feature_1204007226__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1204007226__private_IsEnabledDeviceUsageNoInline
+++ Feature_1204007226__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,16 @@
+
+ulonglong Feature_1204007226__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  
+  if ((Feature_1204007226__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_1204007226__private_IsEnabledFallback
+                      (Feature_1204007226__private_featureState,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_1204007226__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_1204007226__private_IsEnabledFallback

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_1204007226__private_IsEnabledFallback|
|fullname|Feature_1204007226__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_1204007226__private_IsEnabledDeviceUsageNoInline|
|paramcount|0|
|address|14016cfc4|
|sig|undefined Feature_1204007226__private_IsEnabledFallback(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_1204007226__private_IsEnabledFallback
+++ Feature_1204007226__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_1204007226__private_IsEnabledFallback(undefined8 param_1,undefined8 param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_1204007226__private_descriptor);
+  return;
+}
+

```


## Feature_4272399675__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_4272399675__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_4272399675__private_IsEnabledDeviceUsageNoInline|
|refcount|2|
|length|49|
|called|Feature_4272399675__private_IsEnabledFallback|
|calling|IpGetAllSortedAddressParameters|
|paramcount|0|
|address|1401915c4|
|sig|undefined Feature_4272399675__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_4272399675__private_IsEnabledDeviceUsageNoInline
+++ Feature_4272399675__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,16 @@
+
+ulonglong Feature_4272399675__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  
+  if ((Feature_4272399675__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_4272399675__private_IsEnabledFallback
+                      (Feature_4272399675__private_featureState,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_4272399675__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_4272399675__private_IsEnabledFallback

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_4272399675__private_IsEnabledFallback|
|fullname|Feature_4272399675__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_4272399675__private_IsEnabledDeviceUsageNoInline|
|paramcount|0|
|address|1401915fc|
|sig|undefined Feature_4272399675__private_IsEnabledFallback(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_4272399675__private_IsEnabledFallback
+++ Feature_4272399675__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_4272399675__private_IsEnabledFallback(undefined8 param_1,undefined8 param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_4272399675__private_descriptor);
+  return;
+}
+

```


## Feature_3999242553__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_3999242553__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_3999242553__private_IsEnabledDeviceUsageNoInline|
|refcount|3|
|length|49|
|called|Feature_3999242553__private_IsEnabledFallback|
|calling|Ipv6pHandleNeighborSolicitation|
|paramcount|0|
|address|1401a60ac|
|sig|undefined Feature_3999242553__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3999242553__private_IsEnabledDeviceUsageNoInline
+++ Feature_3999242553__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,16 @@
+
+ulonglong Feature_3999242553__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  
+  if ((Feature_3999242553__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_3999242553__private_IsEnabledFallback
+                      (Feature_3999242553__private_featureState,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_3999242553__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_3999242553__private_IsEnabledFallback

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_3999242553__private_IsEnabledFallback|
|fullname|Feature_3999242553__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_3999242553__private_IsEnabledDeviceUsageNoInline|
|paramcount|0|
|address|1401a60e4|
|sig|undefined Feature_3999242553__private_IsEnabledFallback(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3999242553__private_IsEnabledFallback
+++ Feature_3999242553__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_3999242553__private_IsEnabledFallback(undefined8 param_1,undefined8 param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_3999242553__private_descriptor);
+  return;
+}
+

```


## Feature_3131548987__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_3131548987__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_3131548987__private_IsEnabledDeviceUsageNoInline|
|refcount|6|
|length|49|
|called|Feature_3131548987__private_IsEnabledFallback|
|calling|InetWakeAcquirePortAf<br>InetWakeReleasePortAf|
|paramcount|0|
|address|1401c0a90|
|sig|undefined Feature_3131548987__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3131548987__private_IsEnabledDeviceUsageNoInline
+++ Feature_3131548987__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,16 @@
+
+ulonglong Feature_3131548987__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  
+  if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_3131548987__private_IsEnabledFallback
+                      (Feature_3131548987__private_featureState,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_3131548987__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_3131548987__private_IsEnabledFallback

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_3131548987__private_IsEnabledFallback|
|fullname|Feature_3131548987__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_3131548987__private_IsEnabledDeviceUsageNoInline|
|paramcount|0|
|address|1401c0ac8|
|sig|undefined Feature_3131548987__private_IsEnabledFallback(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_3131548987__private_IsEnabledFallback
+++ Feature_3131548987__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_3131548987__private_IsEnabledFallback(undefined8 param_1,undefined8 param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_3131548987__private_descriptor);
+  return;
+}
+

```


## Feature_4005012793__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_4005012793__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_4005012793__private_IsEnabledDeviceUsageNoInline|
|refcount|4|
|length|49|
|called|Feature_4005012793__private_IsEnabledFallback|
|calling|Fl8AddGroup<br>FlpDeleteGroupUnderLock|
|paramcount|0|
|address|1401c2094|
|sig|undefined Feature_4005012793__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_4005012793__private_IsEnabledDeviceUsageNoInline
+++ Feature_4005012793__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,16 @@
+
+ulonglong Feature_4005012793__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  ulonglong uVar1;
+  
+  if ((Feature_4005012793__private_featureState & 0x10) == 0) {
+    uVar1 = Feature_4005012793__private_IsEnabledFallback
+                      (Feature_4005012793__private_featureState,3);
+  }
+  else {
+    uVar1 = (ulonglong)(Feature_4005012793__private_featureState & 1);
+  }
+  return uVar1;
+}
+

```


## Feature_4005012793__private_IsEnabledFallback

### Function Meta



|Key|tcpip-8875.sys|
| :---: | :---: |
|name|Feature_4005012793__private_IsEnabledFallback|
|fullname|Feature_4005012793__private_IsEnabledFallback|
|refcount|2|
|length|21|
|called|wil_details_IsEnabledFallback|
|calling|Feature_4005012793__private_IsEnabledDeviceUsageNoInline|
|paramcount|0|
|address|1401c20cc|
|sig|undefined Feature_4005012793__private_IsEnabledFallback(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_4005012793__private_IsEnabledFallback
+++ Feature_4005012793__private_IsEnabledFallback
@@ -0,0 +1,8 @@
+
+void Feature_4005012793__private_IsEnabledFallback(undefined8 param_1,undefined8 param_2)
+
+{
+  wil_details_IsEnabledFallback(param_1,param_2,&Feature_4005012793__private_descriptor);
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## InetWakeAcquirePortAf

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.23|
|i_ratio|0.44|
|m_ratio|0.86|
|b_ratio|0.35|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|InetWakeAcquirePortAf|InetWakeAcquirePortAf|
|fullname|InetWakeAcquirePortAf|InetWakeAcquirePortAf|
|refcount|3|3|
|`length`|686|918|
|`called`|InetSetInterfacePropertyAf<br>InetWakeLookupPort<br>IsPortWithinRange<br>McTemplateK0qhqqq_EtwWriteTransfer<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>__security_check_cookie<br>memset|<details><summary>Expand for full list:<br>Feature_3131548987__private_IsEnabledDeviceUsageNoInline<br>InetSetInterfacePropertyAf<br>InetWakeLookupPort<br>InetWakeRemovePortEntryIfPresent<br>IsPortWithinRange<br>McTemplateK0qhqqq_EtwWriteTransfer<br>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>__security_check_cookie</summary>memset</details>|
|calling|InetWakeAcquirePort|InetWakeAcquirePort|
|paramcount|0|0|
|`address`|1401c0810|1401c0b74|
|sig|undefined InetWakeAcquirePortAf(void)|undefined InetWakeAcquirePortAf(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### InetWakeAcquirePortAf Called Diff


```diff
--- InetWakeAcquirePortAf called
+++ InetWakeAcquirePortAf called
@@ -0,0 +1 @@
+Feature_3131548987__private_IsEnabledDeviceUsageNoInline
@@ -2,0 +4 @@
+InetWakeRemovePortEntryIfPresent
```


### InetWakeAcquirePortAf Diff


```diff
--- InetWakeAcquirePortAf
+++ InetWakeAcquirePortAf
@@ -1,123 +1,182 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 ulonglong InetWakeAcquirePortAf
                     (ushort param_1,longlong param_2,undefined8 *param_3,longlong param_4)
 
 {
   longlong *plVar1;
   code *pcVar2;
   char cVar3;
   uint uVar4;
-  longlong lVar5;
-  longlong *plVar6;
-  ulonglong uVar7;
-  undefined4 uVar8;
-  undefined1 auStack_188 [32];
-  undefined4 local_168;
-  undefined1 *local_160;
+  uint uVar5;
+  int iVar6;
+  longlong lVar7;
+  longlong *plVar8;
+  ulonglong uVar9;
+  undefined4 uVar10;
+  undefined1 auStack_178 [32];
   undefined4 local_158;
-  undefined4 local_150;
-  undefined1 local_148;
-  undefined1 local_138 [36];
-  ushort local_114;
-  undefined4 local_110;
-  undefined4 local_70;
-  undefined4 local_68;
-  ulonglong local_58;
+  undefined1 *local_150;
+  undefined4 local_148;
+  undefined4 local_140;
+  undefined1 local_138;
+  longlong local_130;
+  undefined1 local_128 [36];
+  ushort local_104;
+  undefined4 local_100;
+  undefined4 local_60;
+  undefined4 local_58;
+  ulonglong local_48;
   
-  local_58 = __security_cookie ^ (ulonglong)auStack_188;
-  uVar8 = 0;
-  uVar4 = 0;
-  local_148 = KeAcquireSpinLockRaiseToDpc(param_4);
-  lVar5 = InetWakeLookupPort(param_1,param_2,param_3,param_4);
-  if (lVar5 == 0) {
-    plVar6 = (longlong *)ExAllocatePool2(0x40,0x30,0x50576e49);
-    if (plVar6 == (longlong *)0x0) {
-      uVar4 = 0xc0000017;
+  local_48 = __security_cookie ^ (ulonglong)auStack_178;
+  uVar10 = 0;
+  uVar5 = 0;
+  local_130 = param_2;
+  local_138 = KeAcquireSpinLockRaiseToDpc(param_4);
+  lVar7 = InetWakeLookupPort(param_1,param_2,param_3,param_4);
+  if (lVar7 == 0) {
+    plVar8 = (longlong *)ExAllocatePool2(0x40,0x30,0x50576e49);
+    if (plVar8 == (longlong *)0x0) {
+      uVar5 = 0xc0000017;
     }
     else {
-      *(undefined4 *)(plVar6 + 2) = 1;
-      *(ushort *)(plVar6 + 3) = param_1;
-      plVar6[4] = param_2;
-      plVar6[5] = (longlong)param_3;
+      *(undefined4 *)(plVar8 + 2) = 1;
+      if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+        uVar4 = Feature_3131548987__private_IsEnabledDeviceUsageNoInline();
+      }
+      else {
+        uVar4 = Feature_3131548987__private_featureState & 1;
+      }
+      if (uVar4 != 0) {
+        *(undefined4 *)((longlong)plVar8 + 0x14) = 0;
+      }
       plVar1 = (longlong *)(param_4 + 0x10);
-      lVar5 = *plVar1;
-      if (*(longlong **)(lVar5 + 8) != plVar1) goto LAB_0;
-      *plVar6 = lVar5;
-      plVar6[1] = (longlong)plVar1;
-      *(longlong **)(lVar5 + 8) = plVar6;
-      *plVar1 = (longlong)plVar6;
+      *(ushort *)((longlong)plVar8 + 0x1c) = param_1;
+      plVar8[4] = param_2;
+      plVar8[5] = (longlong)param_3;
+      lVar7 = *plVar1;
+      if (*(longlong **)(lVar7 + 8) != plVar1) goto LAB_0;
+      *plVar8 = lVar7;
+      plVar8[1] = (longlong)plVar1;
+      *(longlong **)(lVar7 + 8) = plVar8;
+      *plVar1 = (longlong)plVar8;
       cVar3 = IsPortWithinRange(param_1,param_4 + 0x20);
       if (cVar3 == '\0') {
-        *(int *)(plVar6 + 2) = (int)plVar6[2] + 1;
+        if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+          uVar5 = Feature_3131548987__private_IsEnabledDeviceUsageNoInline();
+        }
+        else {
+          uVar5 = Feature_3131548987__private_featureState & 1;
+        }
+        if (uVar5 == 0) {
+          *(int *)(plVar8 + 2) = (int)plVar8[2] + 1;
+        }
+        else {
+          *(undefined4 *)((longlong)plVar8 + 0x14) = 1;
+        }
         KeReleaseSpinLock(param_4);
-        memset(local_138,0,0xd8);
-        local_110 = *(undefined4 *)(param_4 + 8);
-        local_160 = local_138;
-        local_158 = 0xd8;
-        local_168 = 0;
-        local_70 = 3;
-        local_114 = param_1;
-        uVar4 = InetSetInterfacePropertyAf(param_2,param_3,0,0x12);
-        local_148 = KeAcquireSpinLockRaiseToDpc(param_4);
-        plVar1 = plVar6 + 2;
-        *(int *)plVar1 = (int)*plVar1 + -1;
-        if ((int)*plVar1 == 0) {
-          if (-1 < (int)uVar4) {
-            KeReleaseSpinLock(param_4,local_148);
-            local_160 = local_138;
-            local_158 = 0xd8;
-            local_168 = 0;
+        memset(local_128,0,0xd8);
+        local_100 = *(undefined4 *)(param_4 + 8);
+        local_150 = local_128;
+        local_148 = 0xd8;
+        local_158 = 0;
+        local_60 = 3;
+        local_104 = param_1;
+        uVar5 = InetSetInterfacePropertyAf(param_2,param_3,0,0x12);
+        local_138 = KeAcquireSpinLockRaiseToDpc(param_4);
+        if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+          uVar4 = Feature_3131548987__private_IsEnabledDeviceUsageNoInline();
+        }
+        else {
+          uVar4 = Feature_3131548987__private_featureState & 1;
+        }
+        if (uVar4 == 0) {
+          iVar6 = (int)plVar8[2] + -1;
+          *(int *)(plVar8 + 2) = iVar6;
+          if (iVar6 != 0) goto LAB_1;
+          if (-1 < (int)uVar5) {
+            KeReleaseSpinLock(param_4);
+            local_150 = local_128;
+            local_148 = 0xd8;
+            local_158 = 0;
             InetSetInterfacePropertyAf(param_2,param_3,0,0x13);
-            lVar5 = *plVar6;
-            if ((*(longlong **)(lVar5 + 8) != plVar6) ||
-               (plVar1 = (longlong *)plVar6[1], (longlong *)*plVar1 != plVar6)) goto LAB_0;
-            *plVar1 = lVar5;
-            *(longlong **)(lVar5 + 8) = plVar1;
-            ExFreePoolWithTag(plVar6,0);
-            goto LAB_1;
+            lVar7 = *plVar8;
+            if ((*(longlong **)(lVar7 + 8) != plVar8) ||
+               (plVar1 = (longlong *)plVar8[1], (longlong *)*plVar1 != plVar8)) goto LAB_0;
+            *plVar1 = lVar7;
+            *(longlong **)(lVar7 + 8) = plVar1;
+            goto LAB_2;
           }
         }
-        else if (-1 < (int)uVar4) {
-          *(undefined4 *)((longlong)plVar6 + 0x14) = local_68;
-          goto LAB_2;
+        else {
+          *(undefined4 *)((longlong)plVar8 + 0x14) = 0;
+          if ((int)plVar8[2] == 0) {
+            if (-1 < (int)uVar5) {
+              KeReleaseSpinLock(param_4);
+              local_150 = local_128;
+              local_148 = 0xd8;
+              local_158 = 0;
+              InetSetInterfacePropertyAf(param_2,param_3,0,0x13);
+LAB_2:
+              ExFreePoolWithTag(plVar8,0);
+              goto LAB_3;
+            }
+          }
+          else {
+LAB_1:
+            if (-1 < (int)uVar5) {
+              *(undefined4 *)(plVar8 + 3) = local_58;
+              goto LAB_4;
+            }
+          }
         }
-        lVar5 = *plVar6;
-        if ((*(longlong **)(lVar5 + 8) != plVar6) ||
-           (plVar1 = (longlong *)plVar6[1], (longlong *)*plVar1 != plVar6)) {
+        if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+          uVar4 = Feature_3131548987__private_IsEnabledDeviceUsageNoInline();
+        }
+        else {
+          uVar4 = Feature_3131548987__private_featureState & 1;
+        }
+        if (uVar4 == 0) {
+          lVar7 = *plVar8;
+          if ((*(longlong **)(lVar7 + 8) != plVar8) ||
+             (plVar1 = (longlong *)plVar8[1], (longlong *)*plVar1 != plVar8)) {
 LAB_0:
-          pcVar2 = (code *)swi(0x29);
-          (*pcVar2)(3);
-          pcVar2 = (code *)swi(3);
-          uVar7 = (*pcVar2)();
-          return uVar7;
+            pcVar2 = (code *)swi(0x29);
+            (*pcVar2)(3);
+            pcVar2 = (code *)swi(3);
+            uVar9 = (*pcVar2)();
+            return uVar9;
+          }
+          *plVar1 = lVar7;
+          *(longlong **)(lVar7 + 8) = plVar1;
         }
-        *plVar1 = lVar5;
-        *(longlong **)(lVar5 + 8) = plVar1;
-        ExFreePoolWithTag(plVar6,0);
+        else {
+          InetWakeRemovePortEntryIfPresent(plVar8);
+        }
+        ExFreePoolWithTag(plVar8,0);
       }
     }
   }
   else {
-    *(int *)(lVar5 + 0x10) = *(int *)(lVar5 + 0x10) + 1;
+    *(int *)(lVar7 + 0x10) = *(int *)(lVar7 + 0x10) + 1;
   }
-LAB_2:
-  KeReleaseSpinLock(param_4,local_148);
-LAB_1:
+LAB_4:
+  KeReleaseSpinLock(param_4,local_138);
+LAB_3:
   if ((Microsoft_Windows_TCPIPEnableBits & 8) != 0) {
     if (param_3 == (undefined8 *)0x0) {
-      local_150 = 0;
+      local_140 = 0;
     }
     else {
-      uVar8 = *(undefined4 *)(param_3 + 1);
-      local_150 = *(undefined4 *)*param_3;
+      uVar10 = *(undefined4 *)(param_3 + 1);
+      local_140 = *(undefined4 *)*param_3;
     }
-    local_160 = (undefined1 *)CONCAT44(local_160._4_4_,(uint)*(ushort *)(param_2 + 0x18));
-    local_168 = CONCAT22(local_168._2_2_,param_1 >> 8 | param_1 << 8);
-    local_158 = uVar8;
+    local_150 = (undefined1 *)CONCAT44(local_150._4_4_,(uint)*(ushort *)(local_130 + 0x18));
+    local_158 = CONCAT22(local_158._2_2_,param_1 >> 8 | param_1 << 8);
+    local_148 = uVar10;
     McTemplateK0qhqqq_EtwWriteTransfer();
   }
-  return (ulonglong)uVar4;
+  return (ulonglong)uVar5;
 }
 

```


## PktMonClientComponentUnregister

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.98|
|i_ratio|0.18|
|m_ratio|0.21|
|b_ratio|0.21|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|PktMonClientComponentUnregister|PktMonClientComponentUnregister|
|fullname|PktMonClientComponentUnregister|PktMonClientComponentUnregister|
|refcount|6|6|
|`length`|26|270|
|`called`||NTOSKRNL.EXE::ExAcquireRundownProtectionCacheAware<br>NTOSKRNL.EXE::ExReleaseRundownProtectionCacheAware<br>NTOSKRNL.EXE::KeReleaseMutex<br>NTOSKRNL.EXE::KeWaitForSingleObject<br>_guard_dispatch_icall<br>memset|
|calling|FlPktMonRegisterInterface<br>FlpDestroyClientInterface<br>IppCleanupInterfaceWorkerRoutine<br>IppPktMonRegisterInterface|FlPktMonRegisterInterface<br>FlpDestroyClientInterface<br>IppCleanupInterfaceWorkerRoutine<br>IppPktMonRegisterInterface|
|paramcount|0|0|
|`address`|140112384|140111794|
|sig|undefined PktMonClientComponentUnregister(void)|undefined PktMonClientComponentUnregister(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### PktMonClientComponentUnregister Called Diff


```diff
--- PktMonClientComponentUnregister called
+++ PktMonClientComponentUnregister called
@@ -0,0 +1,6 @@
+NTOSKRNL.EXE::ExAcquireRundownProtectionCacheAware
+NTOSKRNL.EXE::ExReleaseRundownProtectionCacheAware
+NTOSKRNL.EXE::KeReleaseMutex
+NTOSKRNL.EXE::KeWaitForSingleObject
+_guard_dispatch_icall
+memset
```


### PktMonClientComponentUnregister Diff


```diff
--- PktMonClientComponentUnregister
+++ PktMonClientComponentUnregister
@@ -1,57 +1,57 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void PktMonClientComponentUnregister(longlong *param_1)
 
 {
   longlong lVar1;
   longlong *plVar2;
   undefined8 *puVar3;
   longlong *plVar4;
   code *pcVar5;
   char cVar6;
   
   if (param_1[5] != 0) {
     KeWaitForSingleObject(&PktMonCompMutex,0,0,0,0);
     if (param_1[5] != 0) {
       cVar6 = ExAcquireRundownProtectionCacheAware(DAT_0);
       if (cVar6 != '\0') {
-        (**(code **)(DAT_1 + 0x10))(DAT_14022d9a0);
+        (**(code **)(DAT_1 + 0x10))(DAT_14022e9c0);
         ExReleaseRundownProtectionCacheAware(DAT_0);
       }
       lVar1 = *param_1;
       if ((*(longlong **)(lVar1 + 8) != param_1) ||
          (plVar2 = (longlong *)param_1[1], (longlong *)*plVar2 != param_1)) {
 LAB_2:
         pcVar5 = (code *)swi(0x29);
         (*pcVar5)(3);
         pcVar5 = (code *)swi(0x29);
         (*pcVar5)(3);
         pcVar5 = (code *)swi(3);
         (*pcVar5)();
         return;
       }
       _PktMonCompCount = _PktMonCompCount + -1;
       *plVar2 = lVar1;
       *(longlong **)(lVar1 + 8) = plVar2;
       plVar2 = param_1 + 2;
       while ((longlong *)*plVar2 != plVar2) {
         puVar3 = (undefined8 *)param_1[3];
         if (((longlong *)*puVar3 != plVar2) ||
            (plVar4 = (longlong *)puVar3[1], (undefined8 *)*plVar4 != puVar3)) goto LAB_2;
         param_1[3] = (longlong)plVar4;
         *plVar4 = (longlong)plVar2;
         *puVar3 = 0;
         puVar3[1] = 0;
         puVar3[2] = 0;
         puVar3[3] = 0;
         puVar3[4] = 0;
       }
       memset(param_1,0,0x40);
     }
     KeReleaseMutex(&PktMonCompMutex,0);
   }
   return;
 }
 

```


## Ipv6pHandleNeighborSolicitation

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.08|
|i_ratio|0.29|
|m_ratio|0.85|
|b_ratio|0.3|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|Ipv6pHandleNeighborSolicitation|Ipv6pHandleNeighborSolicitation|
|fullname|Ipv6pHandleNeighborSolicitation|Ipv6pHandleNeighborSolicitation|
|`refcount`|3|2|
|`length`|857|1062|
|`called`|<details><summary>Expand for full list:<br>FUN_1401cceb6<br>FUN_1401ccede<br>IN6_IS_ADDR_UNSPECIFIED<br>IppDereferenceLocalAddress<br>IppHandleNeighborSolicitation<br>IppPktMonToIcmpDropReason<br>Ipv6pSendNeighborAdvertisement<br>LogIcmpReceiveDrop<br>NDIS.SYS::NdisGetDataBuffer<br>NETIO.SYS::NetioPhGetNdLinkLayerOptionAddress<br>NTOSKRNL.EXE::ExAllocatePool2</summary>NetioAdvanceNetBuffer<br>NetioRetreatNetBuffer<br>__security_check_cookie</details>|<details><summary>Expand for full list:<br>CarAcquireCacheAwareReference<br>Feature_3999242553__private_IsEnabledDeviceUsageNoInline<br>IN6_IS_ADDR_UNSPECIFIED<br>IppDereferenceLocalAddress<br>IppHandleNeighborSolicitation<br>IppPktMonToIcmpDropReason<br>IppTimerUpdateNextExpirationTick<br>Ipv6pSendNeighborAdvertisement<br>LogIcmpReceiveDrop<br>NDIS.SYS::NdisGetDataBuffer<br>NETIO.SYS::NetioPhGetNdLinkLayerOptionAddress</summary>NTOSKRNL.EXE::ExAllocatePool2<br>NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel<br>NetioAdvanceNetBuffer<br>NetioRetreatNetBuffer<br>RtlAcquireWriteLockAtDpcLevel<br>TtInitializeTimer<br>TtStartTimerEx<br>__security_check_cookie</details>|
|calling|Icmpv6ReceiveDatagrams|Icmpv6ReceiveDatagrams|
|paramcount|0|0|
|`address`|14008fed8|14014a4f0|
|sig|undefined Ipv6pHandleNeighborSolicitation(void)|undefined Ipv6pHandleNeighborSolicitation(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### Ipv6pHandleNeighborSolicitation Called Diff


```diff
--- Ipv6pHandleNeighborSolicitation called
+++ Ipv6pHandleNeighborSolicitation called
@@ -1,2 +1,2 @@
-FUN_1401cceb6
-FUN_1401ccede
+CarAcquireCacheAwareReference
+Feature_3999242553__private_IsEnabledDeviceUsageNoInline
@@ -6,0 +7 @@
+IppTimerUpdateNextExpirationTick
@@ -11,0 +13 @@
+NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel
@@ -13,0 +16,3 @@
+RtlAcquireWriteLockAtDpcLevel
+TtInitializeTimer
+TtStartTimerEx
```


### Ipv6pHandleNeighborSolicitation Diff


```diff
--- Ipv6pHandleNeighborSolicitation
+++ Ipv6pHandleNeighborSolicitation
@@ -1,174 +1,219 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* WARNING: Removing unreachable block (ram,0x0001401ccf4c) */
+/* WARNING: Removing unreachable block (ram,0x00014014a81c) */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void Ipv6pHandleNeighborSolicitation(longlong param_1,longlong param_2)
 
 {
   undefined4 *puVar1;
-  longlong *plVar2;
-  code *pcVar3;
-  undefined1 auVar4 [16];
-  undefined4 uVar5;
+  longlong lVar2;
+  longlong *plVar3;
+  code *pcVar4;
+  undefined1 auVar5 [16];
   undefined4 uVar6;
-  char cVar7;
-  int iVar8;
-  longlong lVar9;
-  longlong lVar10;
+  undefined4 uVar7;
+  char cVar8;
+  int iVar9;
+  uint uVar10;
   longlong lVar11;
   longlong lVar12;
-  undefined4 uVar13;
-  undefined8 uVar14;
-  undefined1 auStack_c8 [32];
-  longlong *local_a8;
-  undefined1 *local_a0;
-  undefined4 local_98;
-  undefined4 local_90;
-  undefined4 local_88 [2];
-  longlong local_80;
-  longlong local_78;
-  longlong local_70;
-  undefined8 local_68;
-  undefined8 uStack_60;
-  undefined8 local_58;
-  undefined1 local_50 [32];
-  ulonglong local_30;
+  longlong lVar13;
+  undefined1 *puVar14;
+  undefined4 uVar15;
+  ulonglong uVar16;
+  undefined8 uVar17;
+  undefined1 auStack_e8 [8];
+  undefined1 auStack_e0 [24];
+  longlong *local_c8;
+  undefined1 *local_c0;
+  undefined4 local_b8;
+  undefined4 local_b0;
+  undefined4 local_a8 [2];
+  longlong local_a0;
+  char *local_98;
+  longlong local_90;
+  undefined8 local_88;
+  undefined8 uStack_80;
+  undefined8 local_78;
+  undefined8 local_70;
+  undefined8 uStack_68;
+  undefined8 local_60;
+  undefined1 local_58 [32];
+  ulonglong local_38;
   
