Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-netmon.c
Line
Count
Source
1
/* packet-netmon.c
2
 * Routines for Network Monitor capture dissection
3
 *
4
 * Wireshark - Network traffic analyzer
5
 * By Gerald Combs <gerald@wireshark.org>
6
 * Copyright 1998 Gerald Combs
7
 *
8
 * SPDX-License-Identifier: GPL-2.0-or-later
9
 *
10
 * Network Event Tracing event taken from:
11
 *
12
 * https://docs.microsoft.com/en-us/windows/win32/api/evntcons/ns-evntcons-event_header
13
 */
14
15
#include "config.h"
16
17
#include <epan/packet.h>
18
#include <epan/to_str.h>
19
#include <epan/expert.h>
20
#include <epan/tfs.h>
21
#include <wsutil/array.h>
22
#include <wiretap/wtap.h>
23
#include "packet-netmon.h"
24
25
void proto_register_netmon(void);
26
void proto_reg_handoff_netmon(void);
27
28
16
#define EVENT_HEADER_PROPERTY_XML               0x0001
29
16
#define EVENT_HEADER_PROPERTY_FORWARDED_XML     0x0002
30
16
#define EVENT_HEADER_PROPERTY_LEGACY_EVENTLOG   0x0004
31
32
static const value_string event_level_vals[] = {
33
  { 0,  "Log Always"},
34
  { 1,  "Critical"},
35
  { 2,  "Error"},
36
  { 3,  "Warning"},
37
  { 4,  "Info"},
38
  { 5,  "Verbose"},
39
  { 6,  "Reserved"},
40
  { 7,  "Reserved"},
41
  { 8,  "Reserved"},
42
  { 9,  "Reserved"},
43
  { 10, "Reserved"},
44
  { 11, "Reserved"},
45
  { 12, "Reserved"},
46
  { 13, "Reserved"},
47
  { 14, "Reserved"},
48
  { 15, "Reserved"},
49
  { 0,  NULL }
50
};
51
52
static const value_string opcode_vals[] = {
53
  { 0,  "Info"},
54
  { 1,  "Start"},
55
  { 2,  "Stop"},
56
  { 3,  "DC Start"},
57
  { 4,  "DC Stop"},
58
  { 5,  "Extension"},
59
  { 6,  "Reply"},
60
  { 7,  "Resume"},
61
  { 8,  "Suspend"},
62
  { 9,  "Transfer"},
63
  { 0,  NULL }
64
};
65
66
static const range_string filter_types[] = {
67
  { 0,  0,  "Display Filter" },
68
  { 1,  1,  "Capture Filter" },
69
  { 2,  0xFFFFFFFF, "Display Filter" },
70
  { 0, 0, NULL }
71
};
72
73
static dissector_table_t provider_id_table;
74
75
/* Initialize the protocol and registered fields */
76
static int proto_netmon_header;
77
static int proto_netmon_event;
78
static int proto_netmon_filter;
79
static int proto_netmon_network_info;
80
static int proto_netmon_system_trace;
81
static int proto_netmon_system_config;
82
static int proto_netmon_process;
83
84
static int hf_netmon_header_title_comment;
85
static int hf_netmon_header_description_comment;
86
87
static int hf_netmon_event_size;
88
static int hf_netmon_event_header_type;
89
static int hf_netmon_event_flags;
90
static int hf_netmon_event_flags_extended_info;
91
static int hf_netmon_event_flags_private_session;
92
static int hf_netmon_event_flags_string_only;
93
static int hf_netmon_event_flags_trace_message;
94
static int hf_netmon_event_flags_no_cputime;
95
static int hf_netmon_event_flags_32bit_header;
96
static int hf_netmon_event_flags_64bit_header;
97
static int hf_netmon_event_flags_classic_header;
98
static int hf_netmon_event_event_property;
99
static int hf_netmon_event_event_property_xml;
100
static int hf_netmon_event_event_property_forwarded_xml;
101
static int hf_netmon_event_event_property_legacy_eventlog;
102
static int hf_netmon_event_thread_id;
103
static int hf_netmon_event_process_id;
104
static int hf_netmon_event_timestamp;
105
static int hf_netmon_event_provider_id;
106
static int hf_netmon_event_event_desc_id;
107
static int hf_netmon_event_event_desc_version;
108
static int hf_netmon_event_event_desc_channel;
109
static int hf_netmon_event_event_desc_level;
110
static int hf_netmon_event_event_desc_opcode;
111
static int hf_netmon_event_event_desc_task;
112
static int hf_netmon_event_event_desc_keyword;
113
static int hf_netmon_event_kernel_time;
114
static int hf_netmon_event_user_time;
115
static int hf_netmon_event_processor_time;
116
static int hf_netmon_event_activity_id;
117
static int hf_netmon_event_processor_number;
118
static int hf_netmon_event_alignment;
119
static int hf_netmon_event_logger_id;
120
static int hf_netmon_event_extended_data_count;
