FAQ
Answers to the questions that come up most — downloading and installing, injection and proxying, filters, senders and robots. If none of these solve it, open an issue on GitHub or email wpe64@qq.com.
Does it have to run as administrator?
Yes. The WPE x64 launcher requires administrator rights and asks through UAC as soon as you double-click it — there is no reduced-privilege mode. Injection writes into another process and installs hooks; process interception creates a TUN environment; and HTTPS mapping certificate management writes to the certificate store.
Is macOS or Linux supported?
No. WPE x64 is Windows-only: .NET Framework 4.8 with a Vue 3 interface hosted in WebView2, hooking the Windows WinSock API (wsock32.dll / ws2_32.dll / mswsock.dll) and using mihomo TUN for process interception. Running Windows in a VM on macOS or Linux works fine.
Can it capture from phones and emulators?
Yes — connect them to Proxy Mode with the proxy client WPC: install WPC for Android on the phone (download) or WPC for Windows on another PC, enter the subscription ID, pick a node and connect with a WPE proxy account. The device's traffic then reaches WPE over SOCKS5 according to the node rules, with no per-app proxy settings to fill in. What to turn on in WPE, how to set up nodes and how to get a subscription ID are covered in the tutorial: Proxy Mode · bringing in phones, emulators and other PCs with WPC.
HTTPS arriving through WPC is not decrypted. To read HTTPS in the clear, add an enabled HTTPS mapping rule for that host in Map Settings and install the WPE root certificate — see HTTPS in the clear: HTTPS mapping plus certificate.
An Android emulator can run WPC for Android inside it (the published APK is ARM64, so the emulator must be able to run ARM64 apps), or you can install WPC for Windows on the PC running the emulator. There is also a shortcut: the emulator is just a local process, so Inject Mode can hook it directly and skip the whole proxy-and-certificate setup.
There is no WPC for iPhone / iPad yet. Install a SOCKS5-capable proxy client from the App Store (such as Shadowrocket), point it at <PC IP>:1080 and use a WPE proxy account as the username and password. The nodes and rules configured in WPE are not delivered to such clients, so decide inside the client which traffic goes through the proxy — see How each kind of device connects.
Does capturing affect the target program? Which mode is lighter?
It depends on the mode, and it is worth deciding up front:
- Inject Mode: WPE's capture module is loaded into the target process and hooks the WinSock send / receive functions. Normally the program runs as usual, but it has been modified — anything with anti-injection or anti-cheat protection may throw errors, crash or flag the session. Pressing Stop Hook removes every hook and restores the process.
- Proxy Mode: WPE never touches the target process; it only adds a hop on the network path, so it is the least intrusive option. Traffic must reach the proxy first: other PCs and phones connect through WPC; local programs can point at it themselves or be selected in Process Settings for mihomo routing.
Using any capture or packet-editing tool in an online game with anti-cheat can get you penalised. Use it only on your own software, test environments or targets you are authorized to touch.
Can both modes run at the same time?
Not in one instance — once a mode is picked on the start page there is no way back to it. To run both, use Instance Settings to give a second instance its own database path, then start another copy of WPE in the other mode. The two configurations stay completely separate.
People say WPE only captures TCP and barely supports UDP. True?
That describes the 1.x release from twenty years ago. WPE x64 supports UDP fully:
- Inject Mode: besides
send/recv, it hookssendto/recvfrom/WSASendTo/WSARecvFrom. - Proxy Mode: the SOCKS5 service implements a complete UDP relay, with IPv4, IPv6 and domain address types.
- Filters: SendTo / RecvFrom (inject) and UDP request / UDP response (proxy) are separate packet types you can match and rewrite on their own.
What genuinely cannot be captured is ICMP (Ping) and raw sockets — neither goes through the WinSock send / receive family, and the proxy protocols have no channel for them. Full list under Limitations.
Does WPE work at the driver layer or the application layer?
