EN
v2.5
WPE_TUTORIAL_V2 // 10_APPENDIX

Appendix · Reference

Latest tutorial

Four look-it-up-and-go tables: file types by extension, packet types side by side, the directory and dependencies for troubleshooting, and a glossary that settles the naming. Nothing here needs reading front to back — come back when something does not add up.

Appendix A · Data file types

ExtensionContentsExported fromEncrypted
.sbsystem backup — the whole configurationBackUp Settings✓
.fpthe filter listFilter List toolbar / right-click Export✓
.decthe decoder listDecoder List toolbar / right-click Export✓
.pexthe packet extractor listExtractor List toolbar / right-click Export✓
.spthe send listSend List toolbar / right-click Export✓
.sca send set — the packets of one sendSend Editor✓
.rpthe robot listRobot List toolbar / right-click Export✓
.whpthe warehouse listWareHouse List toolbar / right-click Export✓
.whsstored itemsWareHouse Editor toolbar / right-click✓
.pasauto-store rulesAuto Stores✓
.pathe proxy account listAccount List toolbar / right-click Export✓
.pml / .pmrlocal / remote mappingsMap Settings✓
.wl / .blallow list / block listFireWall Settings✓
.uprTCP unpacking rulesHook Settings → UnPack✗
.xlsExcel — tab-separated textExport to Excel, from any list's context menu✗
.cer .crt .pem .0the HTTPS root certificateProxy Settings → Export certificate✗
.filtimport: an old-WPE filterExtraction—
.chlsximport: a Charles sessionExtraction—
.iniimport and export: CCProxy accountsAccount List / Extraction—

Appendix B · Packet types

ValueEnumName on screenModeFilter category
0 / 1WS1_Send / WS2_SendSend 1.1 / SendInjectSend
2 / 3WS1_SendTo / WS2_SendToSendTo 1.1 / SendToInjectSendTo
4 / 5WS1_Recv / WS2_RecvRecv 1.1 / RecvInjectRecv
6 / 7WS1_RecvFrom / WS2_RecvFromRecvFrom 1.1 / RecvFromInjectRecvFrom
8WSASendWSASendInjectWSASend
9WSASendToWSASendToInjectWSASendTo
10 / 11WSARecv / WSARecvExWSARecvInjectWSARecv
12WSARecvFromWSARecvFromInjectWSARecvFrom
13 / 15TCP_Req / TCP_RespTCP Req / TCP ResProxyTCP Req / TCP Res
14 / 16UDP_Req / UDP_RespUDP Req / UDP ResProxyUDP Req / UDP Res
17–20HTTP(S)_Req / RespHTTP(S) Req / ResProxynever filtered; 19 / 20 (HTTPS) currently have no producer
21 / 22WebSocket_Req / RespWebSocket Req / ResProxynever filtered; 21 / 22 have no producer either

Appendix C · Files and dependencies

PathWhat it is
WinsockPacketEditor.exethe main program
WPEHook.dllthe capture module injected into the target process
EasyHook32/64.dll, EasyLoad32/64.dllthe EasyHook bootstrap libraries, picked automatically from the target's bitness
wpe-mihomo.exethe built-in mihomo network core: TUN routes selected process traffic into WPE SOCKS5
runtimes\win-{x86,x64}\native\e_sqlite3.dllthe SQLite engine (Microsoft.Data.Sqlite's native library), chosen by the system architecture
IPLocation\qqwry.datthe offline QQWry IP-location database (currently the 2026-08-26 edition, about 1.56 million ranges)
wwwroot\the interface itself: the Vue 3 build output plus the flag icons. This directory is the interface
McpServer\the server side of local MCP automation (WPEMcpServer.exe and its runtime libraries): WPE starts it on demand and talks to it over a named pipe — see Chapter 8
runtimes\win-{x86,x64,arm64}\native\WebView2Loader.dllWebView2's native loader, one per architecture
Web\the static pages of the remote management console (see Tools section 12)
wpe-data.icothe Explorer icon for the 16 file types WPE exports
WinsockPacketEditor.exe.configconfiguration the program needs to run — do not delete
C:\WPE64DB\<version>.dbthe default SQLite database; the path is changeable in Instance Settings
ComponentVersionUsed for
Microsoft.Web.WebView21.0.4191.47the interface host. The runtime is Evergreen and not shipped with the package; if it is missing, the program walks you through installing it
EasyHook2.7.7097process injection and API hooking
SuperSocket1.6.6.1the SOCKS5 server framework
mihomo1.19.31the TUN network core for process interception
QQWry1.3.1IP location
Microsoft.Data.Sqlite10.0.12persistence (plain SQL)
Microsoft.Owin.*4.2.3self-hosting the Remote MGT web service
InputSimulator1.0.4.0keyboard and mouse simulation for Robots
Newtonsoft.Json13.0.4serialisation for the Remote MGT web API

Appendix D · Glossary

TermMeaning
Inject Modeinjects WPE's capture module into the target process and hooks the WinSock API from inside it
Proxy ModeWPE runs its own SOCKS5 proxy service and the target's traffic detours through it
Socketa connection handle; sending a packet needs a valid one
System socketa global socket variable the Send List and Robot can use
Filtera rule that matches and rewrites real network data. Not to be confused with Leach Settings, which only affects what is displayed
Normal modematching at absolute positions — it compares and rewrites at fixed indexes only
Advanced modea sliding search for a signature; it can match in several places and rewrite at relative offsets
Progressionincrements the marked byte by the step on every match or send, with optional carry-over
Randomfills the marked position with a random 00–FF byte on every match, never the original value
Excludeinverts a search cell: it matches only when the byte is not the value you entered
Changediscards the original packet and builds a new one from the modify row
UnPacksplits a coalesced TCP stream into whole packets using the head and the length field
Process Settingsuses the built-in mihomo TUN to route selected or manually named processes through the WPE proxy
Upstream proxychains WPE's outbound traffic on to a further SOCKS proxy
Map Localreplaces the response body of a remote URL with a local file
Map Remoteredirects a request from one URL to another
WareHousewhere packet samples are archived
Auto Storesfiles matching packets into a warehouse by packet-head rules, in both modes
Speed Modea high-throughput mode that displays nothing and only counts packets and runs the filters
Multiple instancesrunning independent configurations side by side by switching the SQLite database path
WPC Configthe nodes, rules and notices published to the WPEProxyCap accelerator client