121
static int hf_netmon_event_user_data_length;
122
static int hf_netmon_event_reassembled;
123
static int hf_netmon_event_extended_data_reserved;
124
static int hf_netmon_event_extended_data_type;
125
static int hf_netmon_event_extended_data_linkage;
126
static int hf_netmon_event_extended_data_reserved2;
127
static int hf_netmon_event_extended_data_size;
128
static int hf_netmon_event_extended_data;
129
static int hf_netmon_event_user_data;
130
131
static int hf_netmon_filter_version;
132
static int hf_netmon_filter_type;
133
static int hf_netmon_filter_app_major_version;
134
static int hf_netmon_filter_app_minor_version;
135
static int hf_netmon_filter_app_name;
136
static int hf_netmon_filter_filter;
137
138
static int hf_netmon_network_info_version;
139
static int hf_netmon_network_info_adapter_count;
140
static int hf_netmon_network_info_computer_name;
141
static int hf_netmon_network_info_friendly_name;
142
static int hf_netmon_network_info_description;
143
static int hf_netmon_network_info_miniport_guid;
144
static int hf_netmon_network_info_media_type;
145
static int hf_netmon_network_info_mtu;
146
static int hf_netmon_network_info_link_speed;
147
static int hf_netmon_network_info_mac_address;
148
static int hf_netmon_network_info_ipv4_count;
149
static int hf_netmon_network_info_ipv6_count;
150
static int hf_netmon_network_info_gateway_count;
151
static int hf_netmon_network_info_dhcp_server_count;
152
static int hf_netmon_network_info_dns_ipv4_count;
153
static int hf_netmon_network_info_dns_ipv6_count;
154
static int hf_netmon_network_info_ipv4;
155
static int hf_netmon_network_info_subnet;
156
static int hf_netmon_network_info_ipv6;
157
static int hf_netmon_network_info_gateway;
158
static int hf_netmon_network_info_dhcp_server;
159
static int hf_netmon_network_info_dns_ipv4;
160
static int hf_netmon_network_info_dns_ipv6;
161
162
static int hf_netmon_system_trace_buffer_size;
163
static int hf_netmon_system_trace_version;
164
static int hf_netmon_system_trace_provider_version;
165
static int hf_netmon_system_trace_num_processors;
166
static int hf_netmon_system_trace_end_time;
167
static int hf_netmon_system_trace_timer_resolution;
168
static int hf_netmon_system_trace_max_file_size;
169
static int hf_netmon_system_trace_log_file_mode;
170
static int hf_netmon_system_trace_buffers_written;
171
static int hf_netmon_system_trace_start_buffers;
172
static int hf_netmon_system_trace_pointers_size;
173
static int hf_netmon_system_trace_events_lost;
174
static int hf_netmon_system_trace_cpu_speed;
175
static int hf_netmon_system_trace_logger_name;
176
static int hf_netmon_system_trace_log_file_name_ptr;
177
static int hf_netmon_system_trace_time_zone_info;
178
static int hf_netmon_system_trace_boot_time;
179
static int hf_netmon_system_trace_perf_freq;
180
static int hf_netmon_system_trace_start_time;
181
static int hf_netmon_system_trace_reserved_flags;
182
static int hf_netmon_system_trace_buffers_lost;
183
static int hf_netmon_system_trace_session_name;
184
static int hf_netmon_system_trace_log_file_name;
185
static int hf_netmon_system_trace_group_mask1;
186
static int hf_netmon_system_trace_group_mask2;
187
static int hf_netmon_system_trace_group_mask3;
188
static int hf_netmon_system_trace_group_mask4;
189
static int hf_netmon_system_trace_group_mask5;
190
static int hf_netmon_system_trace_group_mask6;
191
static int hf_netmon_system_trace_group_mask7;
192
static int hf_netmon_system_trace_group_mask8;
193
static int hf_netmon_system_trace_kernel_event_version;
194
195
static int hf_netmon_system_config_mhz;
196
static int hf_netmon_system_config_num_processors;
197
static int hf_netmon_system_config_mem_size;
198
static int hf_netmon_system_config_page_size;
199
static int hf_netmon_system_config_allocation_granularity;
200
static int hf_netmon_system_config_computer_name;
201
static int hf_netmon_system_config_domain_name;
202
static int hf_netmon_system_config_hyper_threading_flag;
203
