WPE_TUTORIAL_V2 // 10_APPENDIX
Appendix · Reference
Latest tutorial
Four look-it-up-and-go tables: file types by extension, packet types side by side, the directory and dependencies for troubleshooting, and a glossary that settles the naming. Nothing here needs reading front to back — come back when something does not add up.
Appendix A · Data file types
| Extension | Contents | Exported from | Encrypted |
.sb | system backup — the whole configuration | BackUp Settings | ✓ |
.fp | the filter list | Filter List toolbar / right-click Export | ✓ |
.dec | the decoder list | Decoder List toolbar / right-click Export | ✓ |
.pex | the packet extractor list | Extractor List toolbar / right-click Export | ✓ |
.sp | the send list | Send List toolbar / right-click Export | ✓ |
.sc | a send set — the packets of one send | Send Editor | ✓ |
.rp | the robot list | Robot List toolbar / right-click Export | ✓ |
.whp | the warehouse list | WareHouse List toolbar / right-click Export | ✓ |
.whs | stored items | WareHouse Editor toolbar / right-click | ✓ |
.pas | auto-store rules | Auto Stores | ✓ |
.pa | the proxy account list | Account List toolbar / right-click Export | ✓ |
.pml / .pmr | local / remote mappings | Map Settings | ✓ |
.wl / .bl | allow list / block list | FireWall Settings | ✓ |
.upr | TCP unpacking rules | Hook Settings → UnPack | ✗ |
.xls | Excel — tab-separated text | Export to Excel, from any list's context menu | ✗ |
.cer .crt .pem .0 | the HTTPS root certificate | Proxy Settings → Export certificate | ✗ |
.filt | import: an old-WPE filter | Extraction | — |
.chlsx | import: a Charles session | Extraction | — |
.ini | import and export: CCProxy accounts | Account List / Extraction | — |
Appendix B · Packet types
| Value | Enum | Name on screen | Mode | Filter category |
| 0 / 1 | WS1_Send / WS2_Send | Send 1.1 / Send | Inject | Send |
| 2 / 3 | WS1_SendTo / WS2_SendTo | SendTo 1.1 / SendTo | Inject | SendTo |
| 4 / 5 | WS1_Recv / WS2_Recv | Recv 1.1 / Recv | Inject | Recv |
| 6 / 7 | WS1_RecvFrom / WS2_RecvFrom | RecvFrom 1.1 / RecvFrom | Inject | RecvFrom |
| 8 | WSASend | WSASend | Inject | WSASend |
| 9 | WSASendTo | WSASendTo | Inject | WSASendTo |
| 10 / 11 | WSARecv / WSARecvEx | WSARecv | Inject | WSARecv |
| 12 | WSARecvFrom | WSARecvFrom | Inject | WSARecvFrom |
| 13 / 15 | TCP_Req / TCP_Resp | TCP Req / TCP Res | Proxy | TCP Req / TCP Res |
| 14 / 16 | UDP_Req / UDP_Resp | UDP Req / UDP Res | Proxy | UDP Req / UDP Res |
| 17–20 | HTTP(S)_Req / Resp | HTTP(S) Req / Res | Proxy | never filtered; 19 / 20 (HTTPS) currently have no producer |
| 21 / 22 | WebSocket_Req / Resp | WebSocket Req / Res | Proxy | never filtered; 21 / 22 have no producer either |
Appendix C · Files and dependencies
| Path | What it is |
WinsockPacketEditor.exe | the main program |
WPEHook.dll | the capture module injected into the target process |
EasyHook32/64.dll, EasyLoad32/64.dll | the EasyHook bootstrap libraries, picked automatically from the target's bitness |
wpe-mihomo.exe | the built-in mihomo network core: TUN routes selected process traffic into WPE SOCKS5 |
runtimes\win-{x86,x64}\native\e_sqlite3.dll | the SQLite engine (Microsoft.Data.Sqlite's native library), chosen by the system architecture |
IPLocation\qqwry.dat | the offline QQWry IP-location database (currently the 2026-08-26 edition, about 1.56 million ranges) |
wwwroot\ | the interface itself: the Vue 3 build output plus the flag icons. This directory is the interface |
McpServer\ | the server side of local MCP automation (WPEMcpServer.exe and its runtime libraries): WPE starts it on demand and talks to it over a named pipe — see Chapter 8 |
runtimes\win-{x86,x64,arm64}\native\WebView2Loader.dll | WebView2's native loader, one per architecture |
Web\ | the static pages of the remote management console (see Tools section 12) |
wpe-data.ico | the Explorer icon for the 16 file types WPE exports |
WinsockPacketEditor.exe.config | configuration the program needs to run — do not delete |
C:\WPE64DB\<version>.db | the default SQLite database; the path is changeable in Instance Settings |
| Component | Version | Used for |
| Microsoft.Web.WebView2 | 1.0.4191.47 | the interface host. The runtime is Evergreen and not shipped with the package; if it is missing, the program walks you through installing it |
| EasyHook | 2.7.7097 | process injection and API hooking |
| SuperSocket | 1.6.6.1 | the SOCKS5 server framework |
| mihomo | 1.19.31 | the TUN network core for process interception |
| QQWry | 1.3.1 | IP location |
| Microsoft.Data.Sqlite | 10.0.12 | persistence (plain SQL) |
| Microsoft.Owin.* | 4.2.3 | self-hosting the Remote MGT web service |
| InputSimulator | 1.0.4.0 | keyboard and mouse simulation for Robots |
| Newtonsoft.Json | 13.0.4 | serialisation for the Remote MGT web API |
Appendix D · Glossary
| Term | Meaning |
| Inject Mode | injects WPE's capture module into the target process and hooks the WinSock API from inside it |
| Proxy Mode | WPE runs its own SOCKS5 proxy service and the target's traffic detours through it |
| Socket | a connection handle; sending a packet needs a valid one |
| System socket | a global socket variable the Send List and Robot can use |
| Filter | a rule that matches and rewrites real network data. Not to be confused with Leach Settings, which only affects what is displayed |
| Normal mode | matching at absolute positions — it compares and rewrites at fixed indexes only |
| Advanced mode | a sliding search for a signature; it can match in several places and rewrite at relative offsets |
| Progression | increments the marked byte by the step on every match or send, with optional carry-over |
| Random | fills the marked position with a random 00–FF byte on every match, never the original value |
| Exclude | inverts a search cell: it matches only when the byte is not the value you entered |
| Change | discards the original packet and builds a new one from the modify row |
| UnPack | splits a coalesced TCP stream into whole packets using the head and the length field |
| Process Settings | uses the built-in mihomo TUN to route selected or manually named processes through the WPE proxy |
| Upstream proxy | chains WPE's outbound traffic on to a further SOCKS proxy |
| Map Local | replaces the response body of a remote URL with a local file |
| Map Remote | redirects a request from one URL to another |
| WareHouse | where packet samples are archived |
| Auto Stores | files matching packets into a warehouse by packet-head rules, in both modes |
| Speed Mode | a high-throughput mode that displays nothing and only counts packets and runs the filters |
| Multiple instances | running independent configurations side by side by switching the SQLite database path |
| WPC Config | the nodes, rules and notices published to the WPEProxyCap accelerator client |