EN
v2.5
WPE_TUTORIAL_V2 // 04_FILTER

Filters

Latest tutorial

Filters are the heart of WPE x64: match a packet by rule and rewrite it before it is really sent or received. This chapter covers the matching algorithms, the cell marks, the five actions and chained execution in one go.

00 · Before you edit: which tool should do it

Four places in WPE can change what goes over the wire, and they do not overlap. Picking the wrong one is the number-one reason a filter appears not to work — trying to edit HTTP(S) with a filter, above all, never matches:

What you wantUseWhy not a filter
Change a few bytes in a TCP / UDP packetFilter · Replace— this is it
Stop a kind of packet being sent or received at allFilter · Intercept— this is it
Reply with a fixed payload on a matchFilter · Change, or a filter triggering a Robot— this is it
Change an HTTP / HTTPS response bodyMap Settings · Map Localfilters expose 12 packet-type switches and none covers HTTP(S) or WebSocket — those packets never enter matching
Redirect a request to another host or portMap Settings · Map Remotefilters change content, never the destination
Not capture a packet type at allHook Settingsfilters act after the packet exists; turning it off at the source costs less
Just tidy up a noisy listLeach Settingfilters really do change data; using one as a display filter will damage live traffic
Send packets on your own scheduleSend Listfilters are reactive — with no match, nothing happens
Quick start // building a filter that actually fires

Filters are the only mechanism in WPE that changes real network data. Here is the shortest path from nothing to a working one.

  1. Catch a sample first: find the packet in the list, right-click → Add to Filter List, and the search row is prefilled from its content.
  2. Name the filter and tick the packet types it applies to — Send / Recv and friends in Inject Mode, TCP / UDP request and response in Proxy Mode.
  3. Write the search row: keep only the bytes that identify the packet uniquely; empty cells are wildcards. Fewer bytes match more easily, more bytes match more precisely.
  4. Write the modify row: put the new values at the right offsets. For values that should increment or vary, use the Progression and Random marks.
  5. Pick an action: Replace to edit bytes, Intercept to drop the packet, Change to rebuild it whole (see section 06).
  6. Save, turn the On switch on back in the list, then start capturing. Check the filter log and Statistics to confirm it really fires: the Runs column starts climbing, and matching packets change colour in the packet list.

01 · The life of a filter

01A packet's journey through the filter engine · eligibility first, then content matching, then the action.
a packet hits the hook or relay ① Eligibility checkenabled? type? socket / port / length / header? no skip this filter ② Content matchNormal: offsets · Advanced: sliding no match ③ Run the actionReplace / Change / Intercept / Display / Hidden ④ Chained execution (optional)Send / Robot / another filter / warehouse ⑤ Count +1, write the filter log the execution mode decides if matching continues next filter

02 · The Filter List

02The Filter List · toolbar, an execution-order note, and the table.
WPE x64 filter list: add / enable all / disable all / reset counts, the order note and the filter table
  1. Toolbar: New filter · Enable all · Disable all · Reset counts; Import / Export / Clear all at the right end
  2. The execution-order note: the badge on its left shows the mode actually in force (Run all matches / First match wins, switched under System Settings), and the sentence after it says what order means in that mode. ⚠️ Under "First match wins" the badge turns amber — order means something different there (only the first match runs)
  3. Columns: No. / On / Filter / Action / Runs / Conditions / Step / Actions
  4. The Action column is a single violet; what really is coloured by action is the matched row in the packet list — Replace = magenta · Change = amber · Intercept = red · Display = cyan, and those four palettes can be edited under System Settings · Action Colors (Hidden never reaches the list, so it has no colour)
  5. On is the only checkbox on this screen (every checkbox in WPE is green), and takes effect and is saved on click. Disabled rows are dimmed as a whole, except the checkbox cell
  6. Double-click a row to open the filter editor (so does the pencil at its end)
  7. ⚠️ This table deliberately cannot be sorted by its headers: the order is the data here (the engine walks it top to bottom by index), and sorting once would make the order on screen disagree with the order of execution. Use move to top / up / down / bottom from the context menu instead

Toolbar, left to right: New filter Enable all Disable all Reset counts; the three at the right end act on the whole table — Import (read a .fp), Export (write every filter to a .fp) and Clear all.

The context menu has seven items and they all act on the rows currently selected (the count is appended to each label): Move to top / Move up / Move down / Move to bottom / Export / Duplicate / Delete, plus Select all and Deselect. With nothing selected you get "Select the rows to act on first". Double-click opens the filter editor.

// Order matters

Under "Run all matches", list order is match order. When a filter does not seem to fire, try moving it to the top first.