static int hf_netmon_system_config_disk_number;
204
static int hf_netmon_system_config_bytes_per_sector;
205
static int hf_netmon_system_config_sectors_per_track;
206
static int hf_netmon_system_config_tracks_per_cylinder;
207
static int hf_netmon_system_config_cylinders;
208
static int hf_netmon_system_config_scsi_port;
209
static int hf_netmon_system_config_scsi_path;
210
static int hf_netmon_system_config_scsi_target;
211
static int hf_netmon_system_config_scsi_lun;
212
static int hf_netmon_system_config_manufacturer;
213
static int hf_netmon_system_config_partition_count;
214
static int hf_netmon_system_config_write_cache_enabled;
215
static int hf_netmon_system_config_pad;
216
static int hf_netmon_system_config_boot_drive_letter;
217
static int hf_netmon_system_config_spare;
218
static int hf_netmon_system_config_start_offset;
219
static int hf_netmon_system_config_partition_size;
220
static int hf_netmon_system_config_size;
221
static int hf_netmon_system_config_drive_type;
222
static int hf_netmon_system_config_drive_letter;
223
static int hf_netmon_system_config_partition_number;
224
static int hf_netmon_system_config_sectors_per_cluster;
225
static int hf_netmon_system_config_num_free_clusters;
226
static int hf_netmon_system_config_total_num_clusters;
227
static int hf_netmon_system_config_file_system;
228
static int hf_netmon_system_config_volume_ext;
229
static int hf_netmon_system_config_physical_addr;
230
static int hf_netmon_system_config_physical_addr_len;
231
static int hf_netmon_system_config_ipv4_index;
232
static int hf_netmon_system_config_ipv6_index;
233
static int hf_netmon_system_config_nic_description;
234
static int hf_netmon_system_config_ipaddresses;
235
static int hf_netmon_system_config_dns_server_addresses;
236
static int hf_netmon_system_config_memory_size;
237
static int hf_netmon_system_config_x_resolution;
238
static int hf_netmon_system_config_y_resolution;
239
static int hf_netmon_system_config_bits_per_pixel;
240
static int hf_netmon_system_config_vrefresh;
241
static int hf_netmon_system_config_chip_type;
242
static int hf_netmon_system_config_dac_type;
243
static int hf_netmon_system_config_adapter_string;
244
static int hf_netmon_system_config_bios_string;
245
static int hf_netmon_system_config_device_id;
246
static int hf_netmon_system_config_state_flags;
247
static int hf_netmon_system_config_process_id;
248
static int hf_netmon_system_config_service_state;
249
static int hf_netmon_system_config_sub_process_tag;
250
static int hf_netmon_system_config_service_name;
251
static int hf_netmon_system_config_display_name;
252
static int hf_netmon_system_config_process_name;
253
static int hf_netmon_system_config_s1;
254
static int hf_netmon_system_config_s2;
255
static int hf_netmon_system_config_s3;
256
static int hf_netmon_system_config_s4;
257
static int hf_netmon_system_config_s5;
258
static int hf_netmon_system_config_tcb_table_partitions;
259
static int hf_netmon_system_config_max_hash_table_size;
260
static int hf_netmon_system_config_max_user_port;
261
static int hf_netmon_system_config_tcp_timed_wait_delay;
262
static int hf_netmon_system_config_irq_affinity;
263
static int hf_netmon_system_config_irq_num;
264
static int hf_netmon_system_config_device_desc_len;
265
static int hf_netmon_system_config_device_desc;
266
static int hf_netmon_system_config_device_id_len;
267
static int hf_netmon_system_config_friendly_name_len;
268
static int hf_netmon_system_config_friendly_name;
269
static int hf_netmon_system_config_target_id;
270
static int hf_netmon_system_config_device_type;
271
static int hf_netmon_system_config_device_timing_mode;
272
static int hf_netmon_system_config_location_information_len;
273
static int hf_netmon_system_config_location_information;
274
static int hf_netmon_system_config_system_manufacturer;
275
static int hf_netmon_system_config_system_product_name;
276
static int hf_netmon_system_config_bios_date;
277
static int hf_netmon_system_config_bios_version;
278