-  local_30 = __security_cookie ^ (ulonglong)auStack_c8;
+  puVar14 = auStack_e8;
+  local_38 = __security_cookie ^ (ulonglong)auStack_e8;
   puVar1 = *(undefined4 **)(param_2 + 0x18);
-  lVar10 = *(longlong *)(*(longlong *)(param_2 + 8) + 8);
-  lVar12 = *(longlong *)(param_2 + 0xe0);
-  local_88[0] = 0;
-  lVar11 = *(longlong *)(*(longlong *)(param_2 + 0xd8) + 8);
-  plVar2 = (longlong *)**(longlong **)(*(longlong *)(param_2 + 0xd8) + 0x10);
-  local_68 = 0;
-  uStack_60 = 0;
-  local_58 = 0;
-  cVar7 = *(char *)(*(longlong *)(lVar11 + 0x30) + 2);
-  local_80 = 0;
-  local_78 = lVar11;
-  local_70 = param_1;
-  if (((*(byte *)(param_2 + 0xb8) & 8) != 0) || ((*(byte *)(param_2 + 0xbb) & 1) != 0)) {
-    local_90 = 0xe0004244;
-    iVar8 = 0x2a;
-    goto LAB_0;
-  }
-  if (*(char *)(*(longlong *)(param_2 + 0x118) + 7) != -1) {
-    local_90 = 0xe00041c9;
-    iVar8 = 0x11;
-    goto LAB_0;
-  }
-  if (*(char *)(param_1 + 1) != '\0') {
-    local_90 = 0xe00041ca;
-    iVar8 = 0x12;
-    goto LAB_0;
-  }
-  if (*(uint *)(lVar10 + 0x18) < 0x18) {
-    local_90 = 0xe00041cb;
-    iVar8 = 0xf;
-    goto LAB_0;
-  }
-  local_a8 = (longlong *)((ulonglong)local_a8 & 0xffffffff00000000);
-  lVar9 = NdisGetDataBuffer(lVar10,0x18,&local_68);
-  if (*(char *)(lVar9 + 8) == -1) {
-    local_90 = 0xe00041cc;
-LAB_1:
-    iVar8 = 0x20;
+  lVar12 = *(longlong *)(*(longlong *)(param_2 + 8) + 8);
+  lVar13 = *(longlong *)(param_2 + 0xe0);
+  local_a8[0] = 0;
+  lVar2 = *(longlong *)(*(longlong *)(param_2 + 0xd8) + 8);
+  plVar3 = (longlong *)**(longlong **)(*(longlong *)(param_2 + 0xd8) + 0x10);
+  local_60 = 0;
+  local_70 = 0;
+  uStack_68 = 0;
+  cVar8 = *(char *)(*(longlong *)(lVar2 + 0x30) + 2);
+  local_a0 = 0;
+  local_90 = param_1;
+  if (((*(byte *)(param_2 + 0xb8) & 8) == 0) && ((*(byte *)(param_2 + 0xbb) & 1) == 0)) {
+    if (*(char *)(*(longlong *)(param_2 + 0x118) + 7) == -1) {
+      if (*(char *)(param_1 + 1) == '\0') {
+        if (*(uint *)(lVar12 + 0x18) < 0x18) {
+          local_b0 = 0xe00041cb;
+          iVar9 = 0xf;
+        }
+        else {
+          local_c8 = (longlong *)((ulonglong)local_c8 & 0xffffffff00000000);
+          lVar11 = NdisGetDataBuffer(lVar12,0x18,&local_70);
+          local_98 = (char *)(lVar11 + 8);
+          if (*local_98 == -1) {
+            local_b0 = 0xe00041cc;
+LAB_0:
+            iVar9 = 0x20;
+          }
+          else {
+            NetioAdvanceNetBuffer(lVar12,0x18);
+            if (((*(uint *)(*(longlong *)(lVar2 + 0x30) + 0x1c) & 0x210) == 0x10) && (cVar8 != '\0')
+               ) {
+              uVar17 = 1;
+            }
+            else {
+              uVar17 = 0;
+            }
+            local_c0 = local_58;
+            local_c8 = &local_a0;
+            iVar9 = NetioPhGetNdLinkLayerOptionAddress(lVar12,1,uVar17,cVar8);
+            NetioRetreatNetBuffer(lVar12,0x18);
+            if (((iVar9 + 0x80000000U & 0x80000000) == 0) && (iVar9 != -0x3ffffddb)) {
+              local_b0 = 0xe00041cd;
+              iVar9 = 0x1b;
+            }
+            else {
+              cVar8 = IN6_IS_ADDR_UNSPECIFIED(puVar1);
+              if (cVar8 != '\0') {
+                if (((*plVar3 != 0x2ff) || ((int)plVar3[1] != 0x1000000)) ||
+                   (*(char *)((longlong)plVar3 + 0xc) != -1)) {
+                  local_b0 = 0xe00041ce;
+                  goto LAB_0;
+                }
+                if (local_a0 != 0) {
+                  local_b0 = 0xe00041cf;
+                  iVar9 = 0x15;
+                  goto LAB_1;
+                }
+              }
+              local_c8 = (longlong *)local_a8;
+              lVar12 = IppHandleNeighborSolicitation(lVar13,local_a0,puVar1,local_98);
+              if (lVar12 != 0) {
+                if ((*(int *)(lVar12 + 0x18) == 1) ||
+                   (lVar11 = ExAllocatePool2(0x40,0x48,0x61613649), lVar11 == 0)) {
+                  Ipv6pSendNeighborAdvertisement(lVar13,0,puVar1,lVar12);
+                }
+                else {
+                  *(longlong *)(lVar11 + 0x28) = lVar13;
+                  local_88 = 0;
+                  uStack_80 = 0;
+                  local_78 = 0;
+                  LOCK();
+                  plVar3 = (longlong *)(lVar13 + 0x40);
+                  lVar13 = *plVar3;
+                  *plVar3 = *plVar3 + 1;
+                  UNLOCK();
+                  puVar14 = auStack_e8;
+                  if (lVar13 + 1 < 2) {
+                    pcVar4 = (code *)swi(0x29);
+                    (*pcVar4)(0xe);
+                    puVar14 = auStack_e0;
+                  }
+                  *(longlong *)(lVar11 + 0x30) = lVar12;
+                  uVar17 = *(undefined8 *)(lVar12 + 0x20);
+                  *(undefined8 *)(puVar14 + -8) = 0x14014a795;
+                  CarAcquireCacheAwareReference(uVar17,1);
+                  uVar15 = puVar1[1];
+                  uVar6 = puVar1[2];
+                  uVar7 = puVar1[3];
+                  *(undefined4 *)(lVar11 + 0x38) = *puVar1;
+                  *(undefined4 *)(lVar11 + 0x3c) = uVar15;
+                  *(undefined4 *)(lVar11 + 0x40) = uVar6;
+                  *(undefined4 *)(lVar11 + 0x44) = uVar7;
+                  *(undefined8 *)(puVar14 + -8) = 0x14014a7a7;
+                  TtInitializeTimer(lVar11);
+                  uVar16 = _DAT_2 / 10000;
+                  auVar5._8_8_ = 0;
+                  auVar5._0_8_ = uVar16;
+                  lVar13 = SUB168(ZEXT816(0x624dd2f1a9fbe77) * auVar5,8);
+                  if ((Feature_3999242553__private_featureState & 0x10) == 0) {
+                    *(undefined8 *)(puVar14 + -8) = 0x14014a7f6;
+                    uVar10 = Feature_3999242553__private_IsEnabledDeviceUsageNoInline();
+                  }
+                  else {
+                    uVar10 = Feature_3999242553__private_featureState & 1;
+                  }
+                  if (uVar10 != 0) {
+                    *(undefined8 *)(puVar14 + -8) = 0x14014a80a;
+                    RtlAcquireWriteLockAtDpcLevel(lVar2 + 0x178,&local_88);
+                  }
+                  IppRandomValue = IppRandomValue * 0x19660d + 0x3c6ef35f;
+                  LOCK();
+                  UNLOCK();
+                  uVar17 = *(undefined8 *)(lVar2 + 0x2c8);
+                  uVar15 = (undefined4)((uVar16 - lVar13 >> 1) + lVar13 >> 8);
+                  *(undefined8 *)(puVar14 + -8) = 0x14014a83b;
+                  iVar9 = TtStartTimerEx(uVar17,lVar11,uVar15,1);
+                  if (iVar9 != 0) {
+                    *(undefined8 *)(puVar14 + -8) = 0x14014a848;
+                    IppTimerUpdateNextExpirationTick(uVar15,iVar9);
+                  }
+                  if ((Feature_3999242553__private_featureState & 0x10) == 0) {
+                    *(undefined8 *)(puVar14 + -8) = 0x14014a85c;
+                    uVar10 = Feature_3999242553__private_IsEnabledDeviceUsageNoInline();
+                  }
+                  else {
+                    uVar10 = Feature_3999242553__private_featureState & 1;
+                  }
+                  if (uVar10 != 0) {
+                    *(undefined8 *)(puVar14 + -8) = 0x14014a86b;
+                    KeReleaseInStackQueuedSpinLockFromDpcLevel(&local_88);
+                  }
+                }
+                *(undefined8 *)(puVar14 + -8) = 0x14014a88a;
+                IppDereferenceLocalAddress(lVar12);
+                *(undefined4 *)(*(longlong *)(param_2 + 8) + 0x8c) = 0;
+                goto LAB_3;
+              }
+              iVar9 = IppPktMonToIcmpDropReason(local_a8[0]);
+              local_b0 = 0xe00041d0;
+              puVar14 = auStack_e8;
+              if (iVar9 == 0x2c) goto LAB_3;
+            }
+          }
+        }
+      }
+      else {
+        local_b0 = 0xe00041ca;
+        iVar9 = 0x12;
+      }
+    }
+    else {
+      local_b0 = 0xe00041c9;
+      iVar9 = 0x11;
+    }
   }
   else {
-    NetioAdvanceNetBuffer(lVar10,0x18);
-    if (((*(uint *)(*(longlong *)(lVar11 + 0x30) + 0x1c) & 0x210) == 0x10) && (cVar7 != '\0')) {
-      uVar14 = 1;
-    }
-    else {
-      uVar14 = 0;
-    }
-    local_a0 = local_50;
-    local_a8 = &local_80;
-    iVar8 = NetioPhGetNdLinkLayerOptionAddress(lVar10,1,uVar14,cVar7);
-    NetioRetreatNetBuffer(lVar10,0x18);
-    if (((iVar8 + 0x80000000U & 0x80000000) == 0) && (iVar8 != -0x3ffffddb)) {
-      local_90 = 0xe00041cd;
-      iVar8 = 0x1b;
-      goto LAB_0;
-    }
-    cVar7 = IN6_IS_ADDR_UNSPECIFIED(puVar1);
-    if (cVar7 != '\0') {
-      lVar10 = *plVar2 + -0x2ff;
-      if ((lVar10 == 0) && (lVar10 = (ulonglong)*(uint *)(plVar2 + 1) - 0x1000000, lVar10 == 0)) {
-        FUN_1401cceb6((ulonglong)*(byte *)((longlong)plVar2 + 0xc) - 0xff);
-        return;
-      }
-      if (lVar10 != 0) {
-        local_90 = 0xe00041ce;
-        goto LAB_1;
-      }
-      if (local_80 != 0) {
-        local_90 = 0xe00041cf;
-        iVar8 = 0x15;
-        goto LAB_0;
-      }
-    }
-    local_a8 = (longlong *)local_88;
-    lVar10 = IppHandleNeighborSolicitation(lVar12,local_80,puVar1,(char *)(lVar9 + 8));
-    if (lVar10 != 0) {
-      if ((*(int *)(lVar10 + 0x18) == 1) ||
-         (lVar11 = ExAllocatePool2(0x40,0x48,0x61613649), lVar11 == 0)) {
-        Ipv6pSendNeighborAdvertisement(lVar12,0,puVar1,lVar10);
-      }
-      else {
-        *(longlong *)(lVar11 + 0x28) = lVar12;
-        LOCK();
-        plVar2 = (longlong *)(lVar12 + 0x40);
-        lVar12 = *plVar2;
-        *plVar2 = *plVar2 + 1;
-        UNLOCK();
-        if (lVar12 + 1 < 2) {
-          pcVar3 = (code *)swi(0x29);
-          (*pcVar3)(0xe);
-          FUN_1401ccede();
-          return;
-        }
-        *(longlong *)(lVar11 + 0x30) = lVar10;
-        CarAcquireCacheAwareReference(*(undefined8 *)(lVar10 + 0x20),1);
-        uVar13 = puVar1[1];
-        uVar5 = puVar1[2];
-        uVar6 = puVar1[3];
-        *(undefined4 *)(lVar11 + 0x38) = *puVar1;
-        *(undefined4 *)(lVar11 + 0x3c) = uVar13;
-        *(undefined4 *)(lVar11 + 0x40) = uVar5;
-        *(undefined4 *)(lVar11 + 0x44) = uVar6;
-        TtInitializeTimer(lVar11);
-        auVar4._8_8_ = 0;
-        auVar4._0_8_ = _DAT_2 / 10000;
-        lVar12 = SUB168(ZEXT816(0x624dd2f1a9fbe77) * auVar4,8);
-        IppRandomValue = IppRandomValue * 0x19660d + 0x3c6ef35f;
-        LOCK();
-        UNLOCK();
-        uVar13 = (undefined4)((_DAT_2 / 10000 - lVar12 >> 1) + lVar12 >> 8);
-        iVar8 = TtStartTimerEx(*(undefined8 *)(local_78 + 0x2c8),lVar11,uVar13,1);
-        if (iVar8 != 0) {
-          IppTimerUpdateNextExpirationTick(uVar13,iVar8);
-        }
-      }
-      IppDereferenceLocalAddress(lVar10);
-      *(undefined4 *)(*(longlong *)(param_2 + 8) + 0x8c) = 0;
-      return;
-    }
-    iVar8 = IppPktMonToIcmpDropReason(local_88[0]);
-    local_90 = 0xe00041d0;
-    if (iVar8 == 0x2c) {
-      return;
-    }
+    local_b0 = 0xe0004244;
+    iVar9 = 0x2a;
   }
-LAB_0:
-  local_98 = 8;
+LAB_1:
+  local_b8 = 8;
   *(undefined4 *)(*(longlong *)(param_2 + 8) + 0x8c) = 0xc000021b;
-  local_a8 = (longlong *)CONCAT44(local_a8._4_4_,*(undefined4 *)(*(longlong *)(param_2 + 8) + 0x8c))
+  local_c8 = (longlong *)CONCAT44(local_c8._4_4_,*(undefined4 *)(*(longlong *)(param_2 + 8) + 0x8c))
   ;
-  local_a0 = (undefined1 *)param_2;
-  LogIcmpReceiveDrop(&Ipv6Global,0x87,*(undefined1 *)(local_70 + 1),iVar8);
+  local_c0 = (undefined1 *)param_2;
+  LogIcmpReceiveDrop(&Ipv6Global,0x87,*(undefined1 *)(local_90 + 1),iVar9);
+  puVar14 = auStack_e8;
+LAB_3:
+  *(undefined8 *)(puVar14 + -8) = 0x14014a8f5;
   return;
 }
 

```


## RawBindEndpointInspectComplete

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.85|
|i_ratio|0.53|
|m_ratio|0.74|
|b_ratio|0.74|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|RawBindEndpointInspectComplete|RawBindEndpointInspectComplete|
|fullname|RawBindEndpointInspectComplete|RawBindEndpointInspectComplete|
|refcount|6|6|
|`length`|573|337|
|`called`|<details><summary>Expand for full list:<br>InetDereferenceLocalAddressAf<br>InetFormatLocalSockAddrAtDispatchLevel<br>McTemplateK0pqqbr2qq_EtwWriteTransfer<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireInStackQueuedSpinLock<br>NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLock<br>NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel<br>NTOSKRNL.EXE::KeReleaseSemaphore<br>RawDereferenceEndpoint<br>RtlAcquireWriteLockAtDpcLevel<br>SOCKADDR_SIZE</summary>_InetDereferenceAf<br>__security_check_cookie<br>_guard_dispatch_icall</details>|InetDereferenceLocalAddressAf<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireInStackQueuedSpinLock<br>NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLock<br>NTOSKRNL.EXE::KeReleaseSemaphore<br>RawDereferenceEndpoint<br>_InetDereferenceAf<br>__security_check_cookie<br>_guard_dispatch_icall|
|calling|RawBindEndpointRequestInspectComplete|RawBindEndpointRequestInspectComplete|
|paramcount|0|0|
|`address`|140086c90|140055d00|
|sig|undefined RawBindEndpointInspectComplete(void)|undefined RawBindEndpointInspectComplete(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### RawBindEndpointInspectComplete Called Diff


```diff
--- RawBindEndpointInspectComplete called
+++ RawBindEndpointInspectComplete called
@@ -2,2 +1,0 @@
-InetFormatLocalSockAddrAtDispatchLevel
-McTemplateK0pqqbr2qq_EtwWriteTransfer
@@ -7 +4,0 @@
-NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel
@@ -10,2 +6,0 @@
-RtlAcquireWriteLockAtDpcLevel
-SOCKADDR_SIZE
```


### RawBindEndpointInspectComplete Diff


```diff
--- RawBindEndpointInspectComplete
+++ RawBindEndpointInspectComplete
@@ -1,135 +1,135 @@
 
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void RawBindEndpointInspectComplete(longlong param_1,uint param_2)
 
 {
   longlong *plVar1;
   longlong lVar2;
   longlong *plVar3;
   code *pcVar4;
   char cVar5;
   undefined1 uVar6;
   undefined1 uVar7;
   longlong *plVar8;
   longlong *plVar9;
   undefined2 uVar10;
   int unaff_ESI;
   int unaff_R12D;
   ushort unaff_R13W;
   undefined8 auStack_a8 [4];
-  undefined4 local_88;
+  undefined4 uStack_88;
   undefined1 uStack_60;
-  longlong *local_40;
+  longlong *plStack_40;
   undefined8 uStack_38;
-  undefined8 local_30;
+  undefined8 uStack_30;
   ulonglong local_28;
   
   local_28 = __security_cookie ^ (ulonglong)auStack_a8;
   plVar8 = *(longlong **)(param_1 + 8);
   plVar9 = (longlong *)(ulonglong)param_2;
   KeAcquireInStackQueuedSpinLock(plVar8,&stack0xffffffffffffffa8);
   do {
   } while ((int)plVar8[1] != 0);
   if ((int)param_2 < 0) {
     if ((*(uint *)(plVar8 + 3) & 1) != 0) {
-      local_30 = 0;
-      local_40 = (longlong *)0x0;
+      uStack_30 = 0;
+      plStack_40 = (longlong *)0x0;
       uStack_38 = 0;
       *(uint *)(plVar8 + 3) = *(uint *)(plVar8 + 3) & 0xfffffffe;
-      RtlAcquireWriteLockAtDpcLevel(&RawEndpointMrswLock,&local_40);
+      RtlAcquireWriteLockAtDpcLevel(&RawEndpointMrswLock,&plStack_40);
       plVar1 = plVar8 + 4;
       lVar2 = *plVar1;
       if ((*(longlong **)(lVar2 + 8) != plVar1) ||
          (plVar3 = (longlong *)plVar8[5], (longlong *)*plVar3 != plVar1)) {
         pcVar4 = (code *)swi(0x29);
         (*pcVar4)(3);
 LAB_0:
-        auStack_a8[0] = 0x1401cc67d;
+        auStack_a8[0] = 0x1401c83cb;
         uVar6 = KfRaiseIrql(unaff_R13W & 0xff);
-        auStack_a8[0] = 0x1401cc68e;
+        auStack_a8[0] = 0x1401c83dc;
         uVar7 = SOCKADDR_SIZE(*(undefined2 *)((longlong)plVar9 + 0x34));
-        auStack_a8[0] = 0x1401cc6b7;
+        auStack_a8[0] = 0x1401c8405;
         TcpRecentFailureTrace(uVar7,(longlong)plVar9 + 0x34,0,0);
-        auStack_a8[0] = 0x1401cc6c2;
+        auStack_a8[0] = 0x1401c8410;
         KeLowerIrql(uVar6);
         do {
-          auStack_a8[0] = 0x1400890f4;
+          auStack_a8[0] = 0x140058164;
           TcpBindEndpointRequestInspectComplete(plVar9,unaff_ESI,uStack_60,(longlong)plVar9 + 0x34);
           do {
             plVar9 = plVar8;
             if (plVar9 == (longlong *)0x0) {
               return;
             }
             uStack_60 = (undefined1)unaff_R12D;
             plVar8 = (longlong *)*plVar9;
             lVar2 = plVar9[1];
-            auStack_a8[0] = 0x140089068;
+            auStack_a8[0] = 0x1400580d8;
             KeWaitForSingleObject(lVar2 + 0x100,0,0,0);
             if (*(short *)((longlong)plVar9 + 0x34) == 0x17) {
-              auStack_a8[0] = 0x140089132;
+              auStack_a8[0] = 0x1400581a2;
               cVar5 = IN6_IS_ADDR_V4MAPPED((longlong)plVar9 + 0x3c);
               if (cVar5 != '\0') {
                 *(int *)(plVar9 + 7) = (int)plVar9[9];
                 *(ushort *)((longlong)plVar9 + 0x34) = unaff_R13W;
                 *(undefined2 *)((longlong)plVar9 + 0x36) = *(undefined2 *)((longlong)plVar9 + 0x36);
                 *(undefined8 *)((longlong)plVar9 + 0x3c) = 0;
                 *(byte *)((longlong)plVar9 + 0x32) = *(byte *)((longlong)plVar9 + 0x32) | 1;
               }
             }
-            auStack_a8[0] = 0x1400890a6;
+            auStack_a8[0] = 0x140058116;
             unaff_ESI = AleInspectBindRequest(*(undefined8 *)(lVar2 + 0x50));
             if (DAT_1 != unaff_R12D) {
               if ((DAT_2 & 8) != 0) {
-                auStack_a8[0] = 0x14008919b;
+                auStack_a8[0] = 0x14005820b;
                 McTemplateK0ppqqq_EtwWriteTransfer(&MICROSOFT_TCPIP_PROVIDER_Context);
               }
             }
             if (unaff_ESI < 0) goto LAB_0;
           } while (unaff_ESI == 0x103);
         } while( true );
       }
       *plVar3 = lVar2;
       *(longlong **)(lVar2 + 8) = plVar3;
-      KeReleaseInStackQueuedSpinLockFromDpcLevel(&local_40);
+      KeReleaseInStackQueuedSpinLockFromDpcLevel(&plStack_40);
     }
     *(uint *)(plVar8 + 3) = *(uint *)(plVar8 + 3) & 0xffffffef;
     plVar8[0xf] = plVar8[7];
     plVar8[0xe] = 0;
     *(undefined2 *)(plVar8 + 0xd) = 0;
   }
   else {
     *(longlong *)(param_1 + 0x28) = plVar8[7];
     *(undefined8 *)(param_1 + 0x20) = 0;
     if ((DAT_1 != 0) && ((Microsoft_Windows_TCPIPEnableBits & 8) != 0)) {
       if ((*(uint *)(plVar8 + 3) & 0x10) == 0) {
         uVar10 = *(undefined2 *)(plVar8[7] + 0x18);
       }
       else {
         uVar10 = 0x17;
       }
       uStack_38 = 0;
-      local_40 = plVar8;
+      plStack_40 = plVar8;
       InetFormatLocalSockAddrAtDispatchLevel
                 (plVar8[7],(*(uint *)(plVar8 + 3) & 0x10) != 0,plVar8[0xe],0);
       SOCKADDR_SIZE(uVar10);
-      local_88 = (undefined4)plVar8[8];
+      uStack_88 = (undefined4)plVar8[8];
       McTemplateK0pqqbr2qq_EtwWriteTransfer
-                (&MICROSOFT_TCPIP_PROVIDER_Context,&RAW_BIND_ENDPOINT_COMPLETE,&local_40,plVar8);
+                (&MICROSOFT_TCPIP_PROVIDER_Context,&RAW_BIND_ENDPOINT_COMPLETE,&plStack_40,plVar8);
     }
   }
   KeReleaseInStackQueuedSpinLock(&stack0xffffffffffffffa8);
   KeReleaseSemaphore(plVar8 + 0x1c,0,1);
   (**(code **)(param_1 + 0x10))(*(undefined8 *)(param_1 + 0x18),plVar9,0);
   if (*(longlong *)(param_1 + 0x20) != 0) {
     InetDereferenceLocalAddressAf(*(undefined8 *)(param_1 + 0x28));
   }
   if ((*(longlong *)(param_1 + 0x28) != 0) && (*(longlong *)(param_1 + 0x28) != plVar8[7])) {
     _InetDereferenceAf();
   }
   RawDereferenceEndpoint(*(undefined8 *)(param_1 + 8));
   ExFreePoolWithTag(param_1,0x57456152);
   return;
 }
 

```


## Fl8AddGroup

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.13|
|i_ratio|0.2|
|m_ratio|0.95|
|b_ratio|0.33|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|Fl8AddGroup|Fl8AddGroup|
|fullname|Fl8AddGroup|Fl8AddGroup|
|`refcount`|9|6|
|`length`|1024|1089|
|`called`|<details><summary>Expand for full list:<br>FlpDeleteGroupUnderLock<br>FlpInterfaceAcquireWriteLock<br>FlpInterfaceReleaseReadLock<br>FlpSerializedNdisRequestUnderLock<br>McTemplateK0z_EtwWriteTransfer<br>NTOSKRNL.EXE::ExAllocateFromLookasideListEx<br>PplpLazyInitializeLookasideList<br>__security_check_cookie<br>_guard_dispatch_icall<br>memcmp<br>memmove</summary>memset</details>|<details><summary>Expand for full list:<br>Feature_4005012793__private_IsEnabledDeviceUsageNoInline<br>FlpDeleteGroupUnderLock<br>FlpSerializedNdisRequestUnderLock<br>McTemplateK0z_EtwWriteTransfer<br>NDIS.SYS::NdisAcquireRWLockWrite<br>NDIS.SYS::NdisReleaseRWLock<br>NTOSKRNL.EXE::ExAllocateFromLookasideListEx<br>PplpLazyInitializeLookasideList<br>__security_check_cookie<br>_guard_dispatch_icall<br>memcmp</summary>memmove</details>|
|calling|||
|paramcount|0|0|
|`address`|1400202c0|14014e810|
|sig|undefined Fl8AddGroup(void)|undefined Fl8AddGroup(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### Fl8AddGroup Called Diff


```diff
--- Fl8AddGroup called
+++ Fl8AddGroup called
@@ -0,0 +1 @@
+Feature_4005012793__private_IsEnabledDeviceUsageNoInline
@@ -2,2 +2,0 @@
-FlpInterfaceAcquireWriteLock
-FlpInterfaceReleaseReadLock
@@ -5,0 +5,2 @@
+NDIS.SYS::NdisAcquireRWLockWrite
+NDIS.SYS::NdisReleaseRWLock
@@ -12 +12,0 @@
-memset
```


### Fl8AddGroup Diff


```diff
--- Fl8AddGroup
+++ Fl8AddGroup
@@ -1,226 +1,264 @@
 
+/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 
 ulonglong Fl8AddGroup(undefined8 *param_1)
 
 {
-  longlong *plVar1;
-  byte bVar2;
-  byte bVar3;
-  longlong lVar4;
+  byte bVar1;
+  longlong lVar2;
+  undefined8 *puVar3;
+  undefined8 uVar4;
   code *pcVar5;
-  int iVar6;
+  undefined1 auVar6 [13];
   undefined1 auVar7 [13];
-  undefined1 auVar8 [13];
-  uint5 uVar9;
+  uint5 uVar8;
+  undefined1 auVar9 [13];
   undefined1 auVar10 [13];
-  undefined1 auVar11 [13];
-  uint uVar12;
-  uint uVar13;
-  uint uVar14;
-  longlong *plVar15;
-  ulonglong uVar16;
-  ulonglong uVar17;
-  longlong *plVar18;
+  ulonglong uVar11;
+  longlong *plVar12;
+  longlong *plVar13;
+  ulonglong uVar14;
+  byte *pbVar15;
+  longlong *plVar16;
+  int iVar17;
+  uint uVar18;
   uint uVar19;
   ulonglong uVar20;
-  byte *pbVar21;
-  undefined8 *puVar22;
-  longlong lVar23;
-  undefined8 *puVar24;
-  ulonglong uVar25;
-  uint uVar26;
-  int iVar27;
-  int iVar28;
-  int iVar29;
-  int iVar30;
+  uint uVar21;
+  longlong lVar22;
+  undefined1 *puVar23;
+  undefined1 *puVar24;
+  uint uVar25;
+  undefined8 *puVar26;
+  uint uVar27;
+  uint uVar29;
+  ulonglong uVar30;
   int iVar31;
   int iVar32;
   int iVar33;
   int iVar34;
-  undefined1 auStack_88 [32];
-  undefined8 local_68;
-  undefined8 local_60;
+  int iVar35;
+  int iVar36;
+  int iVar37;
+  int iVar38;
+  undefined1 auStack_88 [8];
+  undefined1 auStack_80 [40];
   undefined2 local_58;
-  undefined1 local_56;
+  undefined1 uStack_56;
   undefined4 local_50;
-  undefined1 local_4c;
-  undefined1 local_4b;
+  uint auStack_4c [7];
   ulonglong local_30;
+  ulonglong uVar28;
   