Three ways to create a filter

  1. Filter List toolbar → New filter: creates an empty filter named Filter N (N being the current count plus one), mode Normal, action Replace, every packet type ticked and the On switch off.
  2. Right-click in the packet or proxy list → Add to filters: prefills the search row from that packet — much the easiest start.
  3. Select bytes in the hex panel or packet editor → right-click → Add to filters: fills from just that selection, for when you have already found the signature; with nothing selected the whole packet is used.

03 · The Filter Edit window

03Filter editor (normal mode) · parameters on top, the search/modify grid in the middle, conditions and progression below.
WPE x64 filter editor: mode, action, execute, modify-from, the search and modify grid, applies-to, conditions and progression
  1. Filter name: free text. A filter created from the packet list's "add to filters" is now named after the server address plus the packet length (e.g. 101.227.22.133:443 [180]), so you can tell at a glance which connection it came from
  2. Mode: Normal (search and modify share the same columns) or Advanced (the two positions are independent), see section 04. The grey line to the right changes with the mode and says exactly that
  3. Action: Replace / Change / Intercept / Display / Hidden — one of five, see section 06
  4. Execute: tick "Run on match", then pick the type on the left (Send List / Robot List / Filter List / WareHouse List) and the target on the right; both dropdowns are dimmed and disabled while it is off
  5. Modify from: advanced mode only (in normal mode it is dimmed but still visible, so you can see the option exists). "Packet head" counts from the first byte; "Given position" is an offset from the match point and may be negative
  6. SEARCH / MODIFY: in normal mode both rows live in one table aligned by column; in advanced mode SEARCH has a single row and MODIFY is a separate table with its own scrollbar. Columns start at 001 and run to 1000 (the row under the grid has a "Go to" box at its right end — type a number and it scrolls there)
  7. The three colour chips in that legend row are the cell marks: Mark exclude · Mark step · Mark random — toggled by right-clicking a cell, see section 05
  8. Applies to: a different set per mode — proxy mode offers TCP and UDP request/response (shown here), inject mode the eight WinSock categories. Tick at least one, or the filter can never match
  9. Conditions: Header / Socket / Length / Port. Only ticked ones count, and several of them are ANDed. The placeholders spell out the accepted syntax (e.g. 80 or 80-90, separate with ;) — saving checks the format and flags a mistake on the spot
  10. Step (progression): Continuous + Step, Carry + Carry at — it sits beside Conditions, two rows each. ⚠️ It only decides how the value grows; which byte it applies to comes from the cells marked "step" in the modify row. You need both
// Column number is not the index

Column 001 is byte index 0. Subtract one whenever you count offsets.

Packet extractors and dynamic replacement (2.5)

Packet Extractors, in the Rules group, save a field from a matching packet as a variable and let a later filter modification write it back. An extractor does not match packets by itself: a filter's extractor-assignment action triggers it. Variables can be constants, packet extractions or expressions; their type is integer, floating point, bytes or text.

  • Extraction reads at an absolute offset or relative to the current match. Integers support byte order and signed parsing; text supports UTF-8, GB18030 and Big5. An out-of-range read or conversion failure produces no value.
  • Scopes are global, socket and proxy session; the latter two can have a TTL. Runtime values exist only in the memory of the process handling packets, not in the database or backup.
  • Expressions may reference enabled variables (${extractor.variable:format}): numbers can calculate, bytes can concatenate and text can concatenate. Circular or unavailable references produce no writable value.
  • Dynamic replacement binds a modify cell to an extractor variable through its right-click menu and chooses an output format. Numeric values require an explicit width and byte order; no value is written when the variable is missing, disabled, unavailable or expired.
// Ordering tip

Place a filter that captures a value before a filter that consumes it. Within a matching packet, WPE captures values before rendering bound modify cells. Extractor configuration supports ordering, copy, import/export and backup.

04Extractor List · Manage names, enablement, scope, variable count and notes.
WPE x64 Extractor List with add, bulk enable, import/export and extractor rows
05Extractor Editor · Configure scope, variable type, extraction range, expressions and TTL.
WPE x64 Extractor Editor with variable configuration and packet extraction parameters
06Bind an extractor variable · Select a variable and output format from a filter modify cell.
WPE x64 extractor-variable binding dialog in the Filter Editor