Both modes work at the application layer — something the overview articles online routinely get wrong:
- Inject Mode injects a capture module into the target and hooks the send / receive functions in
ws2_32.dlland friends. Those are user-mode APIs, not the network stack. - Proxy Mode runs its own SOCKS5 service and traffic is routed through it — an application-layer proxy.
- Process Settings uses the built-in mihomo TUN to route selected process connections into WPE; it does not directly read or write packets at driver level.
This has a practical consequence: traffic that bypasses WinSock is invisible to Inject Mode — a program whose kernel driver sends packets directly, for instance. Use Proxy Mode and, where appropriate, route the process through Process Settings.
Can it capture every program on the machine at once?
No, and it is not meant to. WPE is a debugging tool aimed at one target at a time:
- Inject Mode handles one process per instance. To watch several at once, start multiple instances with Instance Settings and inject each separately.
- Proxy Mode only sees traffic that actually goes through the proxy. For local programs that ignore proxy settings, select them by name in Process Settings; it remains an allow-list, not a whole-machine takeover. When other PCs and phones connect through WPC, node forwarding rules likewise decide what reaches WPE.
That is a deliberate design choice: WPE's value is that it can edit and replay, not that it captures everything. Narrowing the scope to the target process usually makes analysis faster anyway.
How do I install it? Where is the installer?
There is nothing to install. What you download is WPE64 v2.5.zip; unzip it to get the single-file launcher WPE64 v2.5.exe, then double-click it (choose Yes on UAC) and it unpacks the program into %LOCALAPPDATA%\WPE64\app\<version>-<hash>\ and starts it; every later launch verifies and repairs the program files. Nothing goes into Add or Remove Programs. To remove it, delete the launcher and %LOCALAPPDATA%\WPE64\ (the configuration database lives separately under C:\WPE64DB\).
Downloads live under Downloads, on Lanzou or Baidu Pan (the pan link needs the extraction code shown on the page). Full steps in the tutorial: Download and install.
Windows marks files downloaded from the internet, and unzipping passes the mark on to the exe. Right-click the zip → Properties → Unblock → Apply before unzipping; otherwise the mark ends up on the unpacked files and injection fails with Code 15.
How do I know the download is intact?
Every release zip contains a .sha256.txt checksum file next to the exe, holding the exe's SHA256 value. Open PowerShell in the folder with both files, run Get-FileHash "WPE64 v2.5.exe" -Algorithm SHA256, and compare the result with the value at the start of the .sha256.txt file: if they match exactly, the file is fine (letter case does not matter); if not, download it again. Step-by-step instructions are in Downloads · SHA256 check.
Antivirus deleted some program files — what now?
The launcher checks the unpacked files on every start and restores anything missing or damaged before launching, so there is no need to download again. Security software may delete them again next time, though; for long-term use, add the launcher and the %LOCALAPPDATA%\WPE64\ folder to its allow list.
How do I upgrade? What happened to auto-update?
Older releases used ClickOnce online install and auto-update. That is gone. WPE never checks for versions and never prompts you — upgrading means downloading the new build yourself:
- Check the changelog on Downloads and get the new zip.
- Unblock → close the running old build (in Inject Mode, press Stop and exit the injected program first) → unzip and run the new launcher.
- No need to delete the old version folder yourself: the new launcher removes old version folders that are not in use.
The config database is C:\WPE64DB\<version>.db — the filename follows the version. So the first time a new build opens, filters, send lists, robots and proxy accounts all look empty. Nothing is lost; it is still in the old version's .db.
To carry it over: export a .sb file from the old build via BackUp Settings, then import it into the new one. See Upgrading to a new version.
Injection fails with STATUS_INTERNAL_ERROR (Code: 15)
Usually the downloaded file is blocked by Windows. The right order is: right-click the downloaded zip → Properties → Unblock → Apply → OK, and then unzip and run it. If you already ran it, unblock the launcher, delete its version folder under %LOCALAPPDATA%\WPE64\app\, and run it again so it unpacks fresh files.
The other cause: several different versions of WPE64 have injected the same process. Close all injected instances, restart the target, then inject again.