+  puVar24 = auStack_88;
+  puVar23 = auStack_88;
   local_30 = __security_cookie ^ (ulonglong)auStack_88;
-  uVar16 = 0;
-  lVar4 = *(longlong *)(param_1[2] + 0x48);
+  uVar11 = 0;
+  uVar27 = 0;
+  uVar29 = 0;
+  lVar2 = *(longlong *)(param_1[2] + 0x48);
   local_58 = 0;
-  local_56 = 0;
-  lVar23 = *(longlong *)(lVar4 + 0x20);
-  bVar2 = *(byte *)(lVar4 + 0x48a);
+  uStack_56 = 0;
+  lVar22 = *(longlong *)(lVar2 + 0x20);
+  bVar1 = *(byte *)(lVar2 + 0x48a);
   *(undefined8 *)param_1[5] = 0;
-  pcVar5 = *(code **)(lVar23 + 0x198);
-  lVar23 = param_1[4];
-  if (pcVar5 == Fl48pMapMulticastAddress) {
-    iVar27 = *(int *)(lVar4 + 0x138);
-    if (iVar27 == 0) {
-      local_50._0_2_ = 1;
-      local_50._2_1_ = 0x5e;
-      local_50._3_1_ = *(byte *)(lVar23 + 1) & 0x7f;
-      local_4c = *(undefined1 *)(lVar23 + 2);
-      local_4b = *(undefined1 *)(lVar23 + 3);
+  iVar31 = (**(code **)(lVar22 + 0x198))(&local_50,param_1[4],lVar2);
+  if (iVar31 != 0) {
+    uVar11 = 0xc0000001;
+    puVar24 = auStack_88;
+    goto LAB_0;
+  }
+  NdisAcquireRWLockWrite(*(undefined8 *)(lVar2 + 0x28),&local_58,0);
+  uVar25 = 0;
+  uVar21 = (uint)bVar1;
+  uVar14 = uVar11;
+  uVar28 = uVar11;
+  if (7 < uVar21) {
+    iVar35 = 0;
+    iVar36 = 0;
+    iVar37 = 0;
+    iVar38 = 0;
+    iVar31 = 0;
+    iVar32 = 0;
+    iVar33 = 0;
+    iVar34 = 0;
+    do {
+      iVar17 = (int)uVar14;
+      uVar19 = *(uint *)((longlong)auStack_4c + (uVar14 - 4));
+      uVar18 = iVar17 + 8;
+      uVar14 = (ulonglong)uVar18;
+      auVar6[0xc] = (char)(uVar19 >> 0x18);
+      auVar6._0_12_ = ZEXT712(0);
+      uVar8 = CONCAT32(auVar6._10_3_,(ushort)(byte)(uVar19 >> 0x10));
+      auVar9._5_8_ = 0;
+      auVar9._0_5_ = uVar8;
+      iVar35 = iVar35 + (uVar19 & 0xff);
+      iVar36 = iVar36 + (int)CONCAT72(SUB137(auVar9 << 0x40,6),(ushort)(byte)(uVar19 >> 8));
+      iVar37 = iVar37 + (int)uVar8;
+      iVar38 = iVar38 + (uint)(uint3)(auVar6._10_3_ >> 0x10);
+      uVar19 = *(uint *)((longlong)auStack_4c + ((ulonglong)(iVar17 + 4) - 4));
+      auVar7[0xc] = (char)(uVar19 >> 0x18);
+      auVar7._0_12_ = ZEXT712(0);
+      uVar8 = CONCAT32(auVar7._10_3_,(ushort)(byte)(uVar19 >> 0x10));
+      auVar10._5_8_ = 0;
+      auVar10._0_5_ = uVar8;
+      iVar31 = (uVar19 & 0xff) + iVar31;
+      iVar32 = (int)CONCAT72(SUB137(auVar10 << 0x40,6),(ushort)(byte)(uVar19 >> 8)) + iVar32;
+      iVar33 = (int)uVar8 + iVar33;
+      iVar34 = (uint)(uint3)(auVar7._10_3_ >> 0x10) + iVar34;
+    } while (uVar18 < (bVar1 & 0xfffffff8));
+    uVar28 = (ulonglong)
+             (uint)(iVar35 + iVar31 + iVar37 + iVar33 + iVar36 + iVar32 + iVar38 + iVar34);
+  }
+  iVar31 = (int)uVar28;
+  uVar19 = (uint)uVar14;
+  if (uVar19 < uVar21) {
+    if (uVar21 - uVar19 < 2) {
+LAB_1:
+      iVar31 = iVar31 + (uint)*(byte *)((longlong)auStack_4c + (uVar14 - 4));
     }
     else {
-      if (((iVar27 != 9) && (iVar27 != 0x12)) && (iVar27 != 0x13)) {
-        return 0xc0000001;
-      }
-      memset(&local_50,0,(ulonglong)*(byte *)(lVar4 + 0x48a));
-    }
-  }
-  else {
-    iVar27 = (*pcVar5)(&local_50,lVar23,lVar4);
-    if (iVar27 != 0) {
-      return 0xc0000001;
-    }
-  }
-  FlpInterfaceAcquireWriteLock(lVar4,&local_58);
-  uVar14 = 0;
-  uVar26 = (uint)bVar2;
-  uVar17 = uVar16;
-  if (bVar2 != 0) {
-    uVar20 = uVar16;
-    if (7 < uVar26) {
-      iVar31 = 0;
-      iVar32 = 0;
-      iVar33 = 0;
-      iVar34 = 0;
-      iVar27 = 0;
-      iVar28 = 0;
-      iVar29 = 0;
-      iVar30 = 0;
+      uVar18 = ((uVar21 - uVar19) - 2 >> 1) + 1;
+      uVar30 = (ulonglong)uVar18;
+      uVar28 = uVar11;
+      uVar20 = uVar11;
       do {
-        uVar13 = *(uint *)((longlong)&local_50 + uVar20);
-        iVar6 = (int)uVar20;
-        uVar19 = iVar6 + 8;
-        uVar20 = (ulonglong)uVar19;
-        auVar7[0xc] = (char)(uVar13 >> 0x18);
-        auVar7._0_12_ = ZEXT712(0);
-        uVar9 = CONCAT32(auVar7._10_3_,(ushort)(byte)(uVar13 >> 0x10));
-        auVar10._5_8_ = 0;
-        auVar10._0_5_ = uVar9;
-        iVar31 = iVar31 + (uVar13 & 0xff);
-        iVar32 = iVar32 + (int)CONCAT72(SUB137(auVar10 << 0x40,6),(ushort)(byte)(uVar13 >> 8));
-        iVar33 = iVar33 + (int)uVar9;
-        iVar34 = iVar34 + (uint)(uint3)(auVar7._10_3_ >> 0x10);
-        uVar13 = *(uint *)((longlong)&local_50 + (ulonglong)(iVar6 + 4));
-        auVar8[0xc] = (char)(uVar13 >> 0x18);
-        auVar8._0_12_ = ZEXT712(0);
-        uVar9 = CONCAT32(auVar8._10_3_,(ushort)(byte)(uVar13 >> 0x10));
-        auVar11._5_8_ = 0;
-        auVar11._0_5_ = uVar9;
-        iVar27 = iVar27 + (uVar13 & 0xff);
-        iVar28 = iVar28 + (int)CONCAT72(SUB137(auVar11 << 0x40,6),(ushort)(byte)(uVar13 >> 8));
-        iVar29 = iVar29 + (int)uVar9;
-        iVar30 = iVar30 + (uint)(uint3)(auVar8._10_3_ >> 0x10);
-      } while (uVar19 < (bVar2 & 0xfffffff8));
-      uVar17 = (ulonglong)
-               (uint)(iVar27 + iVar31 + iVar29 + iVar33 + iVar28 + iVar32 + iVar30 + iVar34);
-      if (uVar26 <= uVar19) goto LAB_0;
-    }
-    pbVar21 = (byte *)((longlong)&local_50 + uVar20);
-    uVar20 = (ulonglong)((uint)bVar2 - (int)uVar20);
-    do {
-      bVar3 = *pbVar21;
-      pbVar21 = pbVar21 + 1;
-      uVar17 = (ulonglong)((int)uVar17 + (uint)bVar3);
-      uVar20 = uVar20 - 1;
-    } while (uVar20 != 0);
-  }
-LAB_0:
-  puVar22 = (undefined8 *)
-            (((ulonglong)(uint)((int)uVar17 + (int)(uVar17 / 0x1d) * -0x1d) + 0x15) * 0x10 + lVar4);
-  for (puVar24 = (undefined8 *)*puVar22; puVar24 != puVar22; puVar24 = (undefined8 *)*puVar24) {
-    plVar15 = puVar24 + -2;
-    iVar27 = memcmp((void *)((longlong)puVar24 + 0x12),&local_50,(ulonglong)bVar2);
-    if (iVar27 == 0) {
-      if (plVar15 != (longlong *)0x0) {
-        *(short *)(puVar24 + 2) = *(short *)(puVar24 + 2) + 1;
-        goto LAB_1;
+        uVar27 = (int)uVar28 + (uint)*(byte *)((longlong)auStack_4c + (uVar14 - 4));
+        uVar28 = (ulonglong)uVar27;
+        uVar29 = (int)uVar20 + (uint)*(byte *)((longlong)auStack_4c + (uVar14 - 3));
+        uVar20 = (ulonglong)uVar29;
+        uVar14 = uVar14 + 2;
+        uVar30 = uVar30 - 1;
+      } while (uVar30 != 0);
+      if (uVar19 + uVar18 * 2 < uVar21) goto LAB_1;
+    }
+    uVar28 = (ulonglong)(iVar31 + uVar29 + uVar27);
+  }
+  puVar26 = (undefined8 *)
+            (((ulonglong)(uint)((int)uVar28 + (int)(uVar28 / 0x1d) * -0x1d) + 0x15) * 0x10 + lVar2);
+  for (puVar3 = (undefined8 *)*puVar26; puVar3 != puVar26; puVar3 = (undefined8 *)*puVar3) {
+    plVar12 = puVar3 + -2;
+    iVar31 = memcmp(puVar3 + 3,&local_50,(ulonglong)bVar1);
+    if (iVar31 == 0) {
+      if (plVar12 != (longlong *)0x0) {
+        if ((Feature_4005012793__private_featureState & 0x10) == 0) {
+          uVar29 = Feature_4005012793__private_IsEnabledDeviceUsageNoInline();
+        }
+        else {
+          uVar29 = Feature_4005012793__private_featureState & 1;
+        }
+        if (uVar29 == 0) {
+          *(short *)(puVar3 + 2) = *(short *)(puVar3 + 2) + 1;
+          puVar24 = auStack_88;
+        }
+        else {
+          LOCK();
+          plVar13 = puVar3 + 2;
+          lVar22 = *plVar13;
+          *plVar13 = *plVar13 + 1;
+          UNLOCK();
+          if (lVar22 + 1 < 2) {
+            pcVar5 = (code *)swi(0x29);
+            (*pcVar5)(0xe);
+            puVar24 = auStack_80;
+          }
+        }
+        goto LAB_2;
       }
       break;
     }
   }
-  lVar23 = (ulonglong)(SystemReserved1[0x12]._4_4_ + 1) * 0x80 + FlpGroupBlockPool;
-  if (*(char *)(lVar23 + 0xb0) == '\0') {
-    PplpLazyInitializeLookasideList(FlpGroupBlockPool,lVar23 + 0x40);
-  }
-  plVar15 = (longlong *)ExAllocateFromLookasideListEx(lVar23 + 0x40);
-  if (plVar15 == (longlong *)0x0) {
-    if (DAT_2 < '\0') {
+  lVar22 = (ulonglong)(SystemReserved1[0x12]._4_4_ + 1) * 0x80 + FlpGroupBlockPool;
+  if (*(char *)(lVar22 + 0xb0) == '\0') {
+    PplpLazyInitializeLookasideList(FlpGroupBlockPool,lVar22 + 0x40);
+  }
+  plVar12 = (longlong *)ExAllocateFromLookasideListEx(lVar22 + 0x40);
+  if (plVar12 == (longlong *)0x0) {
+    if (DAT_3 < '\0') {
       McTemplateK0z_EtwWriteTransfer(&MICROSOFT_TCPIP_PROVIDER_Context,&TCPIP_MEMORY_FAILURES);
     }
-    FlpInterfaceReleaseReadLock(lVar4,&local_58);
-    return 0xc000009a;
-  }
-  *plVar15 = lVar4;
-  *(undefined1 *)(plVar15 + 1) = 1;
-  *(undefined2 *)(plVar15 + 4) = 1;
-  memmove((void *)((longlong)plVar15 + 0x22),&local_50,(ulonglong)*(byte *)(lVar4 + 0x48a));
-  uVar17 = uVar16;
-  if (uVar26 < 2) {
-    uVar20 = uVar16;
-    uVar19 = uVar14;
-    uVar12 = 0;
-    if (bVar2 == 0) goto LAB_3;
+    NdisReleaseRWLock(*(undefined8 *)(lVar2 + 0x28),&local_58);
+    uVar11 = 0xc000009a;
+    puVar24 = auStack_88;
+    goto LAB_0;
+  }
+  *plVar12 = lVar2;
+  *(undefined1 *)(plVar12 + 1) = 1;
+  if ((Feature_4005012793__private_featureState & 0x10) == 0) {
+    uVar29 = Feature_4005012793__private_IsEnabledDeviceUsageNoInline();
   }
   else {
-    uVar13 = (bVar2 - 2 >> 1) + 1;
-    uVar25 = (ulonglong)uVar13;
-    pbVar21 = (byte *)((longlong)plVar15 + 0x23);
-    uVar20 = uVar16;
+    uVar29 = Feature_4005012793__private_featureState & 1;
+  }
+  if (uVar29 == 0) {
+    *(undefined2 *)(plVar12 + 4) = 1;
+  }
+  else {
+    plVar12[4] = 1;
+  }
+  memmove(plVar12 + 5,&local_50,(ulonglong)*(byte *)(lVar2 + 0x48a));
+  uVar14 = uVar11;
+  uVar28 = uVar11;
+  if (uVar21 < 2) {
+    uVar20 = uVar11;
+    if (bVar1 != 0) goto LAB_4;
+  }
+  else {
+    uVar29 = (uVar21 - 2 >> 1) + 1;
+    uVar20 = (ulonglong)uVar29;
+    pbVar15 = (byte *)((longlong)plVar12 + 0x29);
     do {
-      uVar17 = (ulonglong)((int)uVar17 + (uint)pbVar21[-1]);
-      uVar19 = (int)uVar20 + (uint)*pbVar21;
-      uVar20 = (ulonglong)uVar19;
-      uVar25 = uVar25 - 1;
-      pbVar21 = pbVar21 + 2;
-    } while (uVar25 != 0);
-    uVar20 = (ulonglong)uVar13 * 2;
-    uVar12 = uVar19;
-    if (uVar26 <= uVar13 * 2) goto LAB_3;
-  }
-  uVar19 = uVar12;
-  uVar14 = (uint)*(byte *)(uVar20 + 0x22 + (longlong)plVar15);
-LAB_3:
-  plVar1 = plVar15 + 2;
-  plVar18 = (longlong *)((ulonglong)((uVar14 + uVar19 + (int)uVar17) % 0x1d) * 0x10 + 0x150 + lVar4)
-  ;
-  lVar23 = *plVar18;
-  if (*(longlong **)(lVar23 + 8) != plVar18) {
+      uVar14 = (ulonglong)((int)uVar14 + (uint)pbVar15[-1]);
+      uVar28 = (ulonglong)((int)uVar28 + (uint)*pbVar15);
+      uVar20 = uVar20 - 1;
+      pbVar15 = pbVar15 + 2;
+    } while (uVar20 != 0);
+    uVar20 = (ulonglong)uVar29 * 2;
+    if (uVar29 * 2 < uVar21) {
+LAB_4:
+      uVar25 = (uint)*(byte *)(uVar20 + 0x28 + (longlong)plVar12);
+    }
+  }
+  plVar13 = plVar12 + 2;
+  plVar16 = (longlong *)
+            ((ulonglong)((uVar25 + (int)uVar28 + (int)uVar14) % 0x1d) * 0x10 + 0x150 + lVar2);
+  lVar22 = *plVar16;
+  if (*(longlong **)(lVar22 + 8) != plVar16) {
+    plVar16 = (longlong *)0x3;
     pcVar5 = (code *)swi(0x29);
-    (*pcVar5)(3);
-    pcVar5 = (code *)swi(3);
-    uVar16 = (*pcVar5)();
-    return uVar16;
-  }
-  *plVar1 = lVar23;
-  plVar15[3] = (longlong)plVar18;
-  *(longlong **)(lVar23 + 8) = plVar1;
-  *plVar18 = (longlong)plVar1;
-  *(int *)(lVar4 + 0x148) = *(int *)(lVar4 + 0x148) + 1;
-LAB_1:
-  if ((char)plVar15[1] != '\0') {
-    local_60 = *param_1;
-    local_68 = param_1[1];
-    uVar14 = FlpSerializedNdisRequestUnderLock
-                       (lVar4,FlpSerializedNdisAddGroupWorker,plVar15,param_1[3]);
-    uVar16 = (ulonglong)uVar14;
-    if ((int)uVar14 < 0) {
-      FlpDeleteGroupUnderLock(lVar4,plVar15);
-      FlpInterfaceReleaseReadLock(lVar4,&local_58);
-      return uVar16;
-    }
-  }
-  FlpInterfaceReleaseReadLock(lVar4,&local_58);
-  *(longlong **)param_1[5] = plVar15;
-  return uVar16;
+    plVar13 = (longlong *)(*pcVar5)();
+    puVar23 = auStack_80;
+  }
+  *plVar13 = lVar22;
+  plVar13[1] = (longlong)plVar16;
+  *(longlong **)(lVar22 + 8) = plVar13;
+  *plVar16 = (longlong)plVar13;
+  *(int *)(lVar2 + 0x148) = *(int *)(lVar2 + 0x148) + 1;
+  puVar24 = puVar23;
+LAB_2:
+  if ((char)plVar12[1] != '\0') {
+    uVar4 = param_1[3];
+    *(undefined8 *)(puVar24 + 0x28) = *param_1;
+    *(undefined8 *)(puVar24 + 0x20) = param_1[1];
+    *(undefined8 *)(puVar24 + -8) = 0x14014ebd6;
+    uVar29 = FlpSerializedNdisRequestUnderLock(lVar2,FlpSerializedNdisAddGroupWorker,plVar12,uVar4);
+    uVar11 = (ulonglong)uVar29;
+    if ((int)uVar29 < 0) {
+      *(undefined8 *)(puVar24 + -8) = 0x14014ebe7;
+      FlpDeleteGroupUnderLock(lVar2,plVar12);
+      uVar4 = *(undefined8 *)(lVar2 + 0x28);
+      *(undefined8 *)(puVar24 + -8) = 0x14014ebf7;
+      NdisReleaseRWLock(uVar4,puVar24 + 0x30);
+      goto LAB_0;
+    }
+  }
+  uVar4 = *(undefined8 *)(lVar2 + 0x28);
+  *(undefined8 *)(puVar24 + -8) = 0x14014ec0e;
+  NdisReleaseRWLock(uVar4,puVar24 + 0x30);
+  *(longlong **)param_1[5] = plVar12;
+LAB_0:
+  *(undefined8 *)(puVar24 + -8) = 0x14014ec46;
+  return uVar11;
 }
 

```


## FlpDeleteGroupUnderLock

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.43|
|i_ratio|0.32|
|m_ratio|0.76|
|b_ratio|0.64|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|FlpDeleteGroupUnderLock|FlpDeleteGroupUnderLock|
|fullname|FlpDeleteGroupUnderLock|FlpDeleteGroupUnderLock|
|refcount|3|3|
|`length`|121|189|
|`called`|FlpSerializedNdisRequestUnderLock<br>PplFreeToLookasideList|Feature_4005012793__private_IsEnabledDeviceUsageNoInline<br>FlpSerializedNdisRequestUnderLock<br>PplFreeToLookasideList|
|calling|Fl8AddGroup<br>Fl8DeleteGroup|Fl8AddGroup<br>Fl8DeleteGroup|
|paramcount|0|0|
|`address`|140111948|1400dd328|
|sig|undefined FlpDeleteGroupUnderLock(void)|undefined FlpDeleteGroupUnderLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### FlpDeleteGroupUnderLock Called Diff


```diff
--- FlpDeleteGroupUnderLock called
+++ FlpDeleteGroupUnderLock called
@@ -0,0 +1 @@
+Feature_4005012793__private_IsEnabledDeviceUsageNoInline
```


### FlpDeleteGroupUnderLock Diff


```diff
--- FlpDeleteGroupUnderLock
+++ FlpDeleteGroupUnderLock
@@ -1,32 +1,57 @@
 
 void FlpDeleteGroupUnderLock(longlong param_1,longlong param_2)
 
 {
   short *psVar1;
   longlong *plVar2;
   longlong lVar3;
   longlong *plVar4;
   code *pcVar5;
+  uint uVar6;
   
-  psVar1 = (short *)(param_2 + 0x20);
-  *psVar1 = *psVar1 + -1;
-  if (*psVar1 == 0) {
-    plVar2 = (longlong *)(param_2 + 0x10);
-    lVar3 = *plVar2;
-    if ((*(longlong **)(lVar3 + 8) != plVar2) ||
-       (plVar4 = *(longlong **)(param_2 + 0x18), (longlong *)*plVar4 != plVar2)) {
-      pcVar5 = (code *)swi(0x29);
-      (*pcVar5)(3);
-      pcVar5 = (code *)swi(3);
-      (*pcVar5)();
+  if ((Feature_4005012793__private_featureState & 0x10) == 0) {
+    uVar6 = Feature_4005012793__private_IsEnabledDeviceUsageNoInline();
+  }
+  else {
+    uVar6 = Feature_4005012793__private_featureState & 1;
+  }
+  if (uVar6 == 0) {
+    psVar1 = (short *)(param_2 + 0x20);
+    *psVar1 = *psVar1 + -1;
+    if (*psVar1 != 0) {
       return;
     }
+  }
+  else {
+    LOCK();
+    plVar2 = (longlong *)(param_2 + 0x20);
+    lVar3 = *plVar2;
+    *plVar2 = *plVar2 + -1;
+    UNLOCK();
+    if (1 < lVar3) {
+      return;
+    }
+    if (lVar3 != 1) {
+      pcVar5 = (code *)swi(0x29);
+      (*pcVar5)(0xe);
+      return;
+    }
+  }
+  plVar2 = (longlong *)(param_2 + 0x10);
+  lVar3 = *plVar2;
+  if ((*(longlong **)(lVar3 + 8) == plVar2) &&
+     (plVar4 = *(longlong **)(param_2 + 0x18), (longlong *)*plVar4 == plVar2)) {
     *plVar4 = lVar3;
     *(longlong **)(lVar3 + 8) = plVar4;
     *(int *)(param_1 + 0x148) = *(int *)(param_1 + 0x148) + -1;
     FlpSerializedNdisRequestUnderLock(param_1,FlpSerializedNdisDeleteGroupWorker,0,0,0,0);
     PplFreeToLookasideList(FlpGroupBlockPool,param_2);
+    return;
   }
+  pcVar5 = (code *)swi(0x29);
+  (*pcVar5)(3);
+  pcVar5 = (code *)swi(3);
+  (*pcVar5)();
   return;
 }
 

```


## AleRedirectRecordsDeserializeFromBuffer

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,refcount,length,address,called|
|ratio|0.33|
|i_ratio|0.32|
|m_ratio|0.88|
|b_ratio|0.63|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|AleRedirectRecordsDeserializeFromBuffer|AleRedirectRecordsDeserializeFromBuffer|
|fullname|AleRedirectRecordsDeserializeFromBuffer|AleRedirectRecordsDeserializeFromBuffer|
|`refcount`|4|3|
|`length`|578|685|
|`called`|AleRedirectRecordDereference<br>FUN_1401dad8a<br>WfpPoolAllocNonPaged<br>WfpReportSysErrorAsNtStatus<br>memmove|AleRedirectRecordDereference<br>Feature_1204007226__private_IsEnabledDeviceUsageNoInline<br>WfpPoolAllocNonPaged<br>WfpReportError<br>WfpReportSysErrorAsNtStatus<br>WfpSizeTMultiply<br>memmove|
|calling|TlShimQueryNonTcpRedirectRecords<br>WfpAleProcessSocketOption|TlShimQueryNonTcpRedirectRecords<br>WfpAleProcessSocketOption|
|paramcount|0|0|
|`address`|14011eff4|14013f8bc|
|sig|undefined AleRedirectRecordsDeserializeFromBuffer(void)|undefined AleRedirectRecordsDeserializeFromBuffer(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### AleRedirectRecordsDeserializeFromBuffer Called Diff


```diff
--- AleRedirectRecordsDeserializeFromBuffer called
+++ AleRedirectRecordsDeserializeFromBuffer called
@@ -2 +2 @@
-FUN_1401dad8a
+Feature_1204007226__private_IsEnabledDeviceUsageNoInline
@@ -3,0 +4 @@
+WfpReportError
@@ -4,0 +6 @@
+WfpSizeTMultiply
```


### AleRedirectRecordsDeserializeFromBuffer Diff


```diff
--- AleRedirectRecordsDeserializeFromBuffer
+++ AleRedirectRecordsDeserializeFromBuffer
@@ -1,144 +1,168 @@
 
 longlong AleRedirectRecordsDeserializeFromBuffer
                    (ulonglong *param_1,ulonglong param_2,ulonglong *param_3)
 
 {
   ushort uVar1;
   ulonglong uVar2;
-  ulonglong uVar3;
+  undefined4 uVar3;
   undefined4 uVar4;
-  undefined4 uVar5;
-  ulonglong *puVar6;
-  undefined2 *puVar7;
-  ulonglong *puVar8;
+  ulonglong *puVar5;
+  undefined2 *puVar6;
+  ulonglong *puVar7;
+  uint uVar8;
   longlong lVar9;
   ulonglong *puVar10;
   ulonglong *puVar11;
-  ulonglong uVar12;
+  ulonglong *puVar12;
   ulonglong *puVar13;
   ulonglong *puVar14;
+  ulonglong uVar15;
   ulonglong local_res8;
   ulonglong *local_res10;
   ulonglong *local_res18;
-  undefined2 *local_res20;
+  ulonglong local_res20;
+  undefined2 *local_58 [3];
   