04 · Normal versus Advanced

04How the two match · the same 4A 5B gives completely different results.
Packet content 01 00 4A 5B C3 7F 4A 5B D0 11 0123456789 Normal mode search row: col 003 = 4A, col 004 = 5B → checks indexes 2 and 3 only, 1 match (and only ever 1) match ignored Advanced mode search row: col 001 = 4A, col 002 = 5B (a relative sequence) → slides across the packet anchored on 4A, 2 matches match #1 match #2 "Modify from" picks the first match or every one ※ in Advanced mode with "Given position", modify columns are offsets from the anchor (-1000 to 999)
NormalAdvanced
Meaningmatch at fixed offsetsslide a signature across the packet
How many matchesevaluated oncecan match several times
Data gridone table, two rows (search / modify) sharing a scrollbar and aligned column by column, 001–1000two independent tables (one search row, one modify row), each with its own scrollbar; the modify table's column range follows "Modify from"
Modify offsetsabsolute"Packet head" is absolute; "Given position" is a relative offset, possibly negative
Use whenfields sit at fixed positionsfields move about, or headers vary in length

"Modify from" (Advanced only)

OptionWhat is processedWhat the modify columns mean
Packet head (default)the first match onlyabsolute indexes, starting at 0
Given positionevery matchoffsets relative to the anchor, which is 0 — negatives allowed

Wildcards

Search cells support nibble wildcards:

Written asMeansMask
4Aexactly the byte 0x4A0xFF
4*high nibble must be 4, low nibble anything0xF0
*Alow nibble must be A, high nibble anything0x0F
// Three limitations

① Normal-mode search cells do not accept * — the editor only lets you type 0-9 A-F there. Switch to Advanced to use wildcards in a search cell (modify cells accept them in both modes).
② Only two-character forms like X* and *X count as partial wildcards. A full ** is not added to the match conditions at all — it is the same as leaving the cell empty.
③ In Advanced mode the leftmost filled cell is the anchor: the engine slides it across the packet looking for a whole-byte equality, so a wildcard there is not relaxed nibble-wise. Keep wildcards for the cells after it.

05 · The three cell marks

Right-click a cell in the grid to toggle them; they are told apart by background colour. A row of matching colour chips sits under the grids, so a cell and its meaning line up at a glance; right-click again and choose "Unmark exclude" / "Clear mark" to undo. Step and Random are mutually exclusive — setting one clears the other; and an empty cell cannot be excluded ("Cannot set Exclude for Empty"), with the purple shading dropped again if you delete the value.

MarkRowColourMeaning
Excludesearchpurpleinverted: the byte matches when it differs from the value
Step (progression)modifydark redadds the step on every match, optionally carrying over
Randommodifybright bluewrites a random byte each time, guaranteed to differ from the old one; marking a cell random clears its value (a random cell needs no preset)
// Common mistake

Ticking Continuous without also right-clicking the modify cell and choosing "Mark step" does nothing. The checkbox picks how the value accumulates; the cell shading is what decides which byte it applies to.

How progression is calculated

For each step cell: new = old + step × (progression count + 1), taken modulo 256.

  • With Continuous ticked the count rises by one per match, so the value keeps climbing. Without it, the same increment is applied every time
  • With Carry ticked, a byte overflowing past 0xFF carries into the preceding bytes, across at most Carry at of them; it stops as soon as a byte produces no further carry
  • The progression count is not persisted: restarting the program, or pressing "Reset counts" on the list toolbar, zeroes it together with the run count

06 · The five actions

// Names used in older tutorials

"NoModify Display" and "NoModify NoDisplay" in older tutorials are Display and Hidden here, and filters converted from a .filt file map to these two.

ActionWhat it doesDefault colour of the matched row
Replacerewrites the matched bytes from the modify row, applying progression and random cells. The only action that lets matching continuedeep magenta on bright magenta text
Changediscards the original content and builds a new packet from the modify row, its length being the highest index plus onedeep amber on bright amber text
Interceptthe packet is dropped — never sent, never receiveddeep red on bright red text
Displaycontent untouched, but the packet is guaranteed to reach the list and the countersdeep cyan on bright cyan text
Hiddencontent untouched and kept out of the list — for silencing frequent heartbeats— (it never reaches the list)
// Those four palettes are configurable

The table shows the factory values of a freshly created database (dark ground plus bright text of the same hue, retuned for the dark skin). Click a swatch under System Settings · Action Colors to change the text and background. ⚠️ The colours are stored in the database, so an older database still holds the older set until you change it or switch to a new one.

// Change needs an unbroken modify row

Change replaces the packet wholesale with the modify row, so that row must be filled continuously from column 001: a gap in the middle — or a Random cell, since marking one clears its value — makes saving fail outright with "Change Error". The new packet is as long as the highest index in the modify row plus one. To keep the original content, use Replace.