The window opens completely blank
The current interface is a web page hosted in WebView2, so a blank window has basically three causes:
- The WebView2 runtime is missing (by far the most common). WPE checks for it on startup and, if it is absent, shows a three-step prompt and opens Microsoft's official installer for you. Install it and reopen WPE.
- The system is too old. The supported range is listed under Requirements: Windows 10 / 11 and Server 2019 / 2022.
- The interface files were deleted. The interface itself is
wwwroot\inside the unpacked folder; if antivirus removed it, nothing is left to render. Delete the matching version folder under%LOCALAPPDATA%\WPE64\app\and run the launcher again so it unpacks a fresh copy (it verifies and repairs on every launch anyway).
Crash on launch or on injection
Restart WPE and the machine first. If it persists, work through this:
- Read the System Log page — unhandled exceptions are recorded there and can be exported. Since 2.2 WPE no longer writes a log file into the program folder, so if the process dies outright the Windows Event Viewer is all that is left.
- Let the launcher unpack a clean copy: delete the matching version folder under
%LOCALAPPDATA%\WPE64\app\(it also holds the WebView2 user-data cache) and double-click the launcher again. - If you suspect the configuration itself, try an empty database: on the start page open Instance Settings and point the path at a new folder. Your existing
C:\WPE64DB\is left untouched.
AppData is hidden — turn on "Show hidden files", or paste %LOCALAPPDATA%\WPE64\app\ straight into the address bar.
"Injection failed" after clicking Inject
Check in this order: ① is WPE running as administrator; ② does the target have anti-cheat or anti-injection protection (if so, switch to Proxy Mode); ③ are WPEHook.dll, EasyHook32/64.dll and EasyLoad32/64.dll all present in the program folder; ④ was the launcher unblocked; ⑤ read the full exception in the System Log.
Injection succeeded, but Start Hook captures nothing
① Does the WinSock readout on the run bar show —? It normally reads 1.1 / 2.0 / MS; a dash means the target has not loaded any WinSock module yet — make the program do something on the network, then inject again. ② Are the entry points ticked in Hook Settings (Inject Mode lists 12 WinSock entry points)? Anything newly ticked needs Stop Hook and then Start Hook — hooks are installed at the moment you press Start Hook. ③ Is the Filtered out counter in the stats row climbing? Then Leach Settings is dropping them. ④ Is Speed Mode on in System Settings? ⑤ Does a filter use the Hidden action?
Since 2.2 the WSARecvEx hook is not installed on 64-bit targets — its arguments are truncated under x64 and hooking it could crash the target. The 12 entry points in Hook Settings keep working; programs that receive only through that one extension function are very rare.
After "Pick a File", the target looks frozen
That is expected. This method starts the process suspended and only wakes it once the hooks are in place — pressing Start Hook on the run bar is what lets it run. The payoff is that even the very first packet is captured.
"Failed to start SOCKS5 proxy" when pressing Start
The port is taken, or the bind IP you chose does not exist. Change the port, or tick "auto detect" in Proxy Settings.
Proxy settings refuse to save
"Proxy type not set" → you must tick Enable SOCKS5. And with Auto detect unticked you have to supply a valid listen address; leaving it empty or mistyping it is rejected as well.
The target connected to the proxy, but nothing is captured
① Are the TCP and UDP request / response boxes ticked under Capture Directions in Hook Settings — an unchecked direction is forwarded untouched, with no list entry and no filters; ② is Leach Settings dropping them (watch the Filtered out counter in the stats row); ③ is Speed Mode on.
I selected a process, but the filter does nothing
In the current release, Process Settings uses the built-in mihomo core. Enable the core, select the target process (or type its name manually), then Save to apply the draft together; the status bar shows core and TUN readiness. If no traffic appears just after saving, restart the target program and try again.