   local_res8 = 0;
   puVar13 = &local_res8;
   puVar14 = (ulonglong *)0x0;
-  local_res20 = (undefined2 *)0x0;
+  local_res10 = (ulonglong *)0x0;
+  local_58[0] = (undefined2 *)0x0;
   local_res18 = param_3;
-  if (7 < param_2) {
+  if (param_2 < 8) {
+LAB_0:
+    lVar9 = WfpReportSysErrorAsNtStatus();
+    if (lVar9 == 0) {
+      return 0;
+    }
+  }
+  else {
     uVar2 = *param_1;
     param_1 = param_1 + 1;
-    param_2 = param_2 - 8;
-    if ((uVar2 != 0) && (uVar2 * 0x228 <= param_2)) {
-      for (uVar12 = 0; uVar12 < uVar2; uVar12 = uVar12 + 1) {
+    puVar12 = (ulonglong *)(param_2 - 8);
+    if ((Feature_1204007226__private_featureState & 0x10) == 0) {
+      uVar8 = Feature_1204007226__private_IsEnabledDeviceUsageNoInline();
+    }
+    else {
+      uVar8 = Feature_1204007226__private_featureState & 1;
+    }
+    if (uVar8 != 0) {
+      lVar9 = WfpSizeTMultiply(uVar2,0x228,&local_res10);
+      if (lVar9 != 0) goto LAB_1;
+      if ((uVar2 != 0) && (local_res10 <= puVar12)) goto LAB_2;
+      goto LAB_0;
+    }
+    if ((uVar2 == 0) || (puVar12 < (ulonglong *)(uVar2 * 0x228))) goto LAB_0;
+LAB_2:
+    local_res20 = 0;
+    if (uVar2 != 0) {
+      do {
         local_res10 = (ulonglong *)0x0;
+        if ((Feature_1204007226__private_featureState & 0x10) == 0) {
+          uVar8 = Feature_1204007226__private_IsEnabledDeviceUsageNoInline();
+        }
+        else {
+          uVar8 = Feature_1204007226__private_featureState & 1;
+        }
+        if ((uVar8 != 0) && (puVar12 < (ulonglong *)0x228)) goto LAB_0;
         lVar9 = WfpPoolAllocNonPaged(0x228,0x6c637241,&local_res10);
-        puVar6 = local_res10;
-        if (lVar9 != 0) goto LAB_0;
+        puVar5 = local_res10;
+        if (lVar9 != 0) goto LAB_3;
         lVar9 = 4;
         *puVar13 = (ulonglong)local_res10;
         puVar13 = param_1;
-        puVar8 = puVar6;
+        puVar7 = puVar5;
         do {
-          puVar11 = puVar8;
+          puVar11 = puVar7;
           puVar10 = puVar13;
-          uVar3 = puVar10[1];
+          uVar15 = puVar10[1];
           *puVar11 = *puVar10;
-          puVar11[1] = uVar3;
-          uVar3 = puVar10[3];
+          puVar11[1] = uVar15;
+          uVar15 = puVar10[3];
           puVar11[2] = puVar10[2];
-          puVar11[3] = uVar3;
-          uVar3 = puVar10[5];
+          puVar11[3] = uVar15;
+          uVar15 = puVar10[5];
           puVar11[4] = puVar10[4];
-          puVar11[5] = uVar3;
-          uVar3 = puVar10[7];
+          puVar11[5] = uVar15;
+          uVar15 = puVar10[7];
           puVar11[6] = puVar10[6];
-          puVar11[7] = uVar3;
-          uVar3 = puVar10[9];
+          puVar11[7] = uVar15;
+          uVar15 = puVar10[9];
           puVar11[8] = puVar10[8];
-          puVar11[9] = uVar3;
-          uVar3 = puVar10[0xb];
+          puVar11[9] = uVar15;
+          uVar15 = puVar10[0xb];
           puVar11[10] = puVar10[10];
-          puVar11[0xb] = uVar3;
-          uVar3 = puVar10[0xd];
+          puVar11[0xb] = uVar15;
+          uVar15 = puVar10[0xd];
           puVar11[0xc] = puVar10[0xc];
-          puVar11[0xd] = uVar3;
-          uVar3 = puVar10[0xf];
+          puVar11[0xd] = uVar15;
+          uVar15 = puVar10[0xf];
           puVar11[0xe] = puVar10[0xe];
-          puVar11[0xf] = uVar3;
+          puVar11[0xf] = uVar15;
           lVar9 = lVar9 + -1;
           puVar13 = puVar10 + 0x10;
-          puVar8 = puVar11 + 0x10;
+          puVar7 = puVar11 + 0x10;
         } while (lVar9 != 0);
-        uVar4 = *(undefined4 *)((longlong)puVar10 + 0x84);
-        uVar3 = puVar10[0x11];
-        uVar5 = *(undefined4 *)((longlong)puVar10 + 0x8c);
+        uVar3 = *(undefined4 *)((longlong)puVar10 + 0x84);
+        uVar15 = puVar10[0x11];
+        uVar4 = *(undefined4 *)((longlong)puVar10 + 0x8c);
         param_1 = param_1 + 0x45;
-        param_2 = param_2 - 0x228;
+        puVar12 = puVar12 + -0x45;
         *(int *)(puVar11 + 0x10) = (int)puVar10[0x10];
-        *(undefined4 *)((longlong)puVar11 + 0x84) = uVar4;
-        *(int *)(puVar11 + 0x11) = (int)uVar3;
-        *(undefined4 *)((longlong)puVar11 + 0x8c) = uVar5;
-        uVar4 = *(undefined4 *)((longlong)puVar10 + 0x94);
-        uVar3 = puVar10[0x13];
-        uVar5 = *(undefined4 *)((longlong)puVar10 + 0x9c);
+        *(undefined4 *)((longlong)puVar11 + 0x84) = uVar3;
+        *(int *)(puVar11 + 0x11) = (int)uVar15;
+        *(undefined4 *)((longlong)puVar11 + 0x8c) = uVar4;
+        uVar3 = *(undefined4 *)((longlong)puVar10 + 0x94);
+        uVar15 = puVar10[0x13];
+        uVar4 = *(undefined4 *)((longlong)puVar10 + 0x9c);
         *(int *)(puVar11 + 0x12) = (int)puVar10[0x12];
-        *(undefined4 *)((longlong)puVar11 + 0x94) = uVar4;
-        *(int *)(puVar11 + 0x13) = (int)uVar3;
-        *(undefined4 *)((longlong)puVar11 + 0x9c) = uVar5;
+        *(undefined4 *)((longlong)puVar11 + 0x94) = uVar3;
+        *(int *)(puVar11 + 0x13) = (int)uVar15;
+        *(undefined4 *)((longlong)puVar11 + 0x9c) = uVar4;
         puVar11[0x14] = puVar10[0x14];
-        *(undefined4 *)(puVar6 + 0x3e) = 1;
-        uVar3 = puVar6[0x3d];
-        if (uVar3 != 0) {
-          if (param_2 < uVar3) goto LAB_1;
-          lVar9 = WfpPoolAllocNonPaged(uVar3,0x6c637241,puVar6 + 0x3c);
-          if (lVar9 != 0) goto LAB_0;
-          memmove((void *)puVar6[0x3c],param_1,puVar6[0x3d]);
-          param_1 = (ulonglong *)((longlong)param_1 + puVar6[0x3d]);
-          param_2 = param_2 - puVar6[0x3d];
+        *(undefined4 *)(puVar5 + 0x3e) = 1;
+        puVar13 = (ulonglong *)puVar5[0x3d];
+        if (puVar13 != (ulonglong *)0x0) {
+          if (puVar12 < puVar13) goto LAB_0;
+          lVar9 = WfpPoolAllocNonPaged(puVar13,0x6c637241,puVar5 + 0x3c);
+          if (lVar9 != 0) goto LAB_3;
+          memmove((void *)puVar5[0x3c],param_1,puVar5[0x3d]);
+          param_1 = (ulonglong *)((longlong)param_1 + puVar5[0x3d]);
+          puVar12 = (ulonglong *)((longlong)puVar12 - puVar5[0x3d]);
         }
-        puVar13 = puVar6 + 6;
-        if (uVar12 == uVar2 - 1) {
-          puVar14 = puVar6;
+        puVar13 = puVar5 + 6;
+        if (local_res20 == uVar2 - 1) {
+          puVar14 = puVar5;
         }
-      }
-      if (3 < param_2) {
-        uVar1 = *(ushort *)((longlong)param_1 + 2);
-        uVar12 = (ulonglong)uVar1;
-        uVar2 = *param_1;
-        if (uVar12 <= param_2 - 4) {
-          lVar9 = WfpPoolAllocNonPaged(uVar12 + 0x10,0x6c637241,&local_res20);
-          puVar7 = local_res20;
-          if (lVar9 == 0) {
-            *local_res20 = (short)uVar2;
-            local_res20[1] = uVar1;
-            *(undefined2 **)(local_res20 + 4) = local_res20 + 8;
-            memmove(local_res20 + 8,(undefined2 *)((longlong)param_1 + 4),uVar12);
-            puVar14[7] = (ulonglong)puVar7;
-            *local_res18 = local_res8;
-            return 0;
-          }
-          goto LAB_0;
-        }
-      }
+        local_res20 = local_res20 + 1;
+      } while (local_res20 < uVar2);
+    }
+    if (puVar12 < (ulonglong *)0x4) goto LAB_0;
+    uVar1 = *(ushort *)((longlong)param_1 + 2);
+    uVar15 = (ulonglong)uVar1;
+    uVar2 = *param_1;
+    if ((longlong)puVar12 - 4U < uVar15) goto LAB_0;
+    lVar9 = WfpPoolAllocNonPaged(uVar15 + 0x10,0x6c637241,local_58);
+    puVar6 = local_58[0];
+    if (lVar9 == 0) {
+      *local_58[0] = (short)uVar2;
+      local_58[0][1] = uVar1;
+      *(undefined2 **)(local_58[0] + 4) = local_58[0] + 8;
+      memmove(local_58[0] + 8,(undefined2 *)((longlong)param_1 + 4),uVar15);
+      puVar14[7] = (ulonglong)puVar6;
+      *local_res18 = local_res8;
+      return 0;
     }
   }
+LAB_3:
+  if (local_res8 != 0) {
+    AleRedirectRecordDereference();
+  }
 LAB_1:
-  lVar9 = WfpReportSysErrorAsNtStatus();
-  if (lVar9 == 0) {
-    return 0;
+  if (lVar9 != 0) {
+    WfpReportError(lVar9,"AleRedirectRecordsDeserializeFromBuffer");
   }
-LAB_0:
-  if (local_res8 == 0) {
-    if (lVar9 != 0) {
-      WfpReportError(lVar9,"AleRedirectRecordsDeserializeFromBuffer");
-    }
-    return lVar9;
-  }
-  AleRedirectRecordDereference();
-  lVar9 = FUN_1401dad8a();
   return lVar9;
 }
 

```


## InetWakeReleasePortAf

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.3|
|i_ratio|0.43|
|m_ratio|0.92|
|b_ratio|0.74|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|InetWakeReleasePortAf|InetWakeReleasePortAf|
|fullname|InetWakeReleasePortAf|InetWakeReleasePortAf|
|refcount|4|4|
|`length`|342|383|
|`called`|InetSetInterfacePropertyAf<br>InetWakeLookupPort<br>IsPortWithinRange<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>__security_check_cookie<br>memset|Feature_3131548987__private_IsEnabledDeviceUsageNoInline<br>InetSetInterfacePropertyAf<br>InetWakeLookupPort<br>InetWakeRemovePortEntryIfPresent<br>IsPortWithinRange<br>NTOSKRNL.EXE::ExFreePoolWithTag<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>__security_check_cookie<br>memset|
|calling|InetWakeAcquirePort<br>InetWakeReleasePort|InetWakeAcquirePort<br>InetWakeReleasePort|
|paramcount|0|0|
|`address`|1400ce128|1400c7d58|
|sig|undefined InetWakeReleasePortAf(void)|undefined InetWakeReleasePortAf(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### InetWakeReleasePortAf Called Diff


```diff
--- InetWakeReleasePortAf called
+++ InetWakeReleasePortAf called
@@ -0,0 +1 @@
+Feature_3131548987__private_IsEnabledDeviceUsageNoInline
@@ -2,0 +4 @@
+InetWakeRemovePortEntryIfPresent
```


### InetWakeReleasePortAf Diff


```diff
--- InetWakeReleasePortAf
+++ InetWakeReleasePortAf
@@ -1,72 +1,75 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
-undefined4
+undefined8
 InetWakeReleasePortAf(undefined2 param_1,undefined8 param_2,undefined8 param_3,undefined8 param_4)
 
 {
   longlong lVar1;
   longlong *plVar2;
   code *pcVar3;
-  undefined1 *puVar4;
-  undefined1 uVar5;
-  char cVar6;
+  undefined1 uVar4;
+  char cVar5;
+  uint uVar6;
   longlong *plVar7;
-  undefined1 *puVar8;
-  undefined4 uVar9;
-  undefined1 auStack_168 [8];
-  undefined1 auStack_160 [24];
+  undefined8 uVar8;
+  undefined1 auStack_168 [32];
   undefined4 local_148;
   undefined1 *local_140;
   undefined4 local_138;
   undefined1 local_128 [208];
   undefined4 local_58;
   ulonglong local_48;
   
-  puVar8 = auStack_168;
   local_48 = __security_cookie ^ (ulonglong)auStack_168;
-  uVar9 = 0;
-  uVar5 = KeAcquireSpinLockRaiseToDpc(param_4);
+  uVar4 = KeAcquireSpinLockRaiseToDpc(param_4);
   plVar7 = (longlong *)InetWakeLookupPort(param_1,param_2,param_3,param_4);
   if (plVar7 == (longlong *)0x0) {
-    KeReleaseSpinLock(param_4,uVar5);
-    puVar8 = auStack_168;
-    uVar9 = 0xc0000225;
+    KeReleaseSpinLock(param_4,uVar4);
+    return 0xc0000225;
+  }
+  plVar2 = plVar7 + 2;
+  *(int *)plVar2 = (int)*plVar2 + -1;
+  if ((int)*plVar2 == 0) {
+    if ((Feature_3131548987__private_featureState & 0x10) == 0) {
+      uVar6 = Feature_3131548987__private_IsEnabledDeviceUsageNoInline();
+    }
+    else {
+      uVar6 = Feature_3131548987__private_featureState & 1;
+    }
+    if (uVar6 == 0) {
+      lVar1 = *plVar7;
+      if ((*(longlong **)(lVar1 + 8) != plVar7) ||
+         (plVar2 = (longlong *)plVar7[1], (longlong *)*plVar2 != plVar7)) {
+        pcVar3 = (code *)swi(0x29);
+        (*pcVar3)(3);
+        pcVar3 = (code *)swi(3);
+        uVar8 = (*pcVar3)();
+        return uVar8;
+      }
+      *plVar2 = lVar1;
+      *(longlong **)(lVar1 + 8) = plVar2;
+    }
+    else {
+      InetWakeRemovePortEntryIfPresent(plVar7);
+      if (*(int *)((longlong)plVar7 + 0x14) != 0) goto LAB_0;
+    }
+    KeReleaseSpinLock(param_4,uVar4);
+    cVar5 = IsPortWithinRange(param_1);
+    if (cVar5 == '\0') {
+      memset(local_128,0,0xd8);
+      local_58 = (undefined4)plVar7[3];
+      local_140 = local_128;
+      local_138 = 0xd8;
+      local_148 = 0;
+      InetSetInterfacePropertyAf(param_2,param_3,0,0x13);
+    }
+    ExFreePoolWithTag(plVar7,0);
   }
   else {
-    plVar2 = plVar7 + 2;
-    *(int *)plVar2 = (int)*plVar2 + -1;
-    puVar4 = auStack_168;
-    if ((int)*plVar2 == 0) {
-      lVar1 = *plVar7;
-      if ((*(longlong **)(lVar1 + 8) == plVar7) &&
-         (plVar2 = (longlong *)plVar7[1], (longlong *)*plVar2 == plVar7)) {
-        *plVar2 = lVar1;
-        *(longlong **)(lVar1 + 8) = plVar2;
-        KeReleaseSpinLock(param_4,CONCAT71((int7)((ulonglong)lVar1 >> 8),uVar5));
-        cVar6 = IsPortWithinRange(param_1);
-        if (cVar6 == '\0') {
-          memset(local_128,0,0xd8);
-          local_58 = *(undefined4 *)((longlong)plVar7 + 0x14);
-          local_140 = local_128;
-          local_138 = 0xd8;
-          local_148 = 0;
-          InetSetInterfacePropertyAf(param_2,param_3,0,0x13);
-        }
-        ExFreePoolWithTag(plVar7,0);
-        uVar9 = 0;
-        goto LAB_0;
-      }
-      pcVar3 = (code *)swi(0x29);
-      (*pcVar3)(3);
-      puVar4 = auStack_160;
-    }
-    puVar8 = puVar4;
-    *(undefined8 *)(puVar8 + -8) = 0x1400ce257;
-    KeReleaseSpinLock(param_4,uVar5);
+LAB_0:
+    KeReleaseSpinLock(param_4,uVar4);
   }
-LAB_0:
-  *(undefined8 *)(puVar8 + -8) = 0x1400ce26e;
-  return uVar9;
+  return 0;
 }
 

```


## IpGetAllSortedAddressParameters

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.37|
|i_ratio|0.47|
|m_ratio|0.92|
|b_ratio|0.64|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|IpGetAllSortedAddressParameters|IpGetAllSortedAddressParameters|
|fullname|IpGetAllSortedAddressParameters|IpGetAllSortedAddressParameters|
|refcount|2|2|
|`length`|247|283|
|`called`|IppCreateSortedAddressPairsEx<br>IppDereferenceCompartment<br>IppFindCompartmentById<br>IppIsCompartmentAccessibleByThread<br>memset|Feature_4272399675__private_IsEnabledDeviceUsageNoInline<br>IppCreateSortedAddressPairsEx<br>IppDereferenceCompartment<br>IppFindCompartmentById<br>IppIsCompartmentAccessibleByThread<br>memset|
|calling|||
|paramcount|0|0|
|`address`|1400b4210|140148810|
|sig|undefined IpGetAllSortedAddressParameters(void)|undefined IpGetAllSortedAddressParameters(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### IpGetAllSortedAddressParameters Called Diff


```diff
--- IpGetAllSortedAddressParameters called
+++ IpGetAllSortedAddressParameters called
@@ -0,0 +1 @@
+Feature_4272399675__private_IsEnabledDeviceUsageNoInline
```


### IpGetAllSortedAddressParameters Diff


```diff
--- IpGetAllSortedAddressParameters
+++ IpGetAllSortedAddressParameters
@@ -1,36 +1,45 @@
 
 undefined4 IpGetAllSortedAddressParameters(longlong param_1)
 
 {
   int *piVar1;
   void *_Dst;
   char cVar2;
-  undefined4 uVar3;
-  longlong lVar4;
+  uint uVar3;
+  undefined4 uVar4;
+  longlong lVar5;
   
   piVar1 = *(int **)(param_1 + 0x10);
   _Dst = *(void **)(param_1 + 0x38);
-  if (Ipv6Global == '\0') {
-    return 0xc00000bb;
+  if ((Feature_4272399675__private_featureState & 0x10) == 0) {
+    uVar3 = Feature_4272399675__private_IsEnabledDeviceUsageNoInline();
   }
-  if ((*(int *)(param_1 + 0x20) == 0) && (_Dst != (void *)0x0)) {
-    lVar4 = IppFindCompartmentById(&Ipv6Global);
-    if (lVar4 != 0) {
-      if ((*piVar1 == 0) || (cVar2 = IppIsCompartmentAccessibleByThread(lVar4,0,1), cVar2 != '\0'))
-      {
-        memset(_Dst,0,0x4658);
-        uVar3 = IppCreateSortedAddressPairsEx
-                          (lVar4,piVar1[0xdae],_Dst,(longlong)_Dst + 14000,piVar1 + 1,piVar1[0xdad],
-                           (longlong)_Dst + 0x36b4,(longlong)_Dst + 0x4654);
+  else {
+    uVar3 = Feature_4272399675__private_featureState & 1;
+  }
+  if ((uVar3 == 0) || ((uint)piVar1[0xdad] < 0x1f5)) {
+    if (Ipv6Global == '\0') {
+      return 0xc00000bb;
+    }
+    if ((*(int *)(param_1 + 0x20) == 0) && (_Dst != (void *)0x0)) {
+      lVar5 = IppFindCompartmentById(&Ipv6Global);
+      if (lVar5 != 0) {
+        if ((*piVar1 == 0) || (cVar2 = IppIsCompartmentAccessibleByThread(lVar5,0,1), cVar2 != '\0')
+           ) {
+          memset(_Dst,0,0x4658);
+          uVar4 = IppCreateSortedAddressPairsEx
+                            (lVar5,piVar1[0xdae],_Dst,(longlong)_Dst + 14000,piVar1 + 1,
+                             piVar1[0xdad],(longlong)_Dst + 0x36b4,(longlong)_Dst + 0x4654);
+        }
+        else {
+          uVar4 = 0xc0000225;
+        }
+        IppDereferenceCompartment(lVar5);
+        return uVar4;
       }
-      else {
-        uVar3 = 0xc0000225;
-      }
-      IppDereferenceCompartment(lVar4);
-      return uVar3;
+      return 0xc0000225;
     }
-    return 0xc0000225;
   }
   return 0xc000000d;
 }
 

```


## FUN_1401cd7da

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,called|
|ratio|0.74|
|i_ratio|0.43|
|m_ratio|0.96|
|b_ratio|0.7|
|match_types|BSIM|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|`name`|FUN_1401cd7da|FUN_1401cb93a|
|`fullname`|FUN_1401cd7da|FUN_1401cb93a|
|refcount|4|4|
|`length`|46|50|
|`called`|IppRemoveSitePrefixEntry|IppDeleteReassembly|
|calling|IppResetAllMulticastGroups|IppResetAllMulticastGroups|
|paramcount|0|0|
|`address`|1401cd7da|1401cb93a|
|`sig`|undefined FUN_1401cd7da(void)|undefined FUN_1401cb93a(void)|
|sym_type|Function|Function|
|sym_source|DEFAULT|DEFAULT|
|external|False|False|

### FUN_1401cd7da Called Diff


```diff
--- FUN_1401cd7da called
+++ FUN_1401cb93a called
@@ -1 +1 @@
-IppRemoveSitePrefixEntry
+IppDeleteReassembly
```


### FUN_1401cd7da Diff


```diff
--- FUN_1401cd7da
+++ FUN_1401cb93a
@@ -1,66 +1,75 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* PDB: Separated code (from the compiler): 1401cd7da - 1401cd7f1 for parent address: 140097fe8 */
+/* PDB: Separated code (from the compiler): 1401cb93a - 1401cb951 for parent address: 140075260 */
 
-void FUN_1401cd7da(void)
+void FUN_1401cb93a(void)
 
 {
   undefined8 *puVar1;
   code *pcVar2;
   longlong lVar3;
   longlong *plVar4;
   longlong *unaff_RBX;
   longlong unaff_RBP;
   longlong *unaff_RSI;
   longlong unaff_RDI;
-  longlong unaff_R15;
+  longlong unaff_R14;
+  undefined1 unaff_R15B;
   
   do {
     plVar4 = unaff_RBX;
     if (plVar4 == unaff_RSI) {
       do {
         *(undefined4 *)(unaff_RDI + 0x7c) = 0;
         *(undefined4 *)(unaff_RDI + 0x80) = 0;
         *(undefined4 *)(unaff_RDI + 0x84) = 0;
         CarAcquireCacheAwareReference(*(undefined8 *)(unaff_RDI + 0x20),1);
         IppCancelMulticastTimer(*(undefined8 *)(unaff_RBP + 0x2d0),unaff_RDI + 0x88,unaff_RDI);
         IppCancelMulticastTimer(*(undefined8 *)(unaff_RBP + 0x2d8),unaff_RDI + 0xa0,unaff_RDI);
         IppCancelMulticastTimer(*(undefined8 *)(unaff_RBP + 0x2e0),unaff_RDI + 0xb8,unaff_RDI);
         IppDereferenceLocalMulticastAddressUnderLock(unaff_RDI);
         lVar3 = IppEnumerateAdaptiveTableEntry();
         if (lVar3 == 0) {
           return;
         }
         unaff_RDI = lVar3 + -0x48;
         unaff_RSI = (longlong *)(lVar3 + 0x20);
         plVar4 = (longlong *)*unaff_RSI;
       } while (plVar4 == unaff_RSI);
     }
     *(undefined4 *)(plVar4 + 3) = 0;
     unaff_RBX = (longlong *)*plVar4;
     *(undefined1 *)((longlong)plVar4 + 0x1c) = 0;
   } while (((int)plVar4[2] != 0) || (*(int *)((longlong)plVar4 + 0x14) != 0));
   if (((longlong *)unaff_RBX[1] == plVar4) &&
      (puVar1 = (undefined8 *)plVar4[1], (longlong *)*puVar1 == plVar4)) {
     *puVar1 = unaff_RBX;
     unaff_RBX[1] = (longlong)puVar1;
     ExFreePoolWithTag(plVar4,0);
-    FUN_1401cd7da();
+    FUN_1401cb93a();
     return;
   }
   pcVar2 = (code *)swi(0x29);
   (*pcVar2)(3);
   do {
-    IppRemoveSitePrefixEntry();
-    do {
-      plVar4 = unaff_RBX;
-      if (plVar4 == unaff_RSI) {
-        KeReleaseSpinLock();
-        return;
-      }
-      unaff_RBX = (longlong *)*plVar4;
-    } while ((plVar4[2] != unaff_R15) ||
-            (((int)unaff_RDI != 2 && ((int)plVar4[7] != (int)unaff_RDI))));
+    KeReleaseSpinLockFromDpcLevel();
+    IppDeleteReassembly(unaff_RBX);
+    while( true ) {
+      do {
+        unaff_RBX = (longlong *)RtlEnumerateEntryHashTable();
+        if (unaff_RBX == (longlong *)0x0) {
+          RtlEndEnumerationHashTable();
+          KeReleaseSpinLock(unaff_RSI,unaff_R15B);
+          return;
+        }
+      } while (unaff_RBX[7] != unaff_R14);
+      IppRemoveReassembly(unaff_RSI,unaff_RBX);
+      KeAcquireSpinLockAtDpcLevel(unaff_RBX + 6);
+      if (*(int *)((longlong)unaff_RBX + 0x44) != 1) break;
+      unaff_RBX[7] = 0;
+      *(undefined4 *)((longlong)unaff_RBX + 0x44) = 2;
+      KeReleaseSpinLockFromDpcLevel(unaff_RBX + 6);
+    }
   } while( true );
 }
 

```


## FUN_1401cceb6

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|code,name,fullname,refcount,length,sig,address,calling|
|ratio|0.14|
|i_ratio|0.0|
|m_ratio|0.72|
|b_ratio|0.32|
|match_types|SigCallingCalledHasher|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|`name`|FUN_1401cceb6|InetWakeRemovePortEntryIfPresent|
|`fullname`|FUN_1401cceb6|InetWakeRemovePortEntryIfPresent|
|`refcount`|4|3|
|`length`|40|46|
|called|||
|`calling`|Ipv6pHandleNeighborSolicitation|InetWakeAcquirePortAf<br>InetWakeReleasePortAf|
|paramcount|0|0|
|`address`|1401cceb6|1401c1098|
|`sig`|undefined FUN_1401cceb6(void)|undefined InetWakeRemovePortEntryIfPresent(void)|
|sym_type|Function|Function|
|sym_source|DEFAULT|IMPORTED|
|external|False|False|

### FUN_1401cceb6 Calling Diff


```diff
--- FUN_1401cceb6 calling
+++ InetWakeRemovePortEntryIfPresent calling
@@ -1 +1,2 @@
-Ipv6pHandleNeighborSolicitation
+InetWakeAcquirePortAf
+InetWakeReleasePortAf
```


### FUN_1401cceb6 Diff


```diff
--- FUN_1401cceb6
+++ InetWakeRemovePortEntryIfPresent
@@ -1,97 +1,26 @@
 
-/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-/* WARNING: Removing unreachable block (ram,0x0001401ccf4c) */
-/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
-/* PDB: Separated code (from the compiler): 1401cceb6 - 1401ccf86 for parent address: 14008fed8 */
-
-void FUN_1401cceb6(longlong param_1,longlong param_2)
+void InetWakeRemovePortEntryIfPresent(longlong *param_1)
 
 {
   longlong *plVar1;
-  code *pcVar2;
-  undefined1 auVar3 [16];
-  undefined4 uVar4;
-  undefined4 uVar5;
-  int iVar6;
-  longlong lVar7;
-  longlong lVar8;
-  longlong lVar9;
-  undefined4 uVar10;
-  longlong unaff_RBX;
-  longlong unaff_RSI;
-  undefined4 *unaff_R15;
-  undefined4 extraout_XMM0_Da;
-  undefined4 extraout_XMM0_Da_00;
-  undefined4 *puVar11;
-  undefined4 in_stack_00000040;
-  longlong in_stack_00000050;
-  longlong in_stack_00000058;
+  longlong *plVar2;
+  code *pcVar3;
   
-  if (param_1 == 0) {
-    if (param_2 == 0) {
-      puVar11 = &stack0x00000040;
-      lVar7 = IppHandleNeighborSolicitation();
-      if (lVar7 != 0) {
-        uVar10 = extraout_XMM0_Da;
-        if ((*(int *)(lVar7 + 0x18) == 1) ||
-           (lVar8 = ExAllocatePool2(0x40,0x48,0x61613649), uVar10 = extraout_XMM0_Da_00, lVar8 == 0)
-           ) {
-          Ipv6pSendNeighborAdvertisement(uVar10,0);
-        }
-        else {
-          *(longlong *)(lVar8 + 0x28) = unaff_RBX;
-          LOCK();
-          plVar1 = (longlong *)(unaff_RBX + 0x40);
-          lVar9 = *plVar1;
-          *plVar1 = *plVar1 + 1;
-          UNLOCK();
-          if (lVar9 + 1 < 2) {
-            pcVar2 = (code *)swi(0x29);
-            (*pcVar2)(0xe);
-            FUN_1401ccede();
-            return;
-          }
-          *(longlong *)(lVar8 + 0x30) = lVar7;
-          CarAcquireCacheAwareReference(*(undefined8 *)(lVar7 + 0x20),1);
-          uVar10 = unaff_R15[1];
-          uVar4 = unaff_R15[2];
-          uVar5 = unaff_R15[3];
-          *(undefined4 *)(lVar8 + 0x38) = *unaff_R15;
-          *(undefined4 *)(lVar8 + 0x3c) = uVar10;
-          *(undefined4 *)(lVar8 + 0x40) = uVar4;
-          *(undefined4 *)(lVar8 + 0x44) = uVar5;
-          TtInitializeTimer(lVar8);
-          auVar3._8_8_ = 0;
-          auVar3._0_8_ = _DAT_0 / 10000;
-          lVar9 = SUB168(ZEXT816(0x624dd2f1a9fbe77) * auVar3,8);
-          IppRandomValue = IppRandomValue * 0x19660d + 0x3c6ef35f;
-          LOCK();
-          UNLOCK();
-          uVar10 = (undefined4)((_DAT_0 / 10000 - lVar9 >> 1) + lVar9 >> 8);
-          iVar6 = TtStartTimerEx(*(undefined8 *)(in_stack_00000050 + 0x2c8),lVar8,uVar10,1,puVar11);
-          if (iVar6 != 0) {
-            IppTimerUpdateNextExpirationTick(uVar10,iVar6);
-          }
-        }
-        IppDereferenceLocalAddress(lVar7);
-        *(undefined4 *)(*(longlong *)(unaff_RSI + 8) + 0x8c) = 0;
-        return;
-      }
-      iVar6 = IppPktMonToIcmpDropReason(in_stack_00000040);
-      if (iVar6 == 0x2c) {
-        return;
-      }
+  plVar1 = (longlong *)*param_1;
+  if (plVar1 != param_1) {
+    if (((longlong *)plVar1[1] != param_1) ||
+       (plVar2 = (longlong *)param_1[1], (longlong *)*plVar2 != param_1)) {
+      pcVar3 = (code *)swi(0x29);
+      (*pcVar3)(3);
+      pcVar3 = (code *)swi(3);
+      (*pcVar3)();
+      return;
     }
-    else {
-      iVar6 = 0x15;
-    }
+    *plVar2 = (longlong)plVar1;
+    plVar1[1] = (longlong)plVar2;
+    param_1[1] = (longlong)param_1;
+    *param_1 = (longlong)param_1;
   }
-  else {
-    iVar6 = 0x20;
-  }
-  *(undefined4 *)(*(longlong *)(unaff_RSI + 8) + 0x8c) = 0xc000021b;
-  LogIcmpReceiveDrop(&Ipv6Global,0x87,*(undefined1 *)(in_stack_00000058 + 1),iVar6,
-                     *(undefined4 *)(*(longlong *)(unaff_RSI + 8) + 0x8c));
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## FlpInterfaceAcquireWriteLock

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.86|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|FlpInterfaceAcquireWriteLock|FlpInterfaceAcquireWriteLock|
|fullname|FlpInterfaceAcquireWriteLock|FlpInterfaceAcquireWriteLock|
|`refcount`|34|33|
|length|28|28|
|called|NDIS.SYS::NdisAcquireRWLockWrite|NDIS.SYS::NdisAcquireRWLockWrite|
|`calling`|<details><summary>Expand for full list:<br>Fl8AddGroup<br>Fl8DeleteGroup<br>Fl8pPCFControlInterface<br>Fl8pPCFSerializedControlUnderLock<br>FlRdmaBindAdapter<br>FlRdmaPnpEvent<br>FlRdmapNSINotificationWorkerRoutine<br>FlSetAllInterfaceParameters<br>FlSetAllInterfaceRemoteAddressParameters<br>FlStatus<br>FlpAddSubInterfaceComplete</summary>FlpAddWolPatternEntryToInterface<br>FlpCleanupWolPatternEntries<br>FlpDeleteInterface<br>FlpFlushQueuedPmRemoveOids<br>FlpFlushQueuedPmRemoveOidsUnderLock<br>FlpGetFirstClientInterface<br>FlpGetNextClientInterface<br>FlpOpenAdapterComplete<br>FlpQueueWolPatternEntryDelete<br>FlpResetWolPatternEntries<br>FlpSerializedNdisRequest<br>FlpSetArpNDOffload<br>FlpTryToEnqueuePmRemoveOid<br>TlRdmaProviderCloseNDKAdapter<br>TlRdmaProviderOpenNDKAdapter</details>|<details><summary>Expand for full list:<br>Fl8DeleteGroup<br>Fl8pPCFControlInterface<br>Fl8pPCFSerializedControlUnderLock<br>FlRdmaBindAdapter<br>FlRdmaPnpEvent<br>FlRdmapNSINotificationWorkerRoutine<br>FlSetAllInterfaceParameters<br>FlSetAllInterfaceRemoteAddressParameters<br>FlStatus<br>FlpAddSubInterfaceComplete<br>FlpAddWolPatternEntryToInterface</summary>FlpCleanupWolPatternEntries<br>FlpDeleteInterface<br>FlpFlushQueuedPmRemoveOids<br>FlpFlushQueuedPmRemoveOidsUnderLock<br>FlpGetFirstClientInterface<br>FlpGetNextClientInterface<br>FlpOpenAdapterComplete<br>FlpQueueWolPatternEntryDelete<br>FlpResetWolPatternEntries<br>FlpSerializedNdisRequest<br>FlpSetArpNDOffload<br>FlpTryToEnqueuePmRemoveOid<br>TlRdmaProviderCloseNDKAdapter<br>TlRdmaProviderOpenNDKAdapter</details>|
|paramcount|0|0|
|`address`|1400206c8|1400dc72c|
|sig|undefined FlpInterfaceAcquireWriteLock(void)|undefined FlpInterfaceAcquireWriteLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### FlpInterfaceAcquireWriteLock Calling Diff


```diff
--- FlpInterfaceAcquireWriteLock calling
+++ FlpInterfaceAcquireWriteLock calling
@@ -1 +0,0 @@
-Fl8AddGroup
```


## NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|KeReleaseInStackQueuedSpinLockFromDpcLevel|KeReleaseInStackQueuedSpinLockFromDpcLevel|
|fullname|NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel|NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel|
|`refcount`|304|305|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CreateExclusion<br>EQoSGetAppName<br>EQoSGetQoSProfileFlowHandle<br>EQoSUpdateQoSProfile<br>FUN_1401c3ddf<br>FUN_1401ca926<br>FUN_1401d0f74<br>Icmpv4HandleRouterAdvertisement<br>InetFindAndReferenceAf<br>InetLookupPortEndpoint<br>IpFlcUpdateSubInterface</summary>IpNlpConfirmForwardReachability<br>IpNlpReferenceCompartment<br>IppAddAutoConfiguredRoutesForAddress<br>IppAddRemoveInterfaceProcessorContext<br>IppAddRemoveSubinterfacesProcessorContext<br>IppAddressSetGetNextExpirationTick<br>IppAddressSetTimeout<br>IppCommitSetAllLocalAddressParameters<br>IppCommitSetAllSubInterfaceParameters<br>IppCompartmentSetGetNextExpirationTick<br>IppCreateForwardPath<br>IppCreateSubInterface<br>IppDadAnnouncementGetNextExpirationTick<br>IppDadAnnouncementTimeout<br>IppDeleteAutoConfiguredRoutesForAddress<br>IppDeleteNeighbor<br>IppDeleteNeighborsUnderNSLock<br>IppDeleteSubInterface<br>IppEphemeralLoopbackAddressSetTimeout<br>IppEvaluateSortInformation<br>IppFillInterfaceData<br>IppFillUnicastRouteData<br>IppFindAddressInAddressSet<br>IppFindAddressInScopeEx<br>IppFindAddressOnInterfaceEx<br>IppFindAnySubInterfaceOnInterface<br>IppFindBestSourceAddressOnHost<br>IppFindBestSourceAddressOnInterfaceUnderLock<br>IppFindCompartmentById<br>IppFindInterfaceByIndex<br>IppFindInterfaceByLuid<br>IppFindInterfaceForThread<br>IppFindNeighborUnderNSLock<br>IppFindNextHopAtDpc<br>IppFindNextHopInForwardPathSet<br>IppFindOrCreateNeighborAtDpc<br>IppFindOrCreatePath<br>IppFindPath<br>IppForwardMulticastPackets<br>IppGarbageCollectLoopbackAddressSet<br>IppGetAllBestRouteParameters<br>IppGetCompartment<br>IppGetNeighborReachability<br>IppGetNextCompartment<br>IppGetNextHopFromPath<br>IppGetNextInterfaceForThread<br>IppGetNextRoute<br>IppGetRouteFromPath<br>IppGetRouteKey<br>IppGetThreadCompartmentInfo<br>IppHandleNeighborAdvertisement<br>IppHandleNeighborSolicitation<br>IppInsertNeighbor<br>IppInspectFindInterfaceByIndex<br>IppInspectInjectReceive<br>IppInspectInjectReceiveEx<br>IppIsCompartmentAccessibleByThread<br>IppJoinPath<br>IppLinkLocalAddressConfigurationTimeout<br>IppLookupPrefixPolicy<br>IppMfeSetTimeOut<br>IppMorphNeighborAtDpc<br>IppMulticastDiscoveryGetNextExpirationTick<br>IppNeighborSetTimeout<br>IppNeighborSolicitationWorker<br>IppPathSetTimeout<br>IppProbeNeighborReachability<br>IppPruneNeighborSet<br>IppResetNeighborsAtDpc<br>IppResetNeighborsUnderNSLock<br>IppRouteSetTimeout<br>IppSetAllNeighborParametersHelper<br>IppSetDhcpOperationalStatus<br>IppSetInterfaceMtuAtDpc<br>IppUpdateBestSourceAddress<br>IppUpdateCompartment<br>IppUpdateUnicastRoute<br>Ipv4SetAllRouteParameters<br>Ipv4pRouterDiscoveryTimeout<br>Ipv6SetAllRouteParameters<br>Ipv6pHandleAnycastAdvertisementTimeout<br>Ipv6pHandleRouterAdvertisement<br>Ipv6pHandleRouterSolicitation<br>Ipv6pInterfaceSetGetNextExpirationTick<br>Ipv6pRouterDiscoveryTimeout<br>Ipv6pRouterDnsGetNextExpirationTick<br>Ipv6pRouterDnsTimeout<br>Ipv6pRouterPref64GetNextExpirationTick<br>Ipv6pRouterPref64Timeout<br>QimInspectCreateEndpoint<br>QimMatchPolicyForTCPConnection<br>RawActivateEndpointBindRequestComplete<br>RawBindEndpointInspectComplete<br>RawBindEndpointRequestInspectComplete<br>RawCloseEndpoint<br>RawReceiveDatagrams<br>RtlAcquireReadLock<br>RtlAcquireReadLockAtDpcLevel<br>RtlAcquireScalableReadLock<br>RtlAcquireScalableReadLockAtDpcLevel<br>TcpCloseSynTcb<br>TcpConnectionRundown<br>TcpCreateAndAcceptTcb<br>TcpCreateAndAcceptTcbComplete<br>TcpCreateTimeWaitTcb<br>TcpDelayOrScheduleAck<br>TcpDequeueTcbSend<br>TcpEnumerateConnections<br>TcpEnumerateListeners<br>TcpGetAndReadLockPartitionAtDpcLevel<br>TcpGetAndWriteLockPartitionAtDpcLevel<br>TcpInsertStandbySynTcb<br>TcpInsertSynTcb<br>TcpInsertTcb<br>TcpInspectReceive<br>TcpListenerReceive<br>TcpMatchControlReceive<br>TcpMatchReceive<br>TcpMppIsCandidate<br>TcpPartitionGetNextExpirationTick<br>TcpPartitionStartOrContinueMppEvaluation<br>TcpPartitionStopMppEvaluation<br>TcpPortPoolReferenceFunction<br>TcpPortPropertyGetAllParameters<br>TcpProcessExpiredSynTcbTimers<br>TcpProcessExpiredTcbTimers<br>TcpProcessExpiredTimeWaitTcbTimers<br>TcpProcessFastDatagramBatch<br>TcpRemoveTcb<br>TcpReplaceTimeWaitTcbWithSynTcb<br>TcpReplaceTimeWaitTcbWithTcb<br>TcpResizeHashTablesForProcessor<br>TcpSelectWildcardPort<br>TcpShutdownSynTcb<br>TcpShutdownTcb<br>TcpShutdownTimeWaitTcb<br>TcpStartTimerSynTcb<br>TcpStartTimerTcbInternal<br>TcpStartTimerTimeWaitTcb<br>TcpTcbAcceptDatagram<br>TcpTcbCarefulDatagram<br>TcpTcbFastDatagram<br>TcpTcbReceive<br>TcpTcbSend<br>TcpUpdateIsnGenerator<br>TlShimCacheMatchedFilterList<br>TlShimLookupLayerCache<br>UdpCountEndpoints<br>UdpEnumerateEndpoints<br>UdpPortPoolReferenceFunction<br>UdpReceiveDatagrams<br>UdpSendMessages<br>WfpAleAcquireEndpoint<br>WfpAleAcquireEndpointContextFromHandle<br>WfpAleFindTupleStateEntry<br>WfpGetProfileIdFromInterface<br>WfpGetProfileIdFromPacketInbound<br>WfpInspectReceiveControlShimV4</details>|<details><summary>Expand for full list:<br>CreateExclusion<br>EQoSGetAppName<br>EQoSGetQoSProfileFlowHandle<br>EQoSUpdateQoSProfile<br>FUN_1401c429f<br>FUN_1401ce798<br>FUN_1401d0db4<br>Icmpv4HandleRouterAdvertisement<br>InetFindAndReferenceAf<br>InetLookupPortEndpoint<br>IpFlcUpdateSubInterface</summary>IpNlpConfirmForwardReachability<br>IpNlpReferenceCompartment<br>IppAddAutoConfiguredRoutesForAddress<br>IppAddRemoveInterfaceProcessorContext<br>IppAddRemoveSubinterfacesProcessorContext<br>IppAddressSetGetNextExpirationTick<br>IppAddressSetTimeout<br>IppCommitSetAllLocalAddressParameters<br>IppCommitSetAllSubInterfaceParameters<br>IppCompartmentSetGetNextExpirationTick<br>IppCreateForwardPath<br>IppCreateSubInterface<br>IppDadAnnouncementGetNextExpirationTick<br>IppDadAnnouncementTimeout<br>IppDeleteAutoConfiguredRoutesForAddress<br>IppDeleteNeighbor<br>IppDeleteNeighborsUnderNSLock<br>IppDeleteSubInterface<br>IppEphemeralLoopbackAddressSetTimeout<br>IppEvaluateSortInformation<br>IppFillInterfaceData<br>IppFillUnicastRouteData<br>IppFindAddressInAddressSet<br>IppFindAddressInScopeEx<br>IppFindAddressOnInterfaceEx<br>IppFindAnySubInterfaceOnInterface<br>IppFindBestSourceAddressOnHost<br>IppFindBestSourceAddressOnInterfaceUnderLock<br>IppFindCompartmentById<br>IppFindInterfaceByIndex<br>IppFindInterfaceByLuid<br>IppFindInterfaceForThread<br>IppFindNeighborUnderNSLock<br>IppFindNextHopAtDpc<br>IppFindNextHopInForwardPathSet<br>IppFindOrCreateNeighborAtDpc<br>IppFindOrCreatePath<br>IppFindPath<br>IppForwardMulticastPackets<br>IppGarbageCollectLoopbackAddressSet<br>IppGetAllBestRouteParameters<br>IppGetCompartment<br>IppGetNeighborReachability<br>IppGetNextCompartment<br>IppGetNextHopFromPath<br>IppGetNextInterfaceForThread<br>IppGetNextRoute<br>IppGetRouteFromPath<br>IppGetRouteKey<br>IppGetThreadCompartmentInfo<br>IppHandleNeighborAdvertisement<br>IppHandleNeighborSolicitation<br>IppInsertNeighbor<br>IppInspectFindInterfaceByIndex<br>IppInspectInjectReceive<br>IppInspectInjectReceiveEx<br>IppIsCompartmentAccessibleByThread<br>IppJoinPath<br>IppLinkLocalAddressConfigurationTimeout<br>IppLookupPrefixPolicy<br>IppMfeSetTimeOut<br>IppMorphNeighborAtDpc<br>IppMulticastDiscoveryGetNextExpirationTick<br>IppNeighborSetTimeout<br>IppNeighborSolicitationWorker<br>IppPathSetTimeout<br>IppProbeNeighborReachability<br>IppPruneNeighborSet<br>IppResetNeighborsAtDpc<br>IppResetNeighborsUnderNSLock<br>IppRouteSetTimeout<br>IppSetAllNeighborParametersHelper<br>IppSetDhcpOperationalStatus<br>IppSetInterfaceMtuAtDpc<br>IppUpdateBestSourceAddress<br>IppUpdateCompartment<br>IppUpdateUnicastRoute<br>Ipv4SetAllRouteParameters<br>Ipv4pRouterDiscoveryTimeout<br>Ipv6SetAllRouteParameters<br>Ipv6pHandleAnycastAdvertisementTimeout<br>Ipv6pHandleNeighborSolicitation<br>Ipv6pHandleRouterAdvertisement<br>Ipv6pHandleRouterSolicitation<br>Ipv6pInterfaceSetGetNextExpirationTick<br>Ipv6pRouterDiscoveryTimeout<br>Ipv6pRouterDnsGetNextExpirationTick<br>Ipv6pRouterDnsTimeout<br>Ipv6pRouterPref64GetNextExpirationTick<br>Ipv6pRouterPref64Timeout<br>QimInspectCreateEndpoint<br>QimMatchPolicyForTCPConnection<br>RawActivateEndpointBindRequestComplete<br>RawBindEndpointRequestInspectComplete<br>RawCloseEndpoint<br>RawReceiveDatagrams<br>RtlAcquireReadLock<br>RtlAcquireReadLockAtDpcLevel<br>RtlAcquireScalableReadLock<br>RtlAcquireScalableReadLockAtDpcLevel<br>TcpCloseSynTcb<br>TcpConnectionRundown<br>TcpCreateAndAcceptTcb<br>TcpCreateAndAcceptTcbComplete<br>TcpCreateTimeWaitTcb<br>TcpDelayOrScheduleAck<br>TcpDequeueTcbSend<br>TcpEnumerateConnections<br>TcpEnumerateListeners<br>TcpGetAndReadLockPartitionAtDpcLevel<br>TcpGetAndWriteLockPartitionAtDpcLevel<br>TcpInsertStandbySynTcb<br>TcpInsertSynTcb<br>TcpInsertTcb<br>TcpInspectReceive<br>TcpListenerReceive<br>TcpMatchControlReceive<br>TcpMatchReceive<br>TcpMppIsCandidate<br>TcpPartitionGetNextExpirationTick<br>TcpPartitionStartOrContinueMppEvaluation<br>TcpPartitionStopMppEvaluation<br>TcpPortPoolReferenceFunction<br>TcpPortPropertyGetAllParameters<br>TcpProcessExpiredSynTcbTimers<br>TcpProcessExpiredTcbTimers<br>TcpProcessExpiredTimeWaitTcbTimers<br>TcpProcessFastDatagramBatch<br>TcpRemoveTcb<br>TcpReplaceTimeWaitTcbWithSynTcb<br>TcpReplaceTimeWaitTcbWithTcb<br>TcpResizeHashTablesForProcessor<br>TcpSelectWildcardPort<br>TcpShutdownSynTcb<br>TcpShutdownTcb<br>TcpShutdownTimeWaitTcb<br>TcpStartTimerSynTcb<br>TcpStartTimerTcbInternal<br>TcpStartTimerTimeWaitTcb<br>TcpTcbAcceptDatagram<br>TcpTcbCarefulDatagram<br>TcpTcbFastDatagram<br>TcpTcbReceive<br>TcpTcbSend<br>TcpUpdateIsnGenerator<br>TlShimCacheMatchedFilterList<br>TlShimLookupLayerCache<br>UdpCountEndpoints<br>UdpEnumerateEndpoints<br>UdpPortPoolReferenceFunction<br>UdpReceiveDatagrams<br>UdpSendMessages<br>WfpAleAcquireEndpoint<br>WfpAleAcquireEndpointContextFromHandle<br>WfpAleFindTupleStateEntry<br>WfpGetProfileIdFromInterface<br>WfpGetProfileIdFromPacketInbound<br>WfpInspectReceiveControlShimV4</details>|
|paramcount|0|0|
|address|EXTERNAL:000000f3|EXTERNAL:000000f3|
|sig|undefined KeReleaseInStackQueuedSpinLockFromDpcLevel(void)|undefined KeReleaseInStackQueuedSpinLockFromDpcLevel(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel Calling Diff


```diff
--- NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel calling
+++ NTOSKRNL.EXE::KeReleaseInStackQueuedSpinLockFromDpcLevel calling
@@ -5,3 +5,3 @@
-FUN_1401c3ddf
-FUN_1401ca926
-FUN_1401d0f74
+FUN_1401c429f
+FUN_1401ce798
+FUN_1401d0db4
@@ -92,0 +93 @@
+Ipv6pHandleNeighborSolicitation
@@ -104 +104,0 @@
-RawBindEndpointInspectComplete
```


## IppReassemblyInterfaceCleanup

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.8|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|IppReassemblyInterfaceCleanup|IppReassemblyInterfaceCleanup|
|fullname|IppReassemblyInterfaceCleanup|IppReassemblyInterfaceCleanup|
|refcount|3|3|
|`length`|298|272|
|`called`|IppDeleteReassembly<br>IppRemoveReassembly<br>NTOSKRNL.EXE::KeAcquireSpinLockAtDpcLevel<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel<br>NTOSKRNL.EXE::RtlEndEnumerationHashTable<br>NTOSKRNL.EXE::RtlEnumerateEntryHashTable<br>NTOSKRNL.EXE::RtlInitEnumerationHashTable|IppRemoveReassembly<br>NTOSKRNL.EXE::KeAcquireSpinLockAtDpcLevel<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock<br>NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel<br>NTOSKRNL.EXE::RtlEndEnumerationHashTable<br>NTOSKRNL.EXE::RtlEnumerateEntryHashTable<br>NTOSKRNL.EXE::RtlInitEnumerationHashTable|
|calling|IpFlcDeleteInterface|IpFlcDeleteInterface|
|paramcount|0|0|
|`address`|140097ed0|1400759c0|
|sig|undefined IppReassemblyInterfaceCleanup(void)|undefined IppReassemblyInterfaceCleanup(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### IppReassemblyInterfaceCleanup Called Diff


```diff
--- IppReassemblyInterfaceCleanup called
+++ IppReassemblyInterfaceCleanup called
@@ -1 +0,0 @@
-IppDeleteReassembly
```


## __GSHandlerCheck

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|__GSHandlerCheck|__GSHandlerCheck|
|fullname|__GSHandlerCheck|__GSHandlerCheck|
|`refcount`|906|905|
|length|29|29|
|called|__GSHandlerCheckCommon|__GSHandlerCheckCommon|
|calling|||
|paramcount|0|0|
|`address`|1401c2a08|1401c2ed8|
|sig|undefined __GSHandlerCheck(void)|undefined __GSHandlerCheck(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## FlpInterfaceReleaseReadLock

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|FlpInterfaceReleaseReadLock|FlpInterfaceReleaseReadLock|
|fullname|FlpInterfaceReleaseReadLock|FlpInterfaceReleaseReadLock|
|`refcount`|59|56|
|length|25|25|
|called|NDIS.SYS::NdisReleaseRWLock|NDIS.SYS::NdisReleaseRWLock|
|`calling`|<details><summary>Expand for full list:<br>FUN_1401db88a<br>Fl8AddGroup<br>Fl8DeleteGroup<br>Fl8pPCFControlInterface<br>Fl8pPCFSerializedControlUnderLock<br>Fl8pPCFSetUDPFilter<br>Fl8pPCFUpdateUDPMulticastTriggeredFilters<br>FlGetAllInterfaceParameters<br>FlGetAllInterfaceRemoteAddressParameters<br>FlRdmaBindAdapter<br>FlRdmaNsiEnumerateInterfaces</summary>FlRdmaNsiGetAllInterfaceParameters<br>FlRdmaPnpEvent<br>FlRdmapNSINotificationWorkerRoutine<br>FlSetAllInterfaceParameters<br>FlSetAllInterfaceRemoteAddressParameters<br>FlStatus<br>FlpAddSubInterfaceComplete<br>FlpAddWolPatternEntryToInterface<br>FlpCleanupWolPatternEntries<br>FlpDeleteInterface<br>FlpFindClientInterfaceByIfIndex<br>FlpFindClientInterfaceByIsolationId<br>FlpFindDefaultClientInterface<br>FlpFlushQueuedPmRemoveOids<br>FlpFlushQueuedPmRemoveOidsUnderLock<br>FlpGetFirstClientInterface<br>FlpGetNextClientInterface<br>FlpOpenAdapterComplete<br>FlpPCFClearFilter<br>FlpQueueWolPatternEntryDelete<br>FlpReinitializePacketProviderInterface<br>FlpResetWolPatternEntries<br>FlpSerializedNdisRequest<br>FlpSerializedNdisSetPacketFilterWorker<br>FlpSetArpNDOffload<br>FlpSetDirectTcpPattern<br>FlpSetLocalPortWakePattern<br>FlpTryToEnqueuePmRemoveOid<br>TlRdmaProviderCloseNDKAdapter<br>TlRdmaProviderOpenNDKAdapter</details>|<details><summary>Expand for full list:<br>FUN_1401dbc46<br>Fl8DeleteGroup<br>Fl8pPCFControlInterface<br>Fl8pPCFSerializedControlUnderLock<br>Fl8pPCFSetUDPFilter<br>Fl8pPCFUpdateUDPMulticastTriggeredFilters<br>FlGetAllInterfaceParameters<br>FlGetAllInterfaceRemoteAddressParameters<br>FlRdmaBindAdapter<br>FlRdmaNsiEnumerateInterfaces<br>FlRdmaNsiGetAllInterfaceParameters</summary>FlRdmaPnpEvent<br>FlRdmapNSINotificationWorkerRoutine<br>FlSetAllInterfaceParameters<br>FlSetAllInterfaceRemoteAddressParameters<br>FlStatus<br>FlpAddSubInterfaceComplete<br>FlpAddWolPatternEntryToInterface<br>FlpCleanupWolPatternEntries<br>FlpDeleteInterface<br>FlpFindClientInterfaceByIfIndex<br>FlpFindClientInterfaceByIsolationId<br>FlpFindDefaultClientInterface<br>FlpFlushQueuedPmRemoveOids<br>FlpFlushQueuedPmRemoveOidsUnderLock<br>FlpGetFirstClientInterface<br>FlpGetNextClientInterface<br>FlpOpenAdapterComplete<br>FlpPCFClearFilter<br>FlpQueueWolPatternEntryDelete<br>FlpReinitializePacketProviderInterface<br>FlpResetWolPatternEntries<br>FlpSerializedNdisRequest<br>FlpSerializedNdisSetPacketFilterWorker<br>FlpSetArpNDOffload<br>FlpSetDirectTcpPattern<br>FlpSetLocalPortWakePattern<br>FlpTryToEnqueuePmRemoveOid<br>TlRdmaProviderCloseNDKAdapter<br>TlRdmaProviderOpenNDKAdapter</details>|
|paramcount|0|0|
|`address`|14001efb8|1400dc750|
|sig|undefined FlpInterfaceReleaseReadLock(void)|undefined FlpInterfaceReleaseReadLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### FlpInterfaceReleaseReadLock Calling Diff


```diff
--- FlpInterfaceReleaseReadLock calling
+++ FlpInterfaceReleaseReadLock calling
@@ -1,2 +1 @@
-FUN_1401db88a
-Fl8AddGroup
+FUN_1401dbc46
```


## NDIS.SYS::NdisAcquireRWLockWrite

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|NdisAcquireRWLockWrite|NdisAcquireRWLockWrite|
|fullname|NDIS.SYS::NdisAcquireRWLockWrite|NDIS.SYS::NdisAcquireRWLockWrite|
|`refcount`|51|52|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>FlPnpEvent<br>FlRdmaUnbindAdapter<br>FlUnbindAdapter<br>FlpAddInterfaceComplete<br>FlpInterfaceAcquireWriteLock<br>FlpSerializedNdisRequestWorkerRoutine<br>FlpSetVirtualInterfaceHelper<br>KfdDispatchDevCtl<br>WfpAcquireFastWriteLock<br>WfpAleGetAndWriteLockPartition<br>WfpAleInsertProcessInformation</summary>WfpAleInsertTokenInformation<br>WfpAlepEndpointCleanupWorkQueueRoutine<br>WfpAlepFreeRemoteEndpointsForEndpointContext<br>WfpAlepRemoveProcessInformation<br>WfpCreateProcessNotifyRoutine<br>WfpInsertModifiedIdCorrelationEntry<br>WfpRemoveModifiedIdCorrelationEntry</details>|<details><summary>Expand for full list:<br>Fl8AddGroup<br>FlPnpEvent<br>FlRdmaUnbindAdapter<br>FlUnbindAdapter<br>FlpAddInterfaceComplete<br>FlpInterfaceAcquireWriteLock<br>FlpSerializedNdisRequestWorkerRoutine<br>FlpSetVirtualInterfaceHelper<br>KfdDispatchDevCtl<br>WfpAcquireFastWriteLock<br>WfpAleGetAndWriteLockPartition</summary>WfpAleInsertProcessInformation<br>WfpAleInsertTokenInformation<br>WfpAlepEndpointCleanupWorkQueueRoutine<br>WfpAlepFreeRemoteEndpointsForEndpointContext<br>WfpAlepRemoveProcessInformation<br>WfpCreateProcessNotifyRoutine<br>WfpInsertModifiedIdCorrelationEntry<br>WfpRemoveModifiedIdCorrelationEntry</details>|
|paramcount|0|0|
|address|EXTERNAL:000002cc|EXTERNAL:000002cc|
|sig|undefined NdisAcquireRWLockWrite(void)|undefined NdisAcquireRWLockWrite(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NDIS.SYS::NdisAcquireRWLockWrite Calling Diff


```diff
--- NDIS.SYS::NdisAcquireRWLockWrite calling
+++ NDIS.SYS::NdisAcquireRWLockWrite calling
@@ -0,0 +1 @@
+Fl8AddGroup
```


## WfpSizeTMultiply

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.72|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|WfpSizeTMultiply|WfpSizeTMultiply|
|fullname|WfpSizeTMultiply|WfpSizeTMultiply|
|`refcount`|6|7|
|length|84|84|
|called|WfpReportError<br>WfpReportSysErrorAsNtStatus|WfpReportError<br>WfpReportSysErrorAsNtStatus|
|`calling`|WfpAleCopyPeerTokenInfoToTupleIPsecState<br>WfpAleSetOrClearPeerTokenInformation<br>WfpAlepCopyCredentialData|AleRedirectRecordsDeserializeFromBuffer<br>WfpAleCopyPeerTokenInfoToTupleIPsecState<br>WfpAleSetOrClearPeerTokenInformation<br>WfpAlepCopyCredentialData|
|paramcount|0|0|
|`address`|14017fba8|14017fe18|
|sig|undefined WfpSizeTMultiply(void)|undefined WfpSizeTMultiply(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### WfpSizeTMultiply Calling Diff


```diff
--- WfpSizeTMultiply calling
+++ WfpSizeTMultiply calling
@@ -0,0 +1 @@
+AleRedirectRecordsDeserializeFromBuffer
```


## NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|KeReleaseSpinLockFromDpcLevel|KeReleaseSpinLockFromDpcLevel|
|fullname|NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel|NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel|
|`refcount`|253|252|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>EQoSpNotifyPolicyChanged<br>FUN_14002c7fa<br>FUN_14002fa40<br>FUN_1401ce9a8<br>Icmpv4pHandleEchoReplyAndError<br>Icmpv6pHandleEchoReplyAndError<br>IpGetAllTunnelPhysicalInterface<br>IpSetAllTunnelPhysicalInterface<br>IppCheckReassemblyQuota<br>IppCleanupEchoRequestManager<br>IppCleanupPhysicalInterfaceRequestManager</summary>IppCreateInReassemblySet<br>IppCreatePhysicalInterfaceRequest<br>IppEchoRequestSetGetNextExpirationTick<br>IppEchoRequestSetTimeout<br>IppFindBestDropCandidateInSet<br>IppFindOrCreateGroupForFragment<br>IppFragmentPackets<br>IppIncreaseReassemblySize<br>IppInsertReassembly<br>IppLbTransmitAdaptiveOrWorkerMode<br>IppLbTransmitStackCallout<br>IppLoopbackEnqueue<br>IppNotificationTimeoutRoutine<br>IppPhysicalInterfaceNotificationTimeoutRoutine<br>IppPhysicalInterfaceRequestSetGetNextExpirationTick<br>IppPhysicalInterfaceRequestSetTimeout<br>IppReassemblyGetNextExpirationTick<br>IppReassemblyInterfaceCleanup<br>IppReassemblyTimeout<br>IppRemoveFromReassemblySet<br>IppRemoveReassembly<br>IppSetNextHopInPathUnderLock<br>IppSitePrefixSetTimeout<br>IppTimeout<br>IppTimerUpdateNextExpirationTick<br>IppValidatePathUnderLock<br>Ipv4GetAllEchoRequestParameters<br>Ipv4SendEchoRequestComplete<br>Ipv4SetAllEchoRequestParameters<br>Ipv4SetEchoRequestCreate<br>Ipv4pFragmentLookup<br>Ipv6GetAllEchoRequestParameters<br>Ipv6SendEchoRequestComplete<br>Ipv6SetEchoRequestCreate<br>Ipv6pFragmentLookup<br>LwUnlockQueue<br>OlmDeactivateAfInterface<br>OlmNotifyOffloadEventInterface<br>OlmSetTcpInterfaceParametersByLuid<br>RssCleanupStaticAdapter<br>RssRemoveAdapter<br>RssStartStaticAdapter<br>RssUpdateAdapter<br>RssUpdateAdapterLinkSpeed<br>RssUpdateAllAdaptersUnderLock<br>RssWorkQueueRoutine<br>TcpAbortTcbComplete<br>TcpAbortTcbDelivery<br>TcpCheckAndThrottleInitialCwndTcb<br>TcpCheckBHMode<br>TcpCheckSynRcvdLimit<br>TcpConnectionRundown<br>TcpCreateAndAcceptTcb<br>TcpCreateAndAcceptTcbComplete<br>TcpCreateAndConnectTcbCancelRoutine<br>TcpCreateAndConnectTcbComplete<br>TcpCreateAndConnectTcbInspectConnectComplete<br>TcpCreateEndpointWorkQueueRoutine<br>TcpCreateTimeWaitTcb<br>TcpDelayOrScheduleAck<br>TcpDeliverDataToClient<br>TcpDeliverInput<br>TcpDisconnectTcbComplete<br>TcpFastRetransmitTcbSend<br>TcpFlushDelay<br>TcpFlushTcbDelivery<br>TcpGetConnectionObject<br>TcpGetTcbConnectionParameters<br>TcpGlobalTimeoutHandler<br>TcpInitializeTimerTcb<br>TcpInjectFin<br>TcpInjectReceive<br>TcpInsertSynTcb<br>TcpInsertTcb<br>TcpInspectConnectionOnListener<br>TcpInspectListenerReceive<br>TcpInspectReceive<br>TcpLimitedTransmitTcbSend<br>TcpListenerReceive<br>TcpMatchControlReceive<br>TcpMatchReceive<br>TcpNotifyBacklogChangeSend<br>TcpNotifyTcbDelay<br>TcpPartitionUpdateNextExpirationTick<br>TcpPeriodicTimeoutHandler<br>TcpProcessExpiredSynTcbTimers<br>TcpProcessExpiredTcbTimers<br>TcpProcessExpiredTimeWaitTcbTimers<br>TcpPtoTimeout<br>TcpRecentFailureTrace<br>TcpRecordSoftErrorDatagram<br>TcpSackRetransmitTcbSend<br>TcpSatisfyReceiveRequests<br>TcpScheduleFlushDelay<br>TcpSetConnectionObject<br>TcpSetSockOptTcb<br>TcpShutdownTcb<br>TcpStartTimerTcbInternal<br>TcpSynTcbReceive<br>TcpTcbCarefulDatagram<br>TcpTcbControlReceive<br>TcpTcbKeepAliveSend<br>TcpTcbProcessNonCumulativeAck<br>TcpTcbReceive<br>TcpTcbSend<br>TcpTimeWaitTcbReceive<br>TcpTimerPowerStateChangeHandler<br>TcpTimerUpdateNextExpirationTick</details>|<details><summary>Expand for full list:<br>EQoSpNotifyPolicyChanged<br>FUN_14002c47a<br>FUN_14002f6c0<br>FUN_1401ccc22<br>Icmpv4pHandleEchoReplyAndError<br>Icmpv6pHandleEchoReplyAndError<br>IpGetAllTunnelPhysicalInterface<br>IpSetAllTunnelPhysicalInterface<br>IppCheckReassemblyQuota<br>IppCleanupEchoRequestManager<br>IppCleanupPhysicalInterfaceRequestManager</summary>IppCreateInReassemblySet<br>IppCreatePhysicalInterfaceRequest<br>IppEchoRequestSetGetNextExpirationTick<br>IppEchoRequestSetTimeout<br>IppFindBestDropCandidateInSet<br>IppFindOrCreateGroupForFragment<br>IppFragmentPackets<br>IppIncreaseReassemblySize<br>IppInsertReassembly<br>IppLbTransmitAdaptiveOrWorkerMode<br>IppLbTransmitStackCallout<br>IppLoopbackEnqueue<br>IppNotificationTimeoutRoutine<br>IppPhysicalInterfaceNotificationTimeoutRoutine<br>IppPhysicalInterfaceRequestSetGetNextExpirationTick<br>IppPhysicalInterfaceRequestSetTimeout<br>IppReassemblyGetNextExpirationTick<br>IppReassemblyInterfaceCleanup<br>IppReassemblyTimeout<br>IppRemoveFromReassemblySet<br>IppRemoveReassembly<br>IppSetNextHopInPathUnderLock<br>IppSitePrefixSetTimeout<br>IppTimeout<br>IppTimerUpdateNextExpirationTick<br>IppValidatePathUnderLock<br>Ipv4GetAllEchoRequestParameters<br>Ipv4SendEchoRequestComplete<br>Ipv4SetAllEchoRequestParameters<br>Ipv4SetEchoRequestCreate<br>Ipv4pFragmentLookup<br>Ipv6GetAllEchoRequestParameters<br>Ipv6SendEchoRequestComplete<br>Ipv6SetEchoRequestCreate<br>Ipv6pFragmentLookup<br>LwUnlockQueue<br>OlmDeactivateAfInterface<br>OlmNotifyOffloadEventInterface<br>OlmSetTcpInterfaceParametersByLuid<br>RssCleanupStaticAdapter<br>RssRemoveAdapter<br>RssStartStaticAdapter<br>RssUpdateAdapter<br>RssUpdateAdapterLinkSpeed<br>RssUpdateAllAdaptersUnderLock<br>RssWorkQueueRoutine<br>TcpAbortTcbComplete<br>TcpAbortTcbDelivery<br>TcpCheckAndThrottleInitialCwndTcb<br>TcpCheckBHMode<br>TcpCheckSynRcvdLimit<br>TcpConnectionRundown<br>TcpCreateAndAcceptTcb<br>TcpCreateAndAcceptTcbComplete<br>TcpCreateAndConnectTcbCancelRoutine<br>TcpCreateAndConnectTcbComplete<br>TcpCreateAndConnectTcbInspectConnectComplete<br>TcpCreateEndpointWorkQueueRoutine<br>TcpCreateTimeWaitTcb<br>TcpDelayOrScheduleAck<br>TcpDeliverDataToClient<br>TcpDeliverInput<br>TcpDisconnectTcbComplete<br>TcpFastRetransmitTcbSend<br>TcpFlushDelay<br>TcpFlushTcbDelivery<br>TcpGetConnectionObject<br>TcpGetTcbConnectionParameters<br>TcpGlobalTimeoutHandler<br>TcpInitializeTimerTcb<br>TcpInjectFin<br>TcpInjectReceive<br>TcpInsertSynTcb<br>TcpInsertTcb<br>TcpInspectConnectionOnListener<br>TcpInspectListenerReceive<br>TcpInspectReceive<br>TcpLimitedTransmitTcbSend<br>TcpListenerReceive<br>TcpMatchControlReceive<br>TcpMatchReceive<br>TcpNotifyBacklogChangeSend<br>TcpNotifyTcbDelay<br>TcpPartitionUpdateNextExpirationTick<br>TcpPeriodicTimeoutHandler<br>TcpProcessExpiredSynTcbTimers<br>TcpProcessExpiredTcbTimers<br>TcpProcessExpiredTimeWaitTcbTimers<br>TcpPtoTimeout<br>TcpRecentFailureTrace<br>TcpRecordSoftErrorDatagram<br>TcpSackRetransmitTcbSend<br>TcpSatisfyReceiveRequests<br>TcpScheduleFlushDelay<br>TcpSetConnectionObject<br>TcpSetSockOptTcb<br>TcpShutdownTcb<br>TcpStartTimerTcbInternal<br>TcpSynTcbReceive<br>TcpTcbCarefulDatagram<br>TcpTcbControlReceive<br>TcpTcbKeepAliveSend<br>TcpTcbProcessNonCumulativeAck<br>TcpTcbReceive<br>TcpTcbSend<br>TcpTimeWaitTcbReceive<br>TcpTimerPowerStateChangeHandler<br>TcpTimerUpdateNextExpirationTick</details>|
|paramcount|0|0|
|address|EXTERNAL:00000093|EXTERNAL:00000093|
|sig|undefined KeReleaseSpinLockFromDpcLevel(void)|undefined KeReleaseSpinLockFromDpcLevel(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel Calling Diff


```diff
--- NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel calling
+++ NTOSKRNL.EXE::KeReleaseSpinLockFromDpcLevel calling
@@ -2,3 +2,3 @@
-FUN_14002c7fa
-FUN_14002fa40
-FUN_1401ce9a8
+FUN_14002c47a
+FUN_14002f6c0
+FUN_1401ccc22
```