static int hf_netmon_system_config_load_order_group;
279
static int hf_netmon_system_config_svc_host_group;
280
static int hf_netmon_system_config_irq_group;
281
static int hf_netmon_system_config_pdo_name;
282
static int hf_netmon_system_config_nic_name;
283
static int hf_netmon_system_config_index;
284
static int hf_netmon_system_config_physical_addr_str;
285
static int hf_netmon_system_config_ip_address;
286
static int hf_netmon_system_config_subnet_mask;
287
static int hf_netmon_system_config_dhcp_server;
288
static int hf_netmon_system_config_gateway;
289
static int hf_netmon_system_config_primary_wins_server;
290
static int hf_netmon_system_config_secondary_wins_server;
291
static int hf_netmon_system_config_dns_server1;
292
static int hf_netmon_system_config_dns_server2;
293
static int hf_netmon_system_config_dns_server3;
294
static int hf_netmon_system_config_dns_server4;
295
static int hf_netmon_system_config_data;
296
297
298
299
static int hf_netmon_process_unique_process_key;
300
static int hf_netmon_process_process_id;
301
static int hf_netmon_process_parent_id;
302
static int hf_netmon_process_session_id;
303
static int hf_netmon_process_exit_status;
304
static int hf_netmon_process_directory_table_base;
305
static int hf_netmon_process_unknown;
306
static int hf_netmon_process_user_sid_revision;
307
static int hf_netmon_process_user_sid_subauth_count;
308
static int hf_netmon_process_user_sid_id;
309
static int hf_netmon_process_user_sid_authority;
310
static int hf_netmon_process_image_file_name;
311
static int hf_netmon_process_command_line;
312
static int hf_netmon_process_page_directory_base;
313
static int hf_netmon_process_page_fault_count;
314
static int hf_netmon_process_handle_count;
315
static int hf_netmon_process_reserved;
316
static int hf_netmon_process_peak_virtual_size;
317
static int hf_netmon_process_peak_working_set_size;
318
static int hf_netmon_process_peak_page_file_usage;
319
static int hf_netmon_process_quota_peak_paged_pool_usage;
320
static int hf_netmon_process_quota_peak_non_paged_pool_usage;
321
static int hf_netmon_process_virtual_size;
322
static int hf_netmon_process_workingset_size;
323
static int hf_netmon_process_pagefile_usage;
324
static int hf_netmon_process_quota_paged_pool_usage;
325
static int hf_netmon_process_quota_non_paged_pool_usage;
326
static int hf_netmon_process_private_page_count;
327
static int hf_netmon_process_directory_table_base32;
328
329
330
static int ett_netmon_header;
331
static int ett_netmon_event;
332
static int ett_netmon_event_desc;
333
static int ett_netmon_event_flags;
334
static int ett_netmon_event_property;
335
static int ett_netmon_event_extended_data;
336
static int ett_netmon_filter;
337
static int ett_netmon_network_info;
338
static int ett_netmon_network_info_list;
339
static int ett_netmon_network_info_adapter;
340
static int ett_netmon_system_trace;
341
static int ett_netmon_event_buffer_context;
342
static int ett_netmon_process;
343
static int ett_netmon_sid;
344
static int ett_netmon_system_config;
345
346
static expert_field ei_netmon_process_user_sid;
347
348
static dissector_table_t wtap_encap_table;
349
350
void
351
netmon_etl_field(proto_tree *tree, tvbuff_t *tvb, unsigned* offset, int hf, uint16_t flags)
352
0
{
353
0
  if (flags & EVENT_HEADER_FLAG_64_BIT_HEADER) {
354
    /* XXX - This seems to be how values are displayed in Network Monitor */
355
0
    uint64_t value = tvb_get_letoh64(tvb, *offset) & 0xFFFFFFFF;
356
0
    proto_tree_add_uint64(tree, hf, tvb, *offset, 8, value);
357
0
    (*offset) += 8;
358
0
  } else {
359
0
    proto_tree_add_item(tree, hf, tvb, *offset, 4, ENC_LITTLE_ENDIAN);
360
0
    (*offset) += 4;
361
0
  }
362
0
}
363
364
void
365
netmon_sid_field(proto_tree *tree, tvbuff_t *tvb, unsigned* offset, packet_info *pinfo,
366
        int hf_revision, int hf_subauthority_count, int hf_sid_id, int hf_sid_authority, expert_field* invalid_sid, bool conformant _U_)
367
0
{
368
0
  proto_item *ti, *sid_item;