HTTPS comes through as garbage
There are two cases. ① No enabled HTTPS mapping rule matches on the way in — that path is SOCKS5, where HTTPS is never decrypted, so encrypted bytes are expected; to read it in the clear, enable an HTTPS mapping rule for that host in Map Settings and make the device trust the WPE root certificate, see HTTPS in the clear: HTTPS mapping plus certificate. ② The rule is in place, but the WPE64 root certificate is not installed on the device. Press Create and then Trust under Proxy Settings → root certificate to install it here; other devices — a phone, another machine — need the certificate exported from Proxy Settings → Export certificate and installed manually as a trusted root.
The WPE64 certificate is installed, but HTTPS still is not readable
Almost certainly the app uses certificate pinning (SSL Pinning): it trusts only the certificate built into it, whatever the system trusts, so installing a certificate cannot fix it. Switch to Inject Mode to capture from inside the process, or skip decryption and watch it as TCP traffic.
Problems after connecting a phone or another PC through WPC
Match the symptom (the full setup steps are in Proxy Mode · bringing in devices with WPC):
| Symptom | Check this first |
|---|---|
| After subscribing the node list is empty, or WPC says the ID does not exist / has expired | ① is the ID valid — see Where subscription IDs come from; ② is WPE's Remote MGT running, and does the ID point at its listening address and port; ③ does the firewall allow inbound traffic on the Remote MGT port; ④ is the node ticked as enabled in WPC Config |
The debugging ID 127.0.0.1:88 returns no nodes | it only works for WPC for Windows on the same PC as WPE, and Remote MGT must listen on 127.0.0.1 — when it listens on a LAN IP, the loopback address cannot reach it |
| Nodes are listed, but connecting fails / verification times out | ① is WPE's proxy service running; ② is the node's server address an IP the device can reach (not 127.0.0.1 when another device uses it); ③ does the firewall allow inbound traffic on the SOCKS5 port, and is the port forwarded across the internet; ④ are both really on the same subnet — is the phone on 4G or a guest network |
| Verification reports a wrong username or password / an expired account | Account / Password is a WPE proxy account, not the subscription ID; the account must be enabled, unexpired and under its link / device limits |
| Connects, then drops immediately | the firewall is in WhiteList Mode and the device is not on the list, or the IP was auto-blocked after failed authentication |
| Connected, but WPE's list stays empty | ① did the node's forwarding rules send that traffic direct (on phones PROCESS-NAME rules are skipped, and check whether the app is selected in per-app proxy); ② are the TCP / UDP boxes ticked in Hook Settings; ③ is Leach Setting hiding them; ④ is Speed Mode on |
| WPE and WPC on the same PC, and the network misbehaves once connected | the rules fall back to MATCH,PROXY, so WPE's own outbound connections are sent back into WPE. Send only the target program through the proxy by process name and fall back to MATCH,DIRECT |
| HTTPS shows only encrypted bytes | HTTPS is not decrypted unless an enabled HTTPS mapping rule matches — that is expected; for plain text see HTTPS mapping plus certificate |
| HTTPS pages report an untrusted certificate | it was never installed, installed as a user certificate on Android 7+, or full trust was not enabled on iOS |
The driver-type radio buttons are greyed out
This is a leftover from older releases: a loaded driver still locks the choice, so it has to be uninstalled first.
Uninstalling the driver reboots the machine immediately. Save your work first.
Process takeover is done by the built-in mihomo core: turn it on in Process Settings, tick the target processes and save. This old option is not part of that path.
How do I get a WPC subscription ID? Can I create one?
You cannot create one; it has to be requested from the subscription server. The ID registry lives on the subscription server — neither the WPC client nor WPE x64 can issue IDs.
An ID maps to the public address of your WPE x64 proxy server: WPC exchanges the ID for that address at the subscription server, then pulls the node list, forwarding rules and notices from your WPE. So before anyone can reach your server with one-click subscribe, its public IP and the port of WPE x64's Remote MGT service (88 by default — not the SOCKS5 port) have to be registered.
- How to ask: GitHub Issue, or QQ group 1121552990.
- Validity: IDs carry an expiry date. Once expired the client cannot resolve the address any more and the ID needs renewing.
A WPC server address can only come from a subscription — there is no field to type an IP or port, so you need a subscription ID to use WPC.