## wil_details_IsEnabledFallback

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|44|49|
|length|140|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|<details><summary>Expand for full list:<br>Feature_2379990329__private_IsEnabledFallback<br>Feature_2468869432__private_IsEnabledFallback<br>Feature_277588282__private_IsEnabledFallback<br>Feature_2800420155__private_IsEnabledFallback<br>Feature_30656824__private_IsEnabledFallback<br>Feature_3136536888__private_IsEnabledFallback<br>Feature_3765945658__private_IsEnabledFallback<br>Feature_3924026683__private_IsEnabledFallback<br>Feature_3968057659__private_IsEnabledFallback<br>Feature_403164475__private_IsEnabledFallback<br>Feature_4046438713__private_IsEnabledFallback</summary>Feature_5988_5730__private_IsEnabledFallback<br>Feature_800060729__private_IsEnabledFallback<br>Feature_BugFix_25D_Optimize_Expensive_Telemetry__private_IsEnabledFallback<br>Feature_CLAT_DHCP_Option108__private_IsEnabledFallback<br>Feature_CLAT_PREF64_FromRA__private_IsEnabledFallback<br>Feature_CLAT_Preview2_DhcpIPxlatPolicyMgr__private_IsEnabledFallback<br>Feature_DPT_K2_IppBuildHeaderCleanup__private_IsEnabledFallback<br>Feature_DPT_K2_RouteTimer_ReInit__private_IsEnabledFallback<br>Feature_FWPS_BugFixes_25B__private_IsEnabledFallback<br>Feature_Firewall_042024__private_IsEnabledFallback<br>Feature_IPSec_Point_To_Site__private_IsEnabledFallback<br>Feature_K2_IPv6Locking__private_IsEnabledFallback<br>Feature_NVBugFixes2507__private_IsEnabledFallback<br>Feature_Netsec_AuditMode_Hardening__private_IsEnabledFallback<br>Feature_Netsec_BugFix_UDPCaching__private_IsEnabledFallback<br>Feature_Servicing_FseUseAfterFreeFix__private_IsEnabledFallback<br>Feature_TCPIP_2025_2512_KCSAN_Fix__private_IsEnabledFallback<br>Feature_TCPIP_2025_KCSAN_RemoveHistograms__private_IsEnabledFallback<br>Feature_TCPIP_2025_TcpAfFix__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave2_SegLibHeap__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_FlVirtualInterfaceQueryCompartment__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_IsolationInfoCompartmentGuid__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_LSO_Diag__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_TCPSackReneging__private_IsEnabledFallback<br>Feature_TCPIP_58629296_Fix__private_IsEnabledFallback<br>Feature_TCPIP_FLS_CrossInterface__private_IsEnabledFallback<br>Feature_TCPIP_SFI_60707507_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Stack_Var_To_Heap_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Stack_Var_To_Heap_Special_Pool__private_IsEnabledFallback<br>Feature_TCPIP_USGv6_FirstFragmentSecurityHeaderFix__private_IsEnabledFallback<br>Feature_TCPIP_Wave5_59975062_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Wave5_FlVirtSetFailureReasonFix__private_IsEnabledFallback</details>|<details><summary>Expand for full list:<br>Feature_1204007226__private_IsEnabledFallback<br>Feature_2379990329__private_IsEnabledFallback<br>Feature_2468869432__private_IsEnabledFallback<br>Feature_277588282__private_IsEnabledFallback<br>Feature_2800420155__private_IsEnabledFallback<br>Feature_30656824__private_IsEnabledFallback<br>Feature_3131548987__private_IsEnabledFallback<br>Feature_3136536888__private_IsEnabledFallback<br>Feature_3765945658__private_IsEnabledFallback<br>Feature_3924026683__private_IsEnabledFallback<br>Feature_3968057659__private_IsEnabledFallback</summary>Feature_3999242553__private_IsEnabledFallback<br>Feature_4005012793__private_IsEnabledFallback<br>Feature_403164475__private_IsEnabledFallback<br>Feature_4046438713__private_IsEnabledFallback<br>Feature_4272399675__private_IsEnabledFallback<br>Feature_5988_5730__private_IsEnabledFallback<br>Feature_800060729__private_IsEnabledFallback<br>Feature_BugFix_25D_Optimize_Expensive_Telemetry__private_IsEnabledFallback<br>Feature_CLAT_DHCP_Option108__private_IsEnabledFallback<br>Feature_CLAT_PREF64_FromRA__private_IsEnabledFallback<br>Feature_CLAT_Preview2_DhcpIPxlatPolicyMgr__private_IsEnabledFallback<br>Feature_DPT_K2_IppBuildHeaderCleanup__private_IsEnabledFallback<br>Feature_DPT_K2_RouteTimer_ReInit__private_IsEnabledFallback<br>Feature_FWPS_BugFixes_25B__private_IsEnabledFallback<br>Feature_Firewall_042024__private_IsEnabledFallback<br>Feature_IPSec_Point_To_Site__private_IsEnabledFallback<br>Feature_K2_IPv6Locking__private_IsEnabledFallback<br>Feature_NVBugFixes2507__private_IsEnabledFallback<br>Feature_Netsec_AuditMode_Hardening__private_IsEnabledFallback<br>Feature_Netsec_BugFix_UDPCaching__private_IsEnabledFallback<br>Feature_Servicing_FseUseAfterFreeFix__private_IsEnabledFallback<br>Feature_TCPIP_2025_2512_KCSAN_Fix__private_IsEnabledFallback<br>Feature_TCPIP_2025_KCSAN_RemoveHistograms__private_IsEnabledFallback<br>Feature_TCPIP_2025_TcpAfFix__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave2_SegLibHeap__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_FlVirtualInterfaceQueryCompartment__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_IsolationInfoCompartmentGuid__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_LSO_Diag__private_IsEnabledFallback<br>Feature_TCPIP_2025_Wave4_TCPSackReneging__private_IsEnabledFallback<br>Feature_TCPIP_58629296_Fix__private_IsEnabledFallback<br>Feature_TCPIP_FLS_CrossInterface__private_IsEnabledFallback<br>Feature_TCPIP_SFI_60707507_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Stack_Var_To_Heap_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Stack_Var_To_Heap_Special_Pool__private_IsEnabledFallback<br>Feature_TCPIP_USGv6_FirstFragmentSecurityHeaderFix__private_IsEnabledFallback<br>Feature_TCPIP_Wave5_59975062_Fix__private_IsEnabledFallback<br>Feature_TCPIP_Wave5_FlVirtSetFailureReasonFix__private_IsEnabledFallback</details>|
|paramcount|0|0|
|`address`|14012ee98|14012e4e8|
|sig|undefined wil_details_IsEnabledFallback(void)|undefined wil_details_IsEnabledFallback(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -0,0 +1 @@
+Feature_1204007226__private_IsEnabledFallback
@@ -5,0 +7 @@
+Feature_3131548987__private_IsEnabledFallback
@@ -9,0 +12,2 @@
+Feature_3999242553__private_IsEnabledFallback
+Feature_4005012793__private_IsEnabledFallback
@@ -11,0 +16 @@
+Feature_4272399675__private_IsEnabledFallback
```


## Fl48pMapMulticastAddress

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|Fl48pMapMulticastAddress|Fl48pMapMulticastAddress|
|fullname|Fl48pMapMulticastAddress|Fl48pMapMulticastAddress|
|`refcount`|5|4|
|length|94|94|
|called|memset|memset|
|calling|Fl48MapAddress|Fl48MapAddress|
|paramcount|0|0|
|`address`|14011f4e0|14011e0f0|
|sig|undefined Fl48pMapMulticastAddress(void)|undefined Fl48pMapMulticastAddress(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## memset

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.85|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|memset|memset|
|fullname|memset|memset|
|`refcount`|707|706|
|length|236|236|
|called|||
|`calling`|<details><summary>Expand for full list:<br>AleInspectAcceptRequest<br>AleInspectBindRequest<br>AleInspectBindRequestComplete<br>AleInspectConnectRequest<br>AleInspectConnectRequestComplete<br>AleNotifyEndpointDeactivate<br>AleNotifyEndpointTeardown<br>AleRedirectRecordsSerializeToBuffer<br>AlepGetCachedConnectionPolicy<br>CBufferAllocate<br>CcmClientInitialize</summary>CheckAcceptBypass<br>CopyEnterpriseId<br>CreateConnectionSocketContext<br>CreateFqbnString<br>CreateListeningSocketContext<br>CreateMessageContext<br>CreatePartition<br>CreateTlgAggregateSession<br>DriverEntry<br>EQoSCreateNetBlockWithUninitializedNetPolicies<br>EQoSCreatePolicyOwner<br>EQoSCreatePolicyTable<br>EQoSCreateQoSProfile<br>EQoSCreateUrlSection<br>EQoSHkeClientNotifyAttachProvider<br>EQoSOpenUserPolicyRootKey<br>EQoSProcessQoSPolicies<br>EQoSQueryRegValueUnderQoSRootKey<br>EQoSStartPacerClient<br>EQoSpAllocateAndInitializePolicy<br>EQoSpCreateQoSFlow<br>EQoSpNmrRegisterClient<br>EQoSpPolicyAddPacketPolicyToScratchTable<br>EQoSpPolicyAddUrlPolicyToScratchTable<br>EQoSpPolicyParseAppName<br>EQoSpPolicyParseUrl<br>EQoSpProcessOnePolicy<br>EQoSpReturnNetPolicy<br>EQoSpReturnUrlPolicy<br>ExitBHMode<br>FUN_1401c7bee<br>FUN_1401d0802<br>FUN_1401d28f0<br>FUN_1401d5d86<br>FUN_1401dab8c<br>FillAddressEntry<br>FillIfEntryWithInterfaceInfo<br>FindPermittedPorts<br>Fl48pMapMulticastAddress<br>Fl48pReceiveArpPackets<br>Fl68pMapMulticastAddress<br>Fl6tpMapNonUnicastAddress<br>Fl8AddGroup<br>Fl8pPCFSetARPFilter<br>Fl8pPCFSetUDPFilter<br>FlBindAdapter<br>FlIfCreateVirtualInterface<br>FlIfProviderQueryObject<br>FlIfpDeleteInterfaceSubKey<br>FlIfpGenerateVirtualInterfaceAlias<br>FlIfpRegisterNdisInterface<br>FlPktMonRegisterProvider<br>FlRdmapNSINotificationWorkerRoutine<br>FlStatus<br>FlTeredoNotifyChangeAtPassive<br>FlTeredoPortNotifyChangeAtPassive<br>FlTunnelNotifyChangeAtPassive<br>FllpGetCompartmentInformation<br>FlpAddLocalPortWolPattern<br>FlpCheckAndCoalesceNBLChain<br>FlpChecksumCsoNbl<br>FlpCreateTcpWolPattern<br>FlpFlsInterceptReceivePackets<br>FlpGenerateWolPatternForAddress<br>FlpInitializeWolPattern<br>FlpInterfaceRundown<br>FlpNdisDirectRequestUnderReference<br>FlpNdisRequestUnderReference<br>FlpNdisSendNbls<br>FlpSerializedWolAddressEvictionWorker<br>FlpSetArpNDOffload<br>FlpSetDirectWolPattern<br>FlpSetWolPattern<br>FseGetCompleteMessage<br>FseInitializeSocketOpContext<br>GetAttribute<br>GetEnterpriseContext<br>HandOffIpsecStateToAleEntry<br>IPSecAddInboundSaToTrafficIndex<br>IPSecAddOutboundSaToTrafficIndex<br>IPSecAuditEvent<br>IPSecClearRekeyOriginalStateOnLarvalSaDeletion<br>IPSecComputeCpusForAllTunnels<br>IPSecCreateInboundPacketContext<br>IPSecCreateOutboundSessionContext<br>IPSecDetermineSaMatchInbound<br>IPSecDetermineSaMatchOutbound<br>IPSecDetermineSecureFilterMatch<br>IPSecDoCommonPerPacketInitInboundProcessing<br>IPSecDoCommonPerTransformInitOutboundProcessing<br>IPSecFindDuplicateInboundLarvalSA<br>IPSecFindDuplicateOutboundSA<br>IPSecFireDiagEvent<br>IPSecFireExternalDiagEvent<br>IPSecFireLpmPacketArrivalEvent<br>IPSecForwardInboundTunnelFilterCalloutClassifyV4<br>IPSecForwardInboundTunnelFilterCalloutClassifyV6<br>IPSecForwardOutboundTunnelFilterCalloutClassifyV4<br>IPSecForwardOutboundTunnelFilterCalloutClassifyV6<br>IPSecFwParseTunneledInnerPkt5Tulple<br>IPSecGetPkt5TupleFromNLTLInfo<br>IPSecGetTunnelInfoFromIPInformation<br>IPSecInboundAcceptAuthorizeCalloutClassify<br>IPSecInitAllModules<br>IPSecInitConf<br>IPSecInitializeUpcallModule<br>IPSecInitiateTransportKeying<br>IPSecInitiateTunnelKeying<br>IPSecIsOnlyActiveIPsec<br>IPSecLookupSaOutboundFromPacketSecurityContext<br>IPSecNlSendTunnelDatagram<br>IPSecNlSendTunnelIcmpError<br>IPSecNsProcessInboundSecurePacketCommon<br>IPSecNsProcessInboundSecurePacketIcmpError<br>IPSecNsProcessOutboundSecurePacketIcmpError<br>IPSecOutboundTransportFilterCalloutClassifyCommon<br>IPSecOutboundTransportFilterCalloutClassifyV4<br>IPSecOutboundTransportFilterCalloutClassifyV6<br>IPSecOutboundTunnelFilterCalloutClassifyCommon<br>IPSecProcessAsyncPendComplete<br>IPSecProcessAsyncUpcallNotifySaNegotiation<br>IPSecProcessClearTextOnInboundTransportFilter<br>IPSecRekeyInboundSa<br>IPSecRekeyOutboundSa<br>IPSecResponderCreateSPIHndlr<br>IPSecSetUpSendDatagram<br>IPSecSetupSendSessionInfo<br>IPSecUpcallNotifySaNegotiation<br>IPSecValidateNLInfoOnInboundTransportModePacket<br>IPSecValidateNLInfoOnInboundTransportModePacketV4<br>IPSecValidateNLInfoOnInboundTransportModePacketV6<br>IPsecAreTunnelEndpointsSameAsIPHeader<br>IPsecCreateFwdStateHelper<br>IPsecDestroyAleDiscardState<br>IPsecFwInboundVerifyPacketAgainstSATS<br>IPsecInboundAcceptAuthorizeCalloutProcessSecurityRealmId<br>IPsecPacketStateCloneInbound<br>IPsecPacketStateCloneOutbound<br>IPsecParseFwdPkt<br>IPsecRestoreTransProtoForInboundPkt<br>IPsecSaOnConnectionOffloaded<br>IPsecToggleFragGrouping<br>IPsecTransformClearTextPacket<br>Icmpv6pHandleEchoRequest<br>IdpCheckAndFireStopEvent<br>IdpCreateStateEntry<br>IdpFireDiagEvent<br>IdpQosCreateFlow<br>IdpQosCreatePacerHandle<br>IndicateAleSuccessAudit<br>IndicateDoSAttackAudit<br>IndicateDropAudit<br>IndicateVetoAudit<br>InetAllocateAndQueryAncillaryDataAf<br>InetCreateAf<br>InetCreateClient<br>InetFastSendDatagramsOnPathAf_scrap<br>InetInitializeTransport<br>InetInspectSetBindEndpointInterface<br>InetJoinPathAf<br>InetLogPacketDrop<br>InetReferencePathAf<br>InetResolveLocalAddressAndSockAddrToPathAndAf<br>InetSendDatagramsAf<br>InetSetPathBHConfirmationAf<br>InetSetPathConnectionFailedAf<br>InetSetSessionInformationAf<br>InetStartInspectionModule<br>InetWakeAcquirePortAf<br>InetWakeReleasePortAf<br>InitalizeClientGlobals<br>InternalGetIpInterfaceEntry<br>IpFlcAddInterface<br>IpGetAllCompartmentParameters<br>IpGetAllGlobalParameters<br>IpGetAllInterfaceHopParameters<br>IpGetAllInterfaceParameters<br>IpGetAllNeighborParameters<br>IpGetAllSortedAddressParameters<br>IpGetAllSubInterfaceParameters<br>IpIpsProviderSendIcmpError<br>IpNlpFastContinueSendLoopbackDatagrams<br>IpNlpSetSessionInfo<br>IpSecAhCompleteOutbound<br>IpSecAhInitInbound<br>IpSecAhProcessAuthenticationData<br>IpSecEntry<br>IpSecEspInitOutbound<br>IpSecGetSessionInformation<br>IpSecIsIcmpNeeded<br>IpSecLookupApplicableOverheadToTcpConnection<br>IpSecProcessInboundSecureDiscardedPacket<br>IpSecTlPacketsInProcessing<br>IpSecTlPacketsOutProcessing<br>IppAddQualifiedRouteAndNextHop<br>IppAddressSetTimeout<br>IppAllocatePathUnderLock<br>IppConfigureIscsiAddress<br>IppCreateForwardPath<br>IppCreateMulticastSessionState<br>IppDadAnnouncementTimeout<br>IppFillInterfaceData<br>IppFillInterfaceInfo<br>IppFillSortingElement<br>IppFindNextHopAtDpcForForwarding<br>IppFindNextHopInFwdCacheOrRouteTable<br>IppFindOrCreateCompartmentByIdEx<br>IppForwardPackets<br>IppGetAddressesFromRoute<br>IppGetAllBestRouteParameters<br>IppGetAllLocalAddressParameters<br>IppGroupFragments<br>IppHandleWolContextEviction<br>IppIndicateArpPacketsToIpsServiceChain<br>IppIndicatePacketsToIpsServiceChain<br>IppInitializePathSet<br>IppInitializeProtocolSettings<br>IppInitializeSessionState<br>IppInjectIpsPackets<br>IppInspectBuildHeaders<br>IppInspectDiscardedPackets<br>IppInspectInjectForward<br>IppInspectInjectRawSend<br>IppInspectInjectTlSend<br>IppInspectLocalDatagramsOut<br>IppInspectOutboundNetworkConnection<br>IppInspectQueryRealNextHopInterfaceInternal<br>IppIpsFindNextHopWithRestrictions<br>IppIpsL3ForwardNbl<br>IppJoinPath<br>IppLbIndicatePackets<br>IppLbLogTransmitPacket<br>IppLogHwUsoFailure<br>IppLogMediaSenseEvent<br>IppLogPacketDiscard<br>IppLogPbrFailure<br>IppLogRouteBlockedEvent<br>IppLogRouteChangeEvents<br>IppLogRouteDgdStateChange<br>IppLogRouteLookupEvent<br>IppLogRouteNotificationEvent<br>IppLogRouteSelectionEvent<br>IppLogSourceConstraint<br>IppLogSrcAddrLookupEvent<br>IppLogStandbyTransitionAdjustment<br>IppNeighborSetTimeout<br>IppNotifyAddressChangeAtPassive<br>IppNotifyDad<br>IppNotifyEchoRequestChangeWorker<br>IppNotifyInterfaceChangeAtPassive<br>IppNotifyMfeChangeWorker<br>IppNotifyNeighborChangeAtPassive<br>IppNotifyRouteChangeAtPassive<br>IppNotifyRoutingEpochChangeAtPassive<br>IppNotifySitePrefixChangeAtPassive<br>IppPersistAndDeleteLocationTableForNetwork<br>IppPktMonRegisterInterface<br>IppProcessMulticastDiscoveryTimeoutEvents<br>IppProcessPhysicalInterfaceRequest<br>IppProtocolNeighborRundown<br>IppProtocolRouteRundown<br>IppReceiveEspNbl<br>IppReceivePackets<br>IppRefreshRouteLifetimes<br>IppRegQueryDwordValue<br>IppSendDatagramsCommon<br>IppSendDirect<br>IppSendError<br>IppSendMulticastDiscoveryRecords<br>IppStartProtocolManager<br>IppTraceAddressChangeNotificationEvent<br>IppTraceDadStateChangeEvent<br>IppTraceDisconnectInterface<br>IppTraceNeighborChangeNotificationEvent<br>IppTraceNeighborDiscovery<br>IppTraceNeighborReset<br>IppTraceNeighborState<br>IppTraceWolAddress<br>IppTraceWolContext<br>IppTransformIPsecPacket<br>IppUpdateBestSourceAddress<br>IppUpdatePathNotificationAtPassiveLevel<br>IppUpdateRoutesWithLocalAddressAsNextHopUnderLock<br>IpsLbFindAndPopulateLoopbackIfInfo<br>IpsLbHandleInitialInterfaceNotification<br>IpsLbHandleInterfaceAddition<br>IpsLbRegisterChangeNotification<br>IpsLbStartup<br>IpsecPktMonClientComponentUnregister<br>IpsecPktMonDetachProvider<br>Ipv4SetEchoRequestCreate<br>Ipv4pAddressInterface<br>Ipv4pCompactFragmentationHeader<br>Ipv4pHandleAddressMaskRequest<br>Ipv4pHandleEchoRequest<br>Ipv4pHandleTimestampRequest<br>Ipv4pReassemblyTimeout<br>Ipv4pRegSyncInterfaceDefaultGatewayChangeHandler<br>Ipv6GetAllPotentialRouters<br>Ipv6GetAllRouterInformation<br>Ipv6NotifyPotentialRouterChangeAtPassive<br>Ipv6SetEchoRequestCreate<br>Ipv6pAddressInterface<br>Ipv6pEnumRoutesAndAddPrefixBasedAddresses<br>Ipv6pNotifyRouteChange<br>Ipv6pNotifyRouterInformationChangeWorker<br>Ipv6pReassemblyTimeout<br>Ipv6pSendRedirectHelper<br>LogEtwIcmpDrop<br>LogEtwIcmpMessage<br>LruCleanupDpcRoutine<br>LwInitializeQueueEx<br>McGenControlCallbackV2<br>NetioAddressChangeCallBack<br>NetioHistogramUpload<br>NetioInterfaceChangeCallBack<br>NlShimFwLayerDirectClassify<br>OlmQuerySetRscCapabilities<br>PktMonDetachProvider<br>ProcessInboundTransportLayerClassify<br>ProcessOutTransportStackIndicationFast<br>ProcessRedirectLayerForNonNativeTCP<br>QimUpdateUDPEndpointOnPolicyChange<br>QueryAttributes<br>RawActivateEndpoint<br>RawBindEndpoint<br>RawCreateMessageIndication<br>RawSendMessages<br>RawSendMessagesOnPathCreation<br>RawSetSockOptEndpoint<br>RawStartNetworkModule<br>RssPrepareReceiveScaleParameters<br>RssQueryInterfacePortInformation<br>RssQueryPortAdapterInfo<br>RssQueryPortIndex<br>RssQueryPortProcessorInfo<br>RssSelectStaticProcessors<br>RssStartDistribution<br>RtlStringCbPrintfExW<br>RtlStringCchPrintfExW<br>RtlStringExHandleOtherFlagsW<br>SegLibCreateMultiNbNblClone<br>SegLibCreateMultiNbNblUsoClone<br>ShimIndicateDiscard<br>ShimIpDiscardV4<br>ShimIpDiscardV6<br>ShimIpForwardDiscard<br>ShimIpFragmentInV4<br>ShimIpFragmentInV6<br>ShimIpPacketInV4<br>ShimIpPacketInV6<br>ShimIpPacketOutV4<br>ShimIpPacketOutV6<br>TcpBwNotifyReceive<br>TcpBwUpdateEre<br>TcpComputeMssOption<br>TcpComputeSynRcvdLimit<br>TcpConnectionRundown<br>TcpCreateEndpoint<br>TcpCreateEndpointWorkQueueRoutine<br>TcpCreateSynTcb<br>TcpDeplumbWakePattern<br>TcpDequeueTcbSend<br>TcpEnumerateBoundEndpoints<br>TcpEnumerateListeners<br>TcpGetSockOptTcb<br>TcpGetTcbConnectionObject<br>TcpHistogramIncrement<br>TcpInitializeIsnGenerator<br>TcpInitializeRttEstimateTcb<br>TcpInitializeTcb<br>TcpInspectListenerReceive<br>TcpInspectListenerRedirect<br>TcpMppInitialize<br>TcpMppNppEvaluationHelper<br>TcpNotifyRetransmitTimeoutAtPassive<br>TcpOptionsForSynSend<br>TcpPlumbWakePattern<br>TcpProcessFastDatagramBatch<br>TcpRecentFailureTrace<br>TcpRemoveTcbTuple<br>TcpRemoveTimewaitTcbTuple<br>TcpResolveConnectRequestToPathAndAf<br>TcpScheduleNotificationChannelWorkItemTcb<br>TcpSendTrackerCreateTransmit<br>TcpSendTrackerGetNextRetransmits<br>TcpSendTrackerMarkTransmits<br>TcpSetFastopenPathInfoTcb<br>TcpSetSockOptListener<br>TcpSetSockOptTcb<br>TcpStartInetModule<br>TcpStartOlmModule<br>TcpTcbEarlyReceive<br>TcpTcbProcessNotificationChannelSetup<br>TcpTcbProcessNotificationChannelSetupRequest<br>TcpTcbProcessNotificationChannelTeardown<br>TcpTcbQueryIpsecMtuAndRetransmit<br>TcpTcbReceive<br>TcpTraceConnectionSummary<br>TcpTryToEnterBHMode<br>TcpTuneTcbEstats<br>TcpipEvaluateTlFilter<br>TcpipPcwGlobalCallback<br>TcpipPcwGlobalExCallback<br>TcpipPcwPerCpuCallback<br>TcpipPcwTlDropsCallback<br>TlShimDirectClassify<br>TlShimInspectTcpTransportReceiveFast<br>TraceFilterEngineValidateAndStoreRules<br>UQoSAttachClient<br>UQoSCreatePolicyInternal<br>UQoSUpdatePolicyInternal<br>UQoSpParseDescriptor<br>UQoSpValidateFilterConditions<br>UdpActivateEndpoint<br>UdpConnectRedirectObsolete<br>UdpEndpointProcessNotificationChannelSetup<br>UdpEndpointProcessNotificationChannelTeardown<br>UdpEnumerateEndpoints<br>UdpGetSockOptEndpoint<br>UdpOffloadAddInterface<br>UdpSendMessages<br>UdpSendMessagesOnPath<br>UdpSetDestinationEndpoint<br>UdpSetSockOptEndpoint<br>UdpTlProviderMessageCalloutRoutine<br>WFPDatagramDataShimV4<br>WFPDatagramDataShimV6<br>WfpAleAcquireFqbnFromToken<br>WfpAleAcquirePackageIdentityFromToken<br>WfpAleAcquireTokenInformationFromToken<br>WfpAleAllocateSecureSocketPolicy<br>WfpAleAuditEvent<br>WfpAleAuthHistogramUpload<br>WfpAleAuthLogHistogramDatapointWorkQueueRoutine<br>WfpAleAuthorizeAccept<br>WfpAleAuthorizeReceive<br>WfpAleAuthorizeSend<br>WfpAleCompleteOperation<br>WfpAleCopyEndpointToPublic<br>WfpAleCreatePeerInformation<br>WfpAleEndpointCreationHandler<br>WfpAleFastUdpInspection<br>WfpAleFindRemoteEndpoint<br>WfpAleGetPolicyAppIdTagFromToken<br>WfpAleGetServiceSidsFromToken<br>WfpAleInitialize<br>WfpAleInitializeIo<br>WfpAleInsertCredentialInformation<br>WfpAleInsertPeerInformation<br>WfpAleInsertProcessInformation<br>WfpAleInsertRemoteEndpoint<br>WfpAleInsertTupleStateEntry<br>WfpAleMarshalFqbnValue<br>WfpAleProcessEndpointEnumIoctl<br>WfpAleProcessExplicitCredentialQuery<br>WfpAleProcessSocketOption<br>WfpAleSecureSocketAdd<br>WfpAleUninitializeTupleState<br>WfpAleValidateISCSIEndPoint<br>WfpAlepAuthorizeAccept<br>WfpAlepAuthorizeOrClassifyListen<br>WfpAlepAuthorizeOrClassifyPort<br>WfpAlepAuthorizeOrClassifyRaw<br>WfpAlepAuthorizePromiscuousMode<br>WfpAlepAuthorizeReceive<br>WfpAlepAuthorizeSend<br>WfpAlepDeleteEntryFromTable<br>WfpAlepFlowEstablishedNotification<br>WfpAlepReauthorizeOutboundConnection<br>WfpAlepSecureSocketAddAsync<br>WfpAlepSetPeerTarget<br>WfpCreateProcessNotifyRoutine<br>WfpDestroyAppSidTable<br>WfpDestroyFilePathTable<br>WfpFreeTemporaryAleEndpoint<br>WfpHandOffTupleStateToTemporaryAleEntry<br>WfpInTransportShimV4Discard<br>WfpInTransportShimV6Discard<br>WfpIndicateSendControl<br>WfpInitializeTimerManager<br>WfpInspectReceiveControlShimV4<br>WfpInspectReceiveControlShimV6<br>WfpIpAddressCheckAndAdd<br>WfpIsLayerOffloadPossible<br>WfpLookupFilePathTableAndUpdateCount<br>WfpLookupSecurityDescriptorAndUpdateCount<br>WfpLookupSidTableAndUpdateCount<br>WfpNlShimInspectForwardDatagram<br>WfpNlShimInspectvSwitchForwardDatagram<br>WfpPacketQueueInit<br>WfpProcessInTransportStackIndication<br>WfpProcessInTransportStackIndicationFast<br>WfpRegGetUint32Value<br>WfpRegisterNlClient<br>WfpReinjectTunnelPacketFL<br>WfpSetVpnTriggerSecurityDescriptor<br>WfpShimGetStorageForClassifyValues<br>WfpShimIndicateDiscardGeneral<br>WfpSysTimerModuleInit<br>WfpTagAppIdToNblForRio<br>WfpTlShimInspectOutboundNetworkConnection<br>WfpTlShimInspectSendTcpDatagram<br>WfpUpdateConnectionContext<br>WfpVpnDisconnectDebounceDpcHandler<br>WfpVpnHandleCalloutClassify<br>WfpVpnHandleFlowDelete<br>WfpVpnNrptDpcHandler<br>WfpVpnNrptTriggerHandlerThread<br>WfpVpnResetFlowCounts<br>WfpVpnResetNrptTriggerInternal<br>WppTraceCallback</details>|<details><summary>Expand for full list:<br>AleInspectAcceptRequest<br>AleInspectBindRequest<br>AleInspectBindRequestComplete<br>AleInspectConnectRequest<br>AleInspectConnectRequestComplete<br>AleNotifyEndpointDeactivate<br>AleNotifyEndpointTeardown<br>AleRedirectRecordsSerializeToBuffer<br>AlepGetCachedConnectionPolicy<br>CBufferAllocate<br>CcmClientInitialize</summary>CheckAcceptBypass<br>CopyEnterpriseId<br>CreateConnectionSocketContext<br>CreateFqbnString<br>CreateListeningSocketContext<br>CreateMessageContext<br>CreatePartition<br>CreateTlgAggregateSession<br>DriverEntry<br>EQoSCreateNetBlockWithUninitializedNetPolicies<br>EQoSCreatePolicyOwner<br>EQoSCreatePolicyTable<br>EQoSCreateQoSProfile<br>EQoSCreateUrlSection<br>EQoSHkeClientNotifyAttachProvider<br>EQoSOpenUserPolicyRootKey<br>EQoSProcessQoSPolicies<br>EQoSQueryRegValueUnderQoSRootKey<br>EQoSStartPacerClient<br>EQoSpAllocateAndInitializePolicy<br>EQoSpCreateQoSFlow<br>EQoSpNmrRegisterClient<br>EQoSpPolicyAddPacketPolicyToScratchTable<br>EQoSpPolicyAddUrlPolicyToScratchTable<br>EQoSpPolicyParseAppName<br>EQoSpPolicyParseUrl<br>EQoSpProcessOnePolicy<br>EQoSpReturnNetPolicy<br>EQoSpReturnUrlPolicy<br>ExitBHMode<br>FUN_1401c80ae<br>FUN_1401d0642<br>FUN_1401d2730<br>FUN_1401d67da<br>FUN_1401daf90<br>FillAddressEntry<br>FillIfEntryWithInterfaceInfo<br>FindPermittedPorts<br>Fl48pMapMulticastAddress<br>Fl48pReceiveArpPackets<br>Fl68pMapMulticastAddress<br>Fl6tpMapNonUnicastAddress<br>Fl8pPCFSetARPFilter<br>Fl8pPCFSetUDPFilter<br>FlBindAdapter<br>FlIfCreateVirtualInterface<br>FlIfProviderQueryObject<br>FlIfpDeleteInterfaceSubKey<br>FlIfpGenerateVirtualInterfaceAlias<br>FlIfpRegisterNdisInterface<br>FlPktMonRegisterProvider<br>FlRdmapNSINotificationWorkerRoutine<br>FlStatus<br>FlTeredoNotifyChangeAtPassive<br>FlTeredoPortNotifyChangeAtPassive<br>FlTunnelNotifyChangeAtPassive<br>FllpGetCompartmentInformation<br>FlpAddLocalPortWolPattern<br>FlpCheckAndCoalesceNBLChain<br>FlpChecksumCsoNbl<br>FlpCreateTcpWolPattern<br>FlpFlsInterceptReceivePackets<br>FlpGenerateWolPatternForAddress<br>FlpInitializeWolPattern<br>FlpInterfaceRundown<br>FlpNdisDirectRequestUnderReference<br>FlpNdisRequestUnderReference<br>FlpNdisSendNbls<br>FlpSerializedWolAddressEvictionWorker<br>FlpSetArpNDOffload<br>FlpSetDirectWolPattern<br>FlpSetWolPattern<br>FseGetCompleteMessage<br>FseInitializeSocketOpContext<br>GetAttribute<br>GetEnterpriseContext<br>HandOffIpsecStateToAleEntry<br>IPSecAddInboundSaToTrafficIndex<br>IPSecAddOutboundSaToTrafficIndex<br>IPSecAuditEvent<br>IPSecClearRekeyOriginalStateOnLarvalSaDeletion<br>IPSecComputeCpusForAllTunnels<br>IPSecCreateInboundPacketContext<br>IPSecCreateOutboundSessionContext<br>IPSecDetermineSaMatchInbound<br>IPSecDetermineSaMatchOutbound<br>IPSecDetermineSecureFilterMatch<br>IPSecDoCommonPerPacketInitInboundProcessing<br>IPSecDoCommonPerTransformInitOutboundProcessing<br>IPSecFindDuplicateInboundLarvalSA<br>IPSecFindDuplicateOutboundSA<br>IPSecFireDiagEvent<br>IPSecFireExternalDiagEvent<br>IPSecFireLpmPacketArrivalEvent<br>IPSecForwardInboundTunnelFilterCalloutClassifyV4<br>IPSecForwardInboundTunnelFilterCalloutClassifyV6<br>IPSecForwardOutboundTunnelFilterCalloutClassifyV4<br>IPSecForwardOutboundTunnelFilterCalloutClassifyV6<br>IPSecFwParseTunneledInnerPkt5Tulple<br>IPSecGetPkt5TupleFromNLTLInfo<br>IPSecGetTunnelInfoFromIPInformation<br>IPSecInboundAcceptAuthorizeCalloutClassify<br>IPSecInitAllModules<br>IPSecInitConf<br>IPSecInitializeUpcallModule<br>IPSecInitiateTransportKeying<br>IPSecInitiateTunnelKeying<br>IPSecIsOnlyActiveIPsec<br>IPSecLookupSaOutboundFromPacketSecurityContext<br>IPSecNlSendTunnelDatagram<br>IPSecNlSendTunnelIcmpError<br>IPSecNsProcessInboundSecurePacketCommon<br>IPSecNsProcessInboundSecurePacketIcmpError<br>IPSecNsProcessOutboundSecurePacketIcmpError<br>IPSecOutboundTransportFilterCalloutClassifyCommon<br>IPSecOutboundTransportFilterCalloutClassifyV4<br>IPSecOutboundTransportFilterCalloutClassifyV6<br>IPSecOutboundTunnelFilterCalloutClassifyCommon<br>IPSecProcessAsyncPendComplete<br>IPSecProcessAsyncUpcallNotifySaNegotiation<br>IPSecProcessClearTextOnInboundTransportFilter<br>IPSecRekeyInboundSa<br>IPSecRekeyOutboundSa<br>IPSecResponderCreateSPIHndlr<br>IPSecSetUpSendDatagram<br>IPSecSetupSendSessionInfo<br>IPSecUpcallNotifySaNegotiation<br>IPSecValidateNLInfoOnInboundTransportModePacket<br>IPSecValidateNLInfoOnInboundTransportModePacketV4<br>IPSecValidateNLInfoOnInboundTransportModePacketV6<br>IPsecAreTunnelEndpointsSameAsIPHeader<br>IPsecCreateFwdStateHelper<br>IPsecDestroyAleDiscardState<br>IPsecFwInboundVerifyPacketAgainstSATS<br>IPsecInboundAcceptAuthorizeCalloutProcessSecurityRealmId<br>IPsecPacketStateCloneInbound<br>IPsecPacketStateCloneOutbound<br>IPsecParseFwdPkt<br>IPsecRestoreTransProtoForInboundPkt<br>IPsecSaOnConnectionOffloaded<br>IPsecToggleFragGrouping<br>IPsecTransformClearTextPacket<br>Icmpv6pHandleEchoRequest<br>IdpCheckAndFireStopEvent<br>IdpCreateStateEntry<br>IdpFireDiagEvent<br>IdpQosCreateFlow<br>IdpQosCreatePacerHandle<br>IndicateAleSuccessAudit<br>IndicateDoSAttackAudit<br>IndicateDropAudit<br>IndicateVetoAudit<br>InetAllocateAndQueryAncillaryDataAf<br>InetCreateAf<br>InetCreateClient<br>InetFastSendDatagramsOnPathAf_scrap<br>InetInitializeTransport<br>InetInspectSetBindEndpointInterface<br>InetJoinPathAf<br>InetLogPacketDrop<br>InetReferencePathAf<br>InetResolveLocalAddressAndSockAddrToPathAndAf<br>InetSendDatagramsAf<br>InetSetPathBHConfirmationAf<br>InetSetPathConnectionFailedAf<br>InetSetSessionInformationAf<br>InetStartInspectionModule<br>InetWakeAcquirePortAf<br>InetWakeReleasePortAf<br>InitalizeClientGlobals<br>InternalGetIpInterfaceEntry<br>IpFlcAddInterface<br>IpGetAllCompartmentParameters<br>IpGetAllGlobalParameters<br>IpGetAllInterfaceHopParameters<br>IpGetAllInterfaceParameters<br>IpGetAllNeighborParameters<br>IpGetAllSortedAddressParameters<br>IpGetAllSubInterfaceParameters<br>IpIpsProviderSendIcmpError<br>IpNlpFastContinueSendLoopbackDatagrams<br>IpNlpSetSessionInfo<br>IpSecAhCompleteOutbound<br>IpSecAhInitInbound<br>IpSecAhProcessAuthenticationData<br>IpSecEntry<br>IpSecEspInitOutbound<br>IpSecGetSessionInformation<br>IpSecIsIcmpNeeded<br>IpSecLookupApplicableOverheadToTcpConnection<br>IpSecProcessInboundSecureDiscardedPacket<br>IpSecTlPacketsInProcessing<br>IpSecTlPacketsOutProcessing<br>IppAddQualifiedRouteAndNextHop<br>IppAddressSetTimeout<br>IppAllocatePathUnderLock<br>IppConfigureIscsiAddress<br>IppCreateForwardPath<br>IppCreateMulticastSessionState<br>IppDadAnnouncementTimeout<br>IppFillInterfaceData<br>IppFillInterfaceInfo<br>IppFillSortingElement<br>IppFindNextHopAtDpcForForwarding<br>IppFindNextHopInFwdCacheOrRouteTable<br>IppFindOrCreateCompartmentByIdEx<br>IppForwardPackets<br>IppGetAddressesFromRoute<br>IppGetAllBestRouteParameters<br>IppGetAllLocalAddressParameters<br>IppGroupFragments<br>IppHandleWolContextEviction<br>IppIndicateArpPacketsToIpsServiceChain<br>IppIndicatePacketsToIpsServiceChain<br>IppInitializePathSet<br>IppInitializeProtocolSettings<br>IppInitializeSessionState<br>IppInjectIpsPackets<br>IppInspectBuildHeaders<br>IppInspectDiscardedPackets<br>IppInspectInjectForward<br>IppInspectInjectRawSend<br>IppInspectInjectTlSend<br>IppInspectLocalDatagramsOut<br>IppInspectOutboundNetworkConnection<br>IppInspectQueryRealNextHopInterfaceInternal<br>IppIpsFindNextHopWithRestrictions<br>IppIpsL3ForwardNbl<br>IppJoinPath<br>IppLbIndicatePackets<br>IppLbLogTransmitPacket<br>IppLogHwUsoFailure<br>IppLogMediaSenseEvent<br>IppLogPacketDiscard<br>IppLogPbrFailure<br>IppLogRouteBlockedEvent<br>IppLogRouteChangeEvents<br>IppLogRouteDgdStateChange<br>IppLogRouteLookupEvent<br>IppLogRouteNotificationEvent<br>IppLogRouteSelectionEvent<br>IppLogSourceConstraint<br>IppLogSrcAddrLookupEvent<br>IppLogStandbyTransitionAdjustment<br>IppNeighborSetTimeout<br>IppNotifyAddressChangeAtPassive<br>IppNotifyDad<br>IppNotifyEchoRequestChangeWorker<br>IppNotifyInterfaceChangeAtPassive<br>IppNotifyMfeChangeWorker<br>IppNotifyNeighborChangeAtPassive<br>IppNotifyRouteChangeAtPassive<br>IppNotifyRoutingEpochChangeAtPassive<br>IppNotifySitePrefixChangeAtPassive<br>IppPersistAndDeleteLocationTableForNetwork<br>IppPktMonRegisterInterface<br>IppProcessMulticastDiscoveryTimeoutEvents<br>IppProcessPhysicalInterfaceRequest<br>IppProtocolNeighborRundown<br>IppProtocolRouteRundown<br>IppReceiveEspNbl<br>IppReceivePackets<br>IppRefreshRouteLifetimes<br>IppRegQueryDwordValue<br>IppSendDatagramsCommon<br>IppSendDirect<br>IppSendError<br>IppSendMulticastDiscoveryRecords<br>IppStartProtocolManager<br>IppTraceAddressChangeNotificationEvent<br>IppTraceDadStateChangeEvent<br>IppTraceDisconnectInterface<br>IppTraceNeighborChangeNotificationEvent<br>IppTraceNeighborDiscovery<br>IppTraceNeighborReset<br>IppTraceNeighborState<br>IppTraceWolAddress<br>IppTraceWolContext<br>IppTransformIPsecPacket<br>IppUpdateBestSourceAddress<br>IppUpdatePathNotificationAtPassiveLevel<br>IppUpdateRoutesWithLocalAddressAsNextHopUnderLock<br>IpsLbFindAndPopulateLoopbackIfInfo<br>IpsLbHandleInitialInterfaceNotification<br>IpsLbHandleInterfaceAddition<br>IpsLbRegisterChangeNotification<br>IpsLbStartup<br>IpsecPktMonClientComponentUnregister<br>IpsecPktMonDetachProvider<br>Ipv4SetEchoRequestCreate<br>Ipv4pAddressInterface<br>Ipv4pCompactFragmentationHeader<br>Ipv4pHandleAddressMaskRequest<br>Ipv4pHandleEchoRequest<br>Ipv4pHandleTimestampRequest<br>Ipv4pReassemblyTimeout<br>Ipv4pRegSyncInterfaceDefaultGatewayChangeHandler<br>Ipv6GetAllPotentialRouters<br>Ipv6GetAllRouterInformation<br>Ipv6NotifyPotentialRouterChangeAtPassive<br>Ipv6SetEchoRequestCreate<br>Ipv6pAddressInterface<br>Ipv6pEnumRoutesAndAddPrefixBasedAddresses<br>Ipv6pNotifyRouteChange<br>Ipv6pNotifyRouterInformationChangeWorker<br>Ipv6pReassemblyTimeout<br>Ipv6pSendRedirectHelper<br>LogEtwIcmpDrop<br>LogEtwIcmpMessage<br>LruCleanupDpcRoutine<br>LwInitializeQueueEx<br>McGenControlCallbackV2<br>NetioAddressChangeCallBack<br>NetioHistogramUpload<br>NetioInterfaceChangeCallBack<br>NlShimFwLayerDirectClassify<br>OlmQuerySetRscCapabilities<br>PktMonClientComponentUnregister<br>PktMonDetachProvider<br>ProcessInboundTransportLayerClassify<br>ProcessOutTransportStackIndicationFast<br>ProcessRedirectLayerForNonNativeTCP<br>QimUpdateUDPEndpointOnPolicyChange<br>QueryAttributes<br>RawActivateEndpoint<br>RawBindEndpoint<br>RawCreateMessageIndication<br>RawSendMessages<br>RawSendMessagesOnPathCreation<br>RawSetSockOptEndpoint<br>RawStartNetworkModule<br>RssPrepareReceiveScaleParameters<br>RssQueryInterfacePortInformation<br>RssQueryPortAdapterInfo<br>RssQueryPortIndex<br>RssQueryPortProcessorInfo<br>RssSelectStaticProcessors<br>RssStartDistribution<br>RtlStringCbPrintfExW<br>RtlStringCchPrintfExW<br>RtlStringExHandleOtherFlagsW<br>SegLibCreateMultiNbNblClone<br>SegLibCreateMultiNbNblUsoClone<br>ShimIndicateDiscard<br>ShimIpDiscardV4<br>ShimIpDiscardV6<br>ShimIpForwardDiscard<br>ShimIpFragmentInV4<br>ShimIpFragmentInV6<br>ShimIpPacketInV4<br>ShimIpPacketInV6<br>ShimIpPacketOutV4<br>ShimIpPacketOutV6<br>TcpBwNotifyReceive<br>TcpBwUpdateEre<br>TcpComputeMssOption<br>TcpComputeSynRcvdLimit<br>TcpConnectionRundown<br>TcpCreateEndpoint<br>TcpCreateEndpointWorkQueueRoutine<br>TcpCreateSynTcb<br>TcpDeplumbWakePattern<br>TcpDequeueTcbSend<br>TcpEnumerateBoundEndpoints<br>TcpEnumerateListeners<br>TcpGetSockOptTcb<br>TcpGetTcbConnectionObject<br>TcpHistogramIncrement<br>TcpInitializeIsnGenerator<br>TcpInitializeRttEstimateTcb<br>TcpInitializeTcb<br>TcpInspectListenerReceive<br>TcpInspectListenerRedirect<br>TcpMppInitialize<br>TcpMppNppEvaluationHelper<br>TcpNotifyRetransmitTimeoutAtPassive<br>TcpOptionsForSynSend<br>TcpPlumbWakePattern<br>TcpProcessFastDatagramBatch<br>TcpRecentFailureTrace<br>TcpRemoveTcbTuple<br>TcpRemoveTimewaitTcbTuple<br>TcpResolveConnectRequestToPathAndAf<br>TcpScheduleNotificationChannelWorkItemTcb<br>TcpSendTrackerCreateTransmit<br>TcpSendTrackerGetNextRetransmits<br>TcpSendTrackerMarkTransmits<br>TcpSetFastopenPathInfoTcb<br>TcpSetSockOptListener<br>TcpSetSockOptTcb<br>TcpStartInetModule<br>TcpStartOlmModule<br>TcpTcbEarlyReceive<br>TcpTcbProcessNotificationChannelSetup<br>TcpTcbProcessNotificationChannelSetupRequest<br>TcpTcbProcessNotificationChannelTeardown<br>TcpTcbQueryIpsecMtuAndRetransmit<br>TcpTcbReceive<br>TcpTraceConnectionSummary<br>TcpTryToEnterBHMode<br>TcpTuneTcbEstats<br>TcpipEvaluateTlFilter<br>TcpipPcwGlobalCallback<br>TcpipPcwGlobalExCallback<br>TcpipPcwPerCpuCallback<br>TcpipPcwTlDropsCallback<br>TlShimDirectClassify<br>TlShimInspectTcpTransportReceiveFast<br>TraceFilterEngineValidateAndStoreRules<br>UQoSAttachClient<br>UQoSCreatePolicyInternal<br>UQoSUpdatePolicyInternal<br>UQoSpParseDescriptor<br>UQoSpValidateFilterConditions<br>UdpActivateEndpoint<br>UdpConnectRedirectObsolete<br>UdpEndpointProcessNotificationChannelSetup<br>UdpEndpointProcessNotificationChannelTeardown<br>UdpEnumerateEndpoints<br>UdpGetSockOptEndpoint<br>UdpOffloadAddInterface<br>UdpSendMessages<br>UdpSendMessagesOnPath<br>UdpSetDestinationEndpoint<br>UdpSetSockOptEndpoint<br>UdpTlProviderMessageCalloutRoutine<br>WFPDatagramDataShimV4<br>WFPDatagramDataShimV6<br>WfpAleAcquireFqbnFromToken<br>WfpAleAcquirePackageIdentityFromToken<br>WfpAleAcquireTokenInformationFromToken<br>WfpAleAllocateSecureSocketPolicy<br>WfpAleAuditEvent<br>WfpAleAuthHistogramUpload<br>WfpAleAuthLogHistogramDatapointWorkQueueRoutine<br>WfpAleAuthorizeAccept<br>WfpAleAuthorizeReceive<br>WfpAleAuthorizeSend<br>WfpAleCompleteOperation<br>WfpAleCopyEndpointToPublic<br>WfpAleCreatePeerInformation<br>WfpAleEndpointCreationHandler<br>WfpAleFastUdpInspection<br>WfpAleFindRemoteEndpoint<br>WfpAleGetPolicyAppIdTagFromToken<br>WfpAleGetServiceSidsFromToken<br>WfpAleInitialize<br>WfpAleInitializeIo<br>WfpAleInsertCredentialInformation<br>WfpAleInsertPeerInformation<br>WfpAleInsertProcessInformation<br>WfpAleInsertRemoteEndpoint<br>WfpAleInsertTupleStateEntry<br>WfpAleMarshalFqbnValue<br>WfpAleProcessEndpointEnumIoctl<br>WfpAleProcessExplicitCredentialQuery<br>WfpAleProcessSocketOption<br>WfpAleSecureSocketAdd<br>WfpAleUninitializeTupleState<br>WfpAleValidateISCSIEndPoint<br>WfpAlepAuthorizeAccept<br>WfpAlepAuthorizeOrClassifyListen<br>WfpAlepAuthorizeOrClassifyPort<br>WfpAlepAuthorizeOrClassifyRaw<br>WfpAlepAuthorizePromiscuousMode<br>WfpAlepAuthorizeReceive<br>WfpAlepAuthorizeSend<br>WfpAlepDeleteEntryFromTable<br>WfpAlepFlowEstablishedNotification<br>WfpAlepReauthorizeOutboundConnection<br>WfpAlepSecureSocketAddAsync<br>WfpAlepSetPeerTarget<br>WfpCreateProcessNotifyRoutine<br>WfpDestroyAppSidTable<br>WfpDestroyFilePathTable<br>WfpFreeTemporaryAleEndpoint<br>WfpHandOffTupleStateToTemporaryAleEntry<br>WfpInTransportShimV4Discard<br>WfpInTransportShimV6Discard<br>WfpIndicateSendControl<br>WfpInitializeTimerManager<br>WfpInspectReceiveControlShimV4<br>WfpInspectReceiveControlShimV6<br>WfpIpAddressCheckAndAdd<br>WfpIsLayerOffloadPossible<br>WfpLookupFilePathTableAndUpdateCount<br>WfpLookupSecurityDescriptorAndUpdateCount<br>WfpLookupSidTableAndUpdateCount<br>WfpNlShimInspectForwardDatagram<br>WfpNlShimInspectvSwitchForwardDatagram<br>WfpPacketQueueInit<br>WfpProcessInTransportStackIndication<br>WfpProcessInTransportStackIndicationFast<br>WfpRegGetUint32Value<br>WfpRegisterNlClient<br>WfpReinjectTunnelPacketFL<br>WfpSetVpnTriggerSecurityDescriptor<br>WfpShimGetStorageForClassifyValues<br>WfpShimIndicateDiscardGeneral<br>WfpSysTimerModuleInit<br>WfpTagAppIdToNblForRio<br>WfpTlShimInspectOutboundNetworkConnection<br>WfpTlShimInspectSendTcpDatagram<br>WfpUpdateConnectionContext<br>WfpVpnDisconnectDebounceDpcHandler<br>WfpVpnHandleCalloutClassify<br>WfpVpnHandleFlowDelete<br>WfpVpnNrptDpcHandler<br>WfpVpnNrptTriggerHandlerThread<br>WfpVpnResetFlowCounts<br>WfpVpnResetNrptTriggerInternal<br>WppTraceCallback</details>|
|paramcount|3|3|
|`address`|1401c3280|1401c3740|
|sig|void * __cdecl memset(void * _Dst, int _Val, size_t _Size)|void * __cdecl memset(void * _Dst, int _Val, size_t _Size)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### memset Calling Diff