Chained execution

Tick "run on match", then the left dropdown picks the type and the right one the target:

TypeTargetWhat happens on a match
Send Listone send itemruns that send immediately — auto-replies, canned sequences
Robot Listone robotstarts that robot, passing the current socket in as FilterSocket
Filter Listanother filterruns that filter as well — chained processing. The candidate list excludes this filter itself, since running itself would loop forever
WareHouse Listone warehousesaves the matched packet there — the rewritten version if it was changed

When the corresponding list is empty the right-hand dropdown reads "That list is empty" — create a send, robot or warehouse first, then come back.

07 · Filter execution mode

Switched under System Settings → Filter Execution → "On multiple matches":

ModeBehaviourUse when
Run all (default)walks every filter top to bottom. Replace lets matching continue, so later filters see the already-edited data; Intercept / Change / Display / Hidden return immediatelyseveral filters need to stack on one packet
First match winsthe first match wins and matching stops therethe rules are mutually exclusive and speed matters

08 · Filter log and statistics

Every match outside Speed Mode writes a log line: Time / Filter / Action / Matches / Type / Length. Read it under System Log → Filter Log, and export to Excel if needed. "Matches" is always 1 in Normal mode; in Advanced mode it is how many places in that packet matched.

The Statistical Data page shows progress bars for how much traffic filters touched and how the actions break down.

09 · Import, export and conversion

  • The native format is .fp — a filter list in XML, optionally encrypted
  • To convert from a legacy WPE .filt file, use the Data Extraction page, pick the Legacy FILT filter card (.filt → .fp), then read the generated .fp back with the Filter List's Import. The converter parses each line's 35 ¥-separated fields and maps out the filter name, the header / socket / length conditions, Normal or Advanced mode, the Replace / Intercept / Hidden / Display actions, the search and modify content, progression and the rest. Converted filters always arrive switched off — turn them on yourself after importing

10 · Five worked examples

Example 1 · pin a field to a fixed value

Goal: in every Send packet, change the fifth byte — index 4 — from 01 to 09.

  1. Add a filter and name it "Lock field".
  2. Mode = Normal; action = Replace.
  3. Tick packet type Send for Inject Mode, or TCP request for Proxy Mode.
  4. Grid: put 01 in column 005 of the search row, and 09 in column 005 of the modify row.
  5. Save, then switch it on in the list.

Example 2 · silence flooding heartbeats

Goal: keep packets with head 01 00 03 and a length of exactly 8 out of the list.

  1. Add a filter with action = Hidden.
  2. Under Conditions, tick Header and enter 01 00 03 (two digits per byte, spaces optional).
  3. Under Conditions, tick Length and enter 8.
  4. In the search row put 01 / 00 / 03 into columns 001 / 002 / 003.
// Do not skip that last step

Step 4 is not optional: a filter with an empty search row never matches. Setting only Conditions · Header is not enough — those four are preconditions; the actual matching is done by the search row.

Example 3 · follow a signature (Advanced mode)

Goal: wherever 4A 5B appears, set the second byte after it to FF.

  1. Mode = Advanced; action = Replace; Modify from = Given position.
  2. Search grid: 4A in 001, 5B in 002.
  3. Modify grid, relative: put FF at offset +3.
    The anchor 4A is offset 0, 5B is 1, the next byte is 2, and the one after that is 3.

Example 4 · an auto-incrementing counter

Goal: add one to byte 9 on every match, carrying across two bytes on overflow.

  1. Mode = Normal; action = Replace.
  2. In the Step group tick Continuous with a Step of 1, and tick Carry with Carry at 2.
  3. Right-click column 009 of the modify row → Mark step; the cell turns dark red.

Example 5 · auto-reply on a match

  1. First create a send item and add the reply packet to its collection.
  2. Create the filter with action Display — you only want the trigger, not an edit.
  3. Tick Run on match → choose Send List on the left → pick the send item you just created on the right.

11 · When a filter does not fire

// Work down this list

① Is the enable switch on in the Filter List?
② Is at least one packet type ticked, and does it match the packets you are after?
③ Did you tick Header / Socket / Length / Port under Conditions but enter a value the packets do not carry? All four are ANDed — one failing skips the whole filter (a malformed value is rejected when you save).
④ Is the search row empty? With nothing to search for, nothing ever matches.
⑤ In Normal mode, does an index run past the packet length? That counts as no match.
⑥ With the execution mode set to "First match wins", an earlier filter that matched takes the packet — try moving this one to the top.
⑦ Trying to edit an HTTP / HTTPS / WebSocket packet? Filters do not apply to those types — use Map Settings instead.

// Editing the wrong bytes

Column 001 is index 0. In Advanced mode with "Modify from → Given position", the modify columns are offsets relative to the anchor (the headers carry a sign, and 000 is the anchor itself), not absolute positions.