WPE itself, though, exposes a standard SOCKS5 server: hand the address, port and proxy credentials to your users and any SOCKS5-capable app connects just as well — that path has nothing to do with subscription IDs. Full explanation under Proxy Cap · where subscription IDs come from.
WPC cannot connect — where do I look first?
① Does the subscription server status in the SUBSCRIPTION bay say Offline? That is the subscription hop, and has nothing to do with your account.
② For the node you picked, is the proxy service on the WPE side actually running (its status bar should read "Running")?
③ The credentials are a WPE proxy account, and that account has to be enabled, unexpired, and within its connection and device limits (the same account connected on another PC or phone also counts against the device limit).
When it will not connect, read WPC's System Log first: it says which step it stopped at and what the server answered. Among the reasons it gives, a connection timeout, SOCKS5 not supported or a communication failure points at the server; wrong account or password, an expired account, a disabled account or a device limit points at the account. The security check lives in the Control Center after connecting, so it cannot be opened while you are not connected.
Double-clicking WPC does nothing, or it flashes and disappears
Download WPC v1.2 (92.38 MB) from the Downloads page first. ① Usually the UAC prompt was declined: run WPC v1.2.exe again and choose Yes; on the first run, wait for the unpacking to finish.
② It says Microsoft Edge WebView2 is missing: install it as prompted and reopen — Windows 11 ships with it and Windows 10 normally has it via Edge.
③ Antivirus blocked it: restore it from the quarantine and add it to the allow list.
WPC stopped connecting after I changed the rules
When the client writes a node's forwarding rules into the acceleration core's configuration, a rule the core does not understand is skipped and an amber line reading 已跳过一条规则:类型,参数(原因) is written to the System Log — when connecting fails, read that line and the red lines around it. Rules are skipped when:
- the type is one the acceleration core does not support, or that needs configuration the client does not generate:
RULE-SET,SUB-RULE,UI-EX,COMMAND,DEVICE-NAME - the parameter is empty on a rule other than
MATCH, or filled in onMATCH - the parameter contains a comma (bracketed
AND/OR/NOTexpressions excepted); separate several ports with/, as in80/443
Fix or disable that rule in WPE x64 under WPC Config · rule types and parameters, have the client fetch the nodes again, then connect.
Other common WPC situations
| Symptom | What to check first |
|---|---|
| Announcements and servers are both empty | No subscription ID, or it has expired — see Entering a subscription ID |
| The SUBSCRIPTION bay says the subscription server is Offline | The hop from this machine to the subscription server is down — unrelated to your WPE. Check the local network and DNS first. The millisecond figure shown beside it is the latency to your own WPE, not to the subscription server |
| It says this account has reached its device limit | The same account connected on another PC or phone takes a slot too — disconnect that one first, or raise the device limit under proxy accounts in WPE x64 |
| Connected, but the game is not going through the proxy | ① Is that traffic being sent direct by a forwarding rule (rules live in WPE's WPC Config, one set per node)? ② Check WPC's System Log: a line reading 已跳过一条规则:…(原因) means that rule was skipped because the core does not understand it. ③ Other details are in the Mihomo lines |
| High latency or poor throughput | Try another node; announcements often mention things like "nodes are under heavy load during the event" |
| Acceleration suddenly disconnected | Check WPC's System Log: when the acceleration core exits unexpectedly, or the link to the server drops (network lost, or the same device signs in elsewhere), the client marks itself disconnected; click the reactor core to connect again. Core-side reasons are in the Mihomo lines |
WPC for Android says "VPN permission was not granted"
The Android version takes over traffic through Android's system VPN. On the first connection Android shows a VPN connection request; if you cancelled or refused it, you get this message. Go back to the Boost tab, tap the core to connect again and tap OK on the system prompt (Allow on some systems). No root is required.