```diff
--- memset calling
+++ memset calling
@@ -42,5 +42,5 @@
-FUN_1401c7bee
-FUN_1401d0802
-FUN_1401d28f0
-FUN_1401d5d86
-FUN_1401dab8c
+FUN_1401c80ae
+FUN_1401d0642
+FUN_1401d2730
+FUN_1401d67da
+FUN_1401daf90
@@ -54 +53,0 @@
-Fl8AddGroup
@@ -329,0 +329 @@
+PktMonClientComponentUnregister
```


## RtlAcquireWriteLockAtDpcLevel

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|0.91|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|RtlAcquireWriteLockAtDpcLevel|RtlAcquireWriteLockAtDpcLevel|
|fullname|RtlAcquireWriteLockAtDpcLevel|RtlAcquireWriteLockAtDpcLevel|
|`refcount`|35|36|
|length|34|34|
|called|NTOSKRNL.EXE::KeAcquireInStackQueuedSpinLockAtDpcLevel|NTOSKRNL.EXE::KeAcquireInStackQueuedSpinLockAtDpcLevel|
|`calling`|<details><summary>Expand for full list:<br>CreateExclusion<br>EQoSGetAppName<br>EQoSGetQoSProfileFlowHandle<br>EQoSUpdateQoSProfile<br>Icmpv4HandleRouterAdvertisement<br>IppAddRemoveInterfaceProcessorContext<br>IppAddRemoveSubinterfacesProcessorContext<br>IppCommitSetAllSubInterfaceParameters<br>IppDeleteSubInterface<br>IppFindNextHopAtDpc<br>IppGarbageCollectLoopbackAddressSet</summary>IppResetNeighborsAtDpc<br>IppRouteSetTimeout<br>IppSetDhcpOperationalStatus<br>IppUpdateCompartment<br>Ipv4pRouterDiscoveryTimeout<br>Ipv6pHandleRouterAdvertisement<br>Ipv6pHandleRouterSolicitation<br>Ipv6pRouterPref64GetNextExpirationTick<br>Ipv6pRouterPref64Timeout<br>RawBindEndpointInspectComplete<br>TcpConnectionRundown<br>TcpFlushDelay<br>TcpGetAndWriteLockPartitionAtDpcLevel<br>TcpPartitionStartOrContinueMppEvaluation<br>TcpPartitionStopMppEvaluation<br>TcpRepartitionState</details>|<details><summary>Expand for full list:<br>CreateExclusion<br>EQoSGetAppName<br>EQoSGetQoSProfileFlowHandle<br>EQoSUpdateQoSProfile<br>Icmpv4HandleRouterAdvertisement<br>IppAddRemoveInterfaceProcessorContext<br>IppAddRemoveSubinterfacesProcessorContext<br>IppCommitSetAllSubInterfaceParameters<br>IppDeleteSubInterface<br>IppFindNextHopAtDpc<br>IppGarbageCollectLoopbackAddressSet</summary>IppResetNeighborsAtDpc<br>IppRouteSetTimeout<br>IppSetDhcpOperationalStatus<br>IppUpdateCompartment<br>Ipv4pRouterDiscoveryTimeout<br>Ipv6pHandleNeighborSolicitation<br>Ipv6pHandleRouterAdvertisement<br>Ipv6pHandleRouterSolicitation<br>Ipv6pRouterPref64GetNextExpirationTick<br>Ipv6pRouterPref64Timeout<br>TcpConnectionRundown<br>TcpFlushDelay<br>TcpGetAndWriteLockPartitionAtDpcLevel<br>TcpPartitionStartOrContinueMppEvaluation<br>TcpPartitionStopMppEvaluation<br>TcpRepartitionState</details>|
|paramcount|0|0|
|address|140010c00|140010c00|
|sig|undefined RtlAcquireWriteLockAtDpcLevel(void)|undefined RtlAcquireWriteLockAtDpcLevel(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### RtlAcquireWriteLockAtDpcLevel Calling Diff


```diff
--- RtlAcquireWriteLockAtDpcLevel calling
+++ RtlAcquireWriteLockAtDpcLevel calling
@@ -16,0 +17 @@
+Ipv6pHandleNeighborSolicitation
@@ -21 +21,0 @@
-RawBindEndpointInspectComplete
```


## NDIS.SYS::NdisReleaseRWLock

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|NdisReleaseRWLock|NdisReleaseRWLock|
|fullname|NDIS.SYS::NdisReleaseRWLock|NDIS.SYS::NdisReleaseRWLock|
|`refcount`|79|82|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>FlPnpEvent<br>FlRdmaUnbindAdapter<br>FlReceiveNetBufferListChainCalloutRoutine<br>FlUnbindAdapter<br>FlpAcceptPacket<br>FlpAddInterfaceComplete<br>FlpInterfaceReleaseReadLock<br>FlpMulticastListSet<br>FlpReceiveNonPreValidatedNetBufferListChain<br>FlpSerializedNdisRequestWorkerRoutine<br>FlpSetVirtualInterfaceHelper</summary>IPSecDoCommonPerPacketInitInboundProcessing<br>IPSecHandlePossibleUdpIdle<br>IPSecInboundSaExpired<br>IPSecLookupSaInbound<br>IPSecLookupSaOutboundFromPacketSecurityContext<br>IPSecNotifyStatusHndlr<br>IPSecNsProcessInboundSecurePacketCommon<br>IPSecPauseOffloadOnInterface<br>IPSecPendOrCopyPacket<br>IPSecResumeOffloadOnInterface<br>IPsecGetCachedTLShimEpoch<br>KfdDispatchDevCtl<br>LruCleanupDpcRoutine<br>TlShimDiscoverPhysicalNexthopInterface<br>WfpAleAcquirePeerInformation<br>WfpAleAcquireProcessInformation<br>WfpAleAcquireTokenInformation<br>WfpAleAcquireTokenInformationEx<br>WfpAleCaptureSecurityInformation<br>WfpAleFastFindRemoteEndpoint<br>WfpAleFindRemoteEndpoint<br>WfpAleGetAndReadLockPartition<br>WfpAleGetAndWriteLockPartition<br>WfpAleGetTupleStateEntry<br>WfpAleInsertCredentialInformation<br>WfpAleInsertProcessInformation<br>WfpAleInsertTokenInformation<br>WfpAleLookupPeerInformation<br>WfpAleLookupProcessInformation<br>WfpAleReleasePeerInformation<br>WfpAleReleaseTokenInformationById<br>WfpAlepEndpointCleanupWorkQueueRoutine<br>WfpAlepFreeRemoteEndpointsForEndpointContext<br>WfpAlepRemoveProcessInformation<br>WfpAlepTokenInformationCleanup<br>WfpCreateProcessNotifyRoutine<br>WfpDiscoverPhysicalNexthopInterfaceComplete<br>WfpFindAleUserIDByModifiedID<br>WfpInsertModifiedIdCorrelationEntry<br>WfpLookupFilePathTableAndUpdateCount<br>WfpLookupSecurityDescriptorAndUpdateCount<br>WfpLookupSidTableAndUpdateCount<br>WfpReleaseFastReadLock<br>WfpRemoveModifiedIdCorrelationEntry</details>|<details><summary>Expand for full list:<br>Fl8AddGroup<br>FlPnpEvent<br>FlRdmaUnbindAdapter<br>FlReceiveNetBufferListChainCalloutRoutine<br>FlUnbindAdapter<br>FlpAcceptPacket<br>FlpAddInterfaceComplete<br>FlpInterfaceReleaseReadLock<br>FlpMulticastListSet<br>FlpReceiveNonPreValidatedNetBufferListChain<br>FlpSerializedNdisRequestWorkerRoutine</summary>FlpSetVirtualInterfaceHelper<br>IPSecDoCommonPerPacketInitInboundProcessing<br>IPSecHandlePossibleUdpIdle<br>IPSecInboundSaExpired<br>IPSecLookupSaInbound<br>IPSecLookupSaOutboundFromPacketSecurityContext<br>IPSecNotifyStatusHndlr<br>IPSecNsProcessInboundSecurePacketCommon<br>IPSecPauseOffloadOnInterface<br>IPSecPendOrCopyPacket<br>IPSecResumeOffloadOnInterface<br>IPsecGetCachedTLShimEpoch<br>KfdDispatchDevCtl<br>LruCleanupDpcRoutine<br>TlShimDiscoverPhysicalNexthopInterface<br>WfpAleAcquirePeerInformation<br>WfpAleAcquireProcessInformation<br>WfpAleAcquireTokenInformation<br>WfpAleAcquireTokenInformationEx<br>WfpAleCaptureSecurityInformation<br>WfpAleFastFindRemoteEndpoint<br>WfpAleFindRemoteEndpoint<br>WfpAleGetAndReadLockPartition<br>WfpAleGetAndWriteLockPartition<br>WfpAleGetTupleStateEntry<br>WfpAleInsertCredentialInformation<br>WfpAleInsertProcessInformation<br>WfpAleInsertTokenInformation<br>WfpAleLookupPeerInformation<br>WfpAleLookupProcessInformation<br>WfpAleReleasePeerInformation<br>WfpAleReleaseTokenInformationById<br>WfpAlepEndpointCleanupWorkQueueRoutine<br>WfpAlepFreeRemoteEndpointsForEndpointContext<br>WfpAlepRemoveProcessInformation<br>WfpAlepTokenInformationCleanup<br>WfpCreateProcessNotifyRoutine<br>WfpDiscoverPhysicalNexthopInterfaceComplete<br>WfpFindAleUserIDByModifiedID<br>WfpInsertModifiedIdCorrelationEntry<br>WfpLookupFilePathTableAndUpdateCount<br>WfpLookupSecurityDescriptorAndUpdateCount<br>WfpLookupSidTableAndUpdateCount<br>WfpReleaseFastReadLock<br>WfpRemoveModifiedIdCorrelationEntry</details>|
|paramcount|0|0|
|address|EXTERNAL:000002cd|EXTERNAL:000002cd|
|sig|undefined NdisReleaseRWLock(void)|undefined NdisReleaseRWLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NDIS.SYS::NdisReleaseRWLock Calling Diff


```diff
--- NDIS.SYS::NdisReleaseRWLock calling
+++ NDIS.SYS::NdisReleaseRWLock calling
@@ -0,0 +1 @@
+Fl8AddGroup
```


## InetSetInterfacePropertyAf

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.84|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|InetSetInterfacePropertyAf|InetSetInterfacePropertyAf|
|fullname|InetSetInterfacePropertyAf|InetSetInterfacePropertyAf|
|`refcount`|7|8|
|length|110|110|
|called|IpNlpSetInterfaceProperty<br>_guard_dispatch_icall|IpNlpSetInterfaceProperty<br>_guard_dispatch_icall|
|calling|InetWakeAcquirePortAf<br>InetWakeReleasePortAf<br>OlmRssSetInterface<br>TcpPlumbWakePattern<br>UdpOffloadSendUroOid|InetWakeAcquirePortAf<br>InetWakeReleasePortAf<br>OlmRssSetInterface<br>TcpPlumbWakePattern<br>UdpOffloadSendUroOid|
|paramcount|0|0|
|`address`|1400c2548|1400bc178|
|sig|undefined InetSetInterfacePropertyAf(void)|undefined InetSetInterfacePropertyAf(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## NTOSKRNL.EXE::KeReleaseSpinLock

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|KeReleaseSpinLock|KeReleaseSpinLock|
|fullname|NTOSKRNL.EXE::KeReleaseSpinLock|NTOSKRNL.EXE::KeReleaseSpinLock|
|`refcount`|283|284|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>EQoSpNotifyPolicyChangedWorkItemRoutine<br>FUN_1401cbed2<br>FUN_1401ce9a8<br>FUN_1401d6795<br>FlpEdgeTraversalCalloutClassify<br>FlpEdgeTraversalCalloutNotify<br>FlpEtDeleteEtFilter<br>FlpEtEndpointDeleteNotification<br>HashTableUninitialize<br>Icmpv4pHandleEchoReplyAndError<br>Icmpv6pHandleEchoReplyAndError</summary>InetAcquirePort<br>InetWakeAcquirePortAf<br>InetWakeIsValidWakePort<br>InetWakeReleasePortAf<br>IpEnumerateFeatureFallbackParameters<br>IpGetAllTunnelPhysicalInterface<br>IpNlpFeatureFallbackCheck<br>IpNlpFeatureFallbackFlush<br>IpNlpFeatureFallbackUpdate<br>IpNlpSetPathInfo<br>IpSetAllTunnelPhysicalInterface<br>IppAddOrRemoveBandwidthListeners<br>IppCheckReassemblyQuota<br>IppCleanupEchoRequestManager<br>IppCleanupLocalAddress<br>IppCleanupPhysicalInterfaceRequestManager<br>IppCreateAndInsertFragmentIntoGroup<br>IppCreateInReassemblySet<br>IppCreatePhysicalInterfaceRequest<br>IppDeleteSitePrefixes<br>IppDereferenceAddressPrimitive<br>IppDereferenceLocalAddress<br>IppDereferenceLocalAddressIdentifier<br>IppDiscoverPhysicalInterfaceRequestComplete<br>IppFillPathInformation<br>IppFindBestDropCandidateInSet<br>IppFindLocationInFragmentGroup<br>IppFindOrCreateGroupForFragment<br>IppFindOrCreateLocalAddressIdentifier<br>IppFindSitePrefix<br>IppGetFirstCompartmentSitePrefix<br>IppGetNextSitePrefix<br>IppGroupFragments<br>IppLbEnqueueAdaptiveOrWorkerMode<br>IppLbTransmitWorker<br>IppLoadOrCreateLocationTableForNetwork<br>IppLocalitySetManagedAddressConfig<br>IppLocalitySetOtherStatefulAddressConfig<br>IppNeighborSetTimeout<br>IppNeighborSolicitationWorker<br>IppPathRandomizeIdentifiers<br>IppPersistAndDeleteLocationTableForNetwork<br>IppPersistNetworkTable<br>IppPopulateNetworkTable<br>IppReassemblyFindLocation<br>IppReassemblyInterfaceCleanup<br>IppRemoveFromReassemblySet<br>IppRemoveNeighborFromNSQueue<br>IppTimerPowerStateChangeHandler<br>Ipv4GetAllEchoRequestParameters<br>Ipv4SendEchoRequestComplete<br>Ipv4SetAllEchoRequestParameters<br>Ipv4SetEchoRequestCreate<br>Ipv6GetAllEchoRequestParameters<br>Ipv6SendEchoRequestComplete<br>Ipv6SetAllEchoRequestParameters<br>Ipv6SetEchoRequestCreate<br>Ipv6SitePrefixMatch<br>Ipv6pResetAutoConfiguredRoutes<br>Ipv6pUpdateSitePrefix<br>LwUnlockQueue<br>MicrosoftTelemetryAssertTriggeredWorker<br>OlmActivateAfInterface<br>OlmGetNextRscInterface<br>OlmNotifyAddInterface<br>OlmNotifyDeleteInterface<br>OlmNotifyDetachAf<br>OlmNotifyOffloadEventInterface<br>OlmNotifyRscIncompatibleCallout<br>OlmNotifyWakeEventInterface<br>OlmProcessRscStateChange<br>OlmQuerySetRscCapabilities<br>OlmQueryTcpInterfaceParametersByLuid<br>OlmSetTcpInterfaceParametersByLuid<br>OlmUpdateInterface<br>OlmUpdateTcpGlobalParameters<br>OlmWorkQueueRoutine<br>PplpLazyInitializeLookasideList<br>RngGetBufferRngPool<br>RssFindNewBindingForAdapter<br>RssGetProcessorAffinity<br>RssInsertAdapter<br>RssQueryScalabilityInfo<br>RssQueueUpdateAllAdapters<br>RssRemoveAdapter<br>RssRundown<br>RssStartStaticAdapter<br>RssUpdateAdapter<br>RssUpdateAdapterLinkSpeed<br>RssWorkQueueRoutine<br>TcpAbortTcb<br>TcpArmGlobalTimer<br>TcpBindEndpointInspectComplete<br>TcpBindEndpointRequestInspectComplete<br>TcpCloseEndpoint<br>TcpCloseSynTcb<br>TcpCloseTcb<br>TcpCompleteAcceptSynTcb<br>TcpCreateAndConnectTcb<br>TcpCreateAndConnectTcbCancelRoutine<br>TcpCreateAndConnectTcbInspectConnectComplete<br>TcpDeliverInput<br>TcpDequeueTcbInput<br>TcpDisconnectTcb<br>TcpEnqueueTcbSend<br>TcpEnumerateBoundEndpoints<br>TcpEnumerateConnections<br>TcpFindReceiveProcessorTcb<br>TcpFinishDeferredPortSelection<br>TcpGetSockOptTcb<br>TcpHandleSockOptSioWakeEndpoint<br>TcpInjectFin<br>TcpIoControlEndpoint<br>TcpIoControlTcb<br>TcpIsInterfaceAoAcCapable<br>TcpNotifyDisconnectDelivery<br>TcpOlmInterfaceRundown<br>TcpPushRequestReceive<br>TcpRequestReceive<br>TcpRestartTimer<br>TcpResumeConnectionOnListener<br>TcpSendDatagramsComplete<br>TcpSetSockOptEndpoint<br>TcpSetSockOptTcb<br>TcpShutdownTcb<br>TcpSynTcbSend<br>TcpSystemAbortTcb<br>TcpTcbHeaderSend<br>TcpTcbProcessNotificationChannelSetup<br>TcpTcbProcessNotificationChannelSetupRequest<br>TcpTcbProcessNotificationChannelTeardown<br>TcpTcbProcessNotificationChannelUnmarkRequest<br>TcpTcbQueryIpsecMtuAndRetransmit<br>TcpTcbSend<br>TcpTimeWaitTcbSend<br>TcpTlEndpointCloseEndpointCalloutRoutine<br>TcpTlEndpointIoControlEndpointCalloutRoutine<br>TcpipHealthTelemetryTimerRoutine<br>TcpipPowerNsiGetPowerPolicy<br>TcpipPowerNsiSetPowerPolicy<br>TcpipPowerQueryPowerPolicy<br>TcpipUpdateUroDisabledMask<br>UdpOffloadAddInterface<br>UdpOffloadDeleteInterface<br>UdpOffloadEnableUroForIpsec<br>UdpOffloadEventInterface<br>UdpOffloadUpdateInterface<br>UdpOffloadUroGetAllStats<br>UdpOffloadWorkQueueRoutine<br>WfpAleStreamLayerChanged</details>|<details><summary>Expand for full list:<br>EQoSpNotifyPolicyChangedWorkItemRoutine<br>FUN_1401ccc22<br>FUN_1401cfd44<br>FUN_1401d71e9<br>FlpEdgeTraversalCalloutClassify<br>FlpEdgeTraversalCalloutNotify<br>FlpEtDeleteEtFilter<br>FlpEtEndpointDeleteNotification<br>HashTableUninitialize<br>Icmpv4pHandleEchoReplyAndError<br>Icmpv6pHandleEchoReplyAndError</summary>InetAcquirePort<br>InetWakeAcquirePortAf<br>InetWakeIsValidWakePort<br>InetWakeReleasePortAf<br>IpEnumerateFeatureFallbackParameters<br>IpGetAllTunnelPhysicalInterface<br>IpNlpFeatureFallbackCheck<br>IpNlpFeatureFallbackFlush<br>IpNlpFeatureFallbackUpdate<br>IpNlpSetPathInfo<br>IpSetAllTunnelPhysicalInterface<br>IppAddOrRemoveBandwidthListeners<br>IppCheckReassemblyQuota<br>IppCleanupEchoRequestManager<br>IppCleanupLocalAddress<br>IppCleanupPhysicalInterfaceRequestManager<br>IppCreateAndInsertFragmentIntoGroup<br>IppCreateInReassemblySet<br>IppCreatePhysicalInterfaceRequest<br>IppDeleteSitePrefixes<br>IppDereferenceAddressPrimitive<br>IppDereferenceLocalAddress<br>IppDereferenceLocalAddressIdentifier<br>IppDiscoverPhysicalInterfaceRequestComplete<br>IppFillPathInformation<br>IppFindBestDropCandidateInSet<br>IppFindLocationInFragmentGroup<br>IppFindOrCreateGroupForFragment<br>IppFindOrCreateLocalAddressIdentifier<br>IppFindSitePrefix<br>IppGetFirstCompartmentSitePrefix<br>IppGetNextSitePrefix<br>IppGroupFragments<br>IppLbEnqueueAdaptiveOrWorkerMode<br>IppLbTransmitWorker<br>IppLoadOrCreateLocationTableForNetwork<br>IppLocalitySetManagedAddressConfig<br>IppLocalitySetOtherStatefulAddressConfig<br>IppNeighborSetTimeout<br>IppNeighborSolicitationWorker<br>IppPathRandomizeIdentifiers<br>IppPersistAndDeleteLocationTableForNetwork<br>IppPersistNetworkTable<br>IppPopulateNetworkTable<br>IppReassemblyFindLocation<br>IppReassemblyInterfaceCleanup<br>IppRemoveFromReassemblySet<br>IppRemoveNeighborFromNSQueue<br>IppTimerPowerStateChangeHandler<br>Ipv4GetAllEchoRequestParameters<br>Ipv4SendEchoRequestComplete<br>Ipv4SetAllEchoRequestParameters<br>Ipv4SetEchoRequestCreate<br>Ipv6GetAllEchoRequestParameters<br>Ipv6SendEchoRequestComplete<br>Ipv6SetAllEchoRequestParameters<br>Ipv6SetEchoRequestCreate<br>Ipv6SitePrefixMatch<br>Ipv6pResetAutoConfiguredRoutes<br>Ipv6pUpdateSitePrefix<br>LwUnlockQueue<br>MicrosoftTelemetryAssertTriggeredWorker<br>OlmActivateAfInterface<br>OlmGetNextRscInterface<br>OlmNotifyAddInterface<br>OlmNotifyDeleteInterface<br>OlmNotifyDetachAf<br>OlmNotifyOffloadEventInterface<br>OlmNotifyRscIncompatibleCallout<br>OlmNotifyWakeEventInterface<br>OlmProcessRscStateChange<br>OlmQuerySetRscCapabilities<br>OlmQueryTcpInterfaceParametersByLuid<br>OlmSetTcpInterfaceParametersByLuid<br>OlmUpdateInterface<br>OlmUpdateTcpGlobalParameters<br>OlmWorkQueueRoutine<br>PplpLazyInitializeLookasideList<br>RngGetBufferRngPool<br>RssFindNewBindingForAdapter<br>RssGetProcessorAffinity<br>RssInsertAdapter<br>RssQueryScalabilityInfo<br>RssQueueUpdateAllAdapters<br>RssRemoveAdapter<br>RssRundown<br>RssStartStaticAdapter<br>RssUpdateAdapter<br>RssUpdateAdapterLinkSpeed<br>RssWorkQueueRoutine<br>TcpAbortTcb<br>TcpArmGlobalTimer<br>TcpBindEndpointInspectComplete<br>TcpBindEndpointRequestInspectComplete<br>TcpCloseEndpoint<br>TcpCloseSynTcb<br>TcpCloseTcb<br>TcpCompleteAcceptSynTcb<br>TcpCreateAndConnectTcb<br>TcpCreateAndConnectTcbCancelRoutine<br>TcpCreateAndConnectTcbInspectConnectComplete<br>TcpDeliverInput<br>TcpDequeueTcbInput<br>TcpDisconnectTcb<br>TcpEnqueueTcbSend<br>TcpEnumerateBoundEndpoints<br>TcpEnumerateConnections<br>TcpFindReceiveProcessorTcb<br>TcpFinishDeferredPortSelection<br>TcpGetSockOptTcb<br>TcpHandleSockOptSioWakeEndpoint<br>TcpInjectFin<br>TcpIoControlEndpoint<br>TcpIoControlTcb<br>TcpIsInterfaceAoAcCapable<br>TcpNotifyDisconnectDelivery<br>TcpOlmInterfaceRundown<br>TcpPushRequestReceive<br>TcpRequestReceive<br>TcpRestartTimer<br>TcpResumeConnectionOnListener<br>TcpSendDatagramsComplete<br>TcpSetSockOptEndpoint<br>TcpSetSockOptTcb<br>TcpShutdownTcb<br>TcpSynTcbSend<br>TcpSystemAbortTcb<br>TcpTcbHeaderSend<br>TcpTcbProcessNotificationChannelSetup<br>TcpTcbProcessNotificationChannelSetupRequest<br>TcpTcbProcessNotificationChannelTeardown<br>TcpTcbProcessNotificationChannelUnmarkRequest<br>TcpTcbQueryIpsecMtuAndRetransmit<br>TcpTcbSend<br>TcpTimeWaitTcbSend<br>TcpTlEndpointCloseEndpointCalloutRoutine<br>TcpTlEndpointIoControlEndpointCalloutRoutine<br>TcpipHealthTelemetryTimerRoutine<br>TcpipPowerNsiGetPowerPolicy<br>TcpipPowerNsiSetPowerPolicy<br>TcpipPowerQueryPowerPolicy<br>TcpipUpdateUroDisabledMask<br>UdpOffloadAddInterface<br>UdpOffloadDeleteInterface<br>UdpOffloadEnableUroForIpsec<br>UdpOffloadEventInterface<br>UdpOffloadUpdateInterface<br>UdpOffloadUroGetAllStats<br>UdpOffloadWorkQueueRoutine<br>WfpAleStreamLayerChanged</details>|
|paramcount|0|0|
|address|EXTERNAL:0000012f|EXTERNAL:0000012f|
|sig|undefined KeReleaseSpinLock(void)|undefined KeReleaseSpinLock(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### NTOSKRNL.EXE::KeReleaseSpinLock Calling Diff


```diff
--- NTOSKRNL.EXE::KeReleaseSpinLock calling
+++ NTOSKRNL.EXE::KeReleaseSpinLock calling
@@ -2,3 +2,3 @@
-FUN_1401cbed2
-FUN_1401ce9a8
-FUN_1401d6795
+FUN_1401ccc22
+FUN_1401cfd44
+FUN_1401d71e9
```


## IppDeleteSitePrefixes

### Match Info



|Key|tcpip-8737.sys - tcpip-8875.sys|
| :---: | :---: |
|diff_type|length,address,called|
|ratio|1.0|
|i_ratio|0.77|
|m_ratio|0.94|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|tcpip-8737.sys|tcpip-8875.sys|
| :---: | :---: | :---: |
|name|IppDeleteSitePrefixes|IppDeleteSitePrefixes|
|fullname|IppDeleteSitePrefixes|IppDeleteSitePrefixes|
|refcount|4|4|
|`length`|149|171|
|`called`|NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock|IppRemoveSitePrefixEntry<br>NTOSKRNL.EXE::KeAcquireSpinLockRaiseToDpc<br>NTOSKRNL.EXE::KeReleaseSpinLock|
|calling|IpFlcDeleteInterface<br>IppHandlePrefixSharingChanged|IpFlcDeleteInterface<br>IppHandlePrefixSharingChanged|
|paramcount|0|0|
|`address`|1400981c4|140075b68|
|sig|undefined IppDeleteSitePrefixes(void)|undefined IppDeleteSitePrefixes(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### IppDeleteSitePrefixes Called Diff


```diff
--- IppDeleteSitePrefixes called
+++ IppDeleteSitePrefixes called
@@ -0,0 +1 @@
+IppRemoveSitePrefixEntry
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-16T10:17:31</sub>