WPC for Android is connected, but there is no internet
Work down this list:
- Node rules: open WPC's System Log and look for skipped rules. Rules the acceleration core does not support, as well as
PROCESS-NAME/PROCESS-PATHrules, are skipped on phones and recorded there. Rules are edited in WPE x64 under WPC Config. - Private DNS: with Android's Private DNS on, lookups no longer go over the usual port 53, so the app sniffs the domain back out — domains on the common ports (HTTP 80 / 8080–8880, HTTPS and QUIC 443 / 8443) are still recognised. Only traffic on other ports cannot be recovered, so those domain-based rules may not match; if that happens, turn Private DNS off in the system settings and try again.
- Per-app proxy: the entry point is on the Boost tab and only appears while you are disconnected (the Me tab does not have it), so disconnect first, edit, then connect again. In "Only selected apps" mode, apps you did not select do not use the proxy.
- The WPE end: is WPE x64's proxy service running on the node you connected to, and is the account enabled and unexpired?
Full details in the WPC Android tutorial · rules and DNS.
WPC for Android disconnects after the screen turns off
Usually Android is restricting the app in the background:
- If a "Background running is restricted" banner appears at the top of the Boost tab, tap Allow and allow it in the battery-optimization prompt; once the banner goes away and the background-running row no longer appears on the Me tab, it is set.
- Some vendor systems also need the app allowed to auto-start / run in the background in their phone manager app.
- Pressing Back only sends the app to the background and the connection keeps running; to disconnect, tap Disconnect on the Boost tab or in the notification.
When you switch between Wi-Fi and mobile data, or the phone briefly freezes the app, the app re-registers automatically and keeps the connection. It only disconnects if the account is rejected (wrong password, expired, disabled, device limit reached, account authentication not enabled on the server) or repeated retries fail, and the reason is written to WPC's System Log. See background running and reconnection.
The phone cannot connect and the System Log mentions the device limit
WPC for Android and WPC on a PC count as separate devices. If the account's device limit is 1 and the PC is already connected, connecting from the phone fails with "Connection failed. Check your subscription, account and password.", and Me → System Log shows 该账号的设备数已达上限 (the account's device limit has been reached; log messages are recorded in Chinese). Disconnect the PC first, or raise that account's device limit under proxy accounts in WPE x64.
WPC for Android says WebView is too old
The Android version's interface runs on Android System WebView and needs version 90 or later. Update "Android System WebView" or "Chrome" from the app store, then reopen the app. Phones without Google services update WebView through their own app store.
PROCESS-NAME rules do nothing on the phone
PROCESS-NAME and PROCESS-PATH rules are skipped by WPC for Android and recorded in the System Log; the connection is not affected. To send a particular game through the proxy on a phone, use per-app proxy: choose "Only selected apps" and tick those apps.
WPC for Android is connected, but no traffic goes through WPE
Per-app proxy and node rules are two gates, one after the other: per-app proxy first decides which apps hand their traffic to WPC, then the node rules decide whether it goes through the proxy or direct. Check in this order:
- Does the node have proxy rules that work on a phone? If the node only sends a game through the proxy by process name (for example just
PROCESS-NAME,game.exe,PROXYandMATCH,DIRECT), the process rule is skipped on the phone and everything left is direct. When such a node is selected, a "This node won't proxy any traffic on a phone" banner appears at the top of the Boost tab, and the node list tags it "No phone proxy rules". In WPE x64's WPC Config, give it proxy rules written by domain, IP or port, or change the catch-all rule toMATCH,PROXY. - Is the app selected? With "Only selected apps", apps you did not select connect directly and no rule reaches them. Changes take effect on the next connection.
Full details in the WPC Android tutorial · rules and DNS.
The filter never matches
Work down this list:
- Is the filter's On switch enabled in the Filter List?
- Is at least one box ticked under "Applies to" in the filter editor, and does it match the packets you are after (the eight WinSock types such as Send / Recv in Inject Mode, TCP / UDP request and response in Proxy Mode)?
- Did you fill in header / socket / port / length under Conditions but enter the wrong value? These are AND conditions — all must hold.
- Is the SEARCH row of the byte grid empty? With nothing to search for, nothing ever matches.
- In Normal mode, does the offset run past the packet length? That counts as no match.
- With "filter execution = priority", an earlier filter that already matched takes the packet — try moving this one to the top.
- Trying to edit an HTTP / HTTPS / WebSocket packet? Filters do not apply to those types. Use Map Settings instead.
The filter works, but edits the wrong bytes
Column heading 001 is byte index 0 — subtract one when counting offsets. In Advanced mode with Modify from set to "Given position", the column numbers in the modify grid are offsets from the match point (negatives allowed), not absolute positions; "Packet head" is what counts from the first byte.
The send ran, but the success count stays at 0
① Is the packet's socket valid (> 0 and still alive)? ② Did you tick "use system socket" without ever setting one — the System Log will say the system socket is not set; right-click a packet in the list and choose "Set as system socket" first. ③ In Proxy Mode the HTTP / HTTPS / WebSocket types cannot go through a send list — they have no socket; the only way to replay one is the packet editor with socket 0, which replies through the session it was captured on.
Pressing Execute on a robot does nothing
Check the System Log. A line like Robot instruction N error! [robot name] means validation failed and the robot refuses to start — most often an unpaired loop start / end, or a send item that has since been deleted.
Hotkeys do nothing
① Is "Applies to" set correctly in HotKey Settings (Send List or Robot List)? ② Is the combination already claimed globally by another program? ③ Does the list item with that index exist (hotkey 1 = first item in the list)?
It stutters under load and the Queue / Queued count climbs
Best return first:
- Turn off the two location columns in List Settings (Local Loc. / Remote Loc. in Inject Mode, Client Loc. / Server Loc. in Proxy Mode) — this drops the IP geolocation lookup and flag rendering, and is by far the biggest win.
- Keep Auto clear on in the toolbar of the data page and lower the row count (it is on by default, at 5000 — past that only the newest rows are kept, the list is never wiped).
- Turn off Auto scroll in the same toolbar.
- Use Leach Settings to show only the packets you care about.
- Turn off the Scan line under Preferences → Display (the gear on the title bar) — one less animation running all the time.
- Last resort: turn on Speed Mode — packet data is no longer displayed, only counted, and filters keep working.
Importing a backup says "Incorrect password"
Only a .sb file exported with Encrypt asks for a password on import, and it needs the same password that was set at export; an unencrypted backup imports straight away with no password box. A wrong entry shows "Wrong password — try again" and lets you retry; pressing Cancel closes the box with "Incorrect password", and nothing is imported.
What is MCP, and how do I let an AI drive WPE?
Since 2.3 WPE ships an MCP (Model Context Protocol) service: an AI client on the same machine that speaks MCP can connect and call WPE's existing features by conversation — read packets, look at logs, write filters, create accounts, run senders and robots. It is a local channel: both the service and the AI client run on this computer and it serves the current Windows user only, with no internet and no account. WPE has to be running — the connector never starts it for you. Full details in Chapter 8 · Local AI Automation.
To connect: home screen → MCP Settings and make sure the master switch is on, then add a stdio server to your AI client's MCP configuration pointing at C:\WPE64DB\McpServer\WPEMcpServer.exe (a fixed path, so upgrading WPE needs no configuration change). For the full walkthrough with VS Code — which file to edit, what JSON to paste, how to start the server and confirm trust — see Chapter 8 · Using VS Code.
| Symptom | What to check first |
|---|---|
| The client cannot connect, or reports WPE offline | ① Is WPE running? ② Is the master switch in MCP Settings still on? ③ Is the MCP status lamp on the status bar grey? |
| The tools are listed but every call fails | Read the System Log → MCP log tab: it carries the tool name and why it failed. Some tools only work under certain conditions (for example, letting the AI pick a mode needs you to still be on the home screen) |
| The AI says it changed something and the UI does not show it | List-type changes apply immediately; settings that concern a running service (listening ports, the system proxy) still need the service stopped first |
| You want it to stop writing | Turn on "MCP operations need confirmation", or switch the master switch off (an already-connected session ends with it) |
Every question above has fuller context and screenshots in the matching chapter of the tutorial.