369
0
  proto_tree *sid_tree;
370
0
  int start_offset = *offset;
371
0
  uint32_t i, revision, count;
372
373
0
  sid_tree = proto_tree_add_subtree(tree, tvb, *offset, 2, ett_netmon_sid, &sid_item, "SID");
374
375
0
  ti = proto_tree_add_item_ret_uint(sid_tree, hf_revision, tvb, *offset, 1, ENC_LITTLE_ENDIAN, &revision);
376
0
  (*offset) += 1;
377
0
  if (revision != 1)
378
0
  {
379
0
    expert_add_info(pinfo, ti, invalid_sid);
380
0
  }
381
0
  proto_tree_add_item_ret_uint(sid_tree, hf_subauthority_count, tvb, *offset, 1, ENC_LITTLE_ENDIAN, &count);
382
0
  (*offset) += 1;
383
0
  if (count > 15)
384
0
  {
385
0
    expert_add_info(pinfo, ti, invalid_sid);
386
0
  }
387
388
0
  proto_tree_add_item(sid_tree, hf_sid_id, tvb, *offset, 6, ENC_NA);
389
0
  (*offset) += 6;
390
391
0
  for (i = 0; i < count; i++)
392
0
  {
393
0
    proto_tree_add_item(sid_tree, hf_sid_authority, tvb, *offset, 4, ENC_LITTLE_ENDIAN);
394
0
    (*offset) += 4;
395
0
  }
396
397
0
  proto_item_set_len(sid_item, (*offset)-start_offset);
398
0
}
399
400
/* Code to actually dissect the packets */
401
static int
402
dissect_netmon_header(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
403
0
{
404
0
  proto_item *ti;
405
0
  proto_tree *header_tree;
406
0
  union wtap_pseudo_header temp_header;
407
0
  char *comment;
408
409
0
  ti = proto_tree_add_item(tree, proto_netmon_header, tvb, 0, 0, ENC_NA);
410
0
  header_tree = proto_item_add_subtree(ti, ett_netmon_header);
411
412
0
  if (pinfo->pseudo_header->netmon.title != NULL) {
413
0
    ti = proto_tree_add_string(header_tree, hf_netmon_header_title_comment, tvb, 0, 0, (char*)pinfo->pseudo_header->netmon.title);
414
0
    proto_item_set_generated(ti);
415
0
  }
416
417
0
  if (pinfo->pseudo_header->netmon.description != NULL) {
418
    /* Description comment is only ASCII.  However, it's
419
     * RTF, not raw text.
420
     */
421
422
    /* Ensure string termination */
423
0
    comment = wmem_strndup(pinfo->pool, (char*)pinfo->pseudo_header->netmon.description, pinfo->pseudo_header->netmon.descLength);
424
425
0
    ti = proto_tree_add_string(header_tree, hf_netmon_header_description_comment, tvb, 0, 0, comment);
426
0
    proto_item_set_generated(ti);
427
0
  }
428
429
  /* Save the pseudo header data to a temp variable before it's copied to
430
   * real pseudo header
431
   */
432
0
  switch (pinfo->pseudo_header->netmon.sub_encap)
433
0
  {
434
0
  case WTAP_ENCAP_ATM_PDUS:
435
0
    memcpy(&temp_header.atm, &pinfo->pseudo_header->netmon.subheader.atm, sizeof(temp_header.atm));
436
0
    memcpy(&pinfo->pseudo_header->atm, &temp_header.atm, sizeof(temp_header.atm));
437
0
    break;
438
0
  case WTAP_ENCAP_ETHERNET:
439
0
    memcpy(&temp_header.eth, &pinfo->pseudo_header->netmon.subheader.eth, sizeof(temp_header.eth));
440
0
    memcpy(&pinfo->pseudo_header->eth, &temp_header.eth, sizeof(temp_header.eth));
441
0
    break;
442
0
  case WTAP_ENCAP_IEEE_802_11_NETMON:
443
0
    memcpy(&temp_header.ieee_802_11, &pinfo->pseudo_header->netmon.subheader.ieee_802_11, sizeof(temp_header.ieee_802_11));
444
0
    memcpy(&pinfo->pseudo_header->ieee_802_11, &temp_header.ieee_802_11, sizeof(temp_header.ieee_802_11));
445
0
    break;
446
0
  }
447
448
0
  if (!dissector_try_uint_with_data(wtap_encap_table,
449
0
    pinfo->pseudo_header->netmon.sub_encap, tvb, pinfo, tree, true,
450
0
    (void *)pinfo->pseudo_header)) {
451
0
    call_data_dissector(tvb, pinfo, tree);
452
0
  }
453
454
0
  return tvb_captured_length(tvb);
455
0
}
456
457
static int
458
dissect_netmon_event(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
459
0
{
460
0
  proto_item *ti, *extended_data_item;
461
0
  proto_tree *event_tree, *event_desc_tree, *extended_data_tree, *buffer_context_tree;
462
0
  int offset = 0, extended_data_count_offset;
463
0
  uint32_t i, thread_id, process_id, extended_data_count, extended_data_size, user_data_size;
464
0
  tvbuff_t *provider_id_tvb;
465
0
  guid_key provider_guid;
466
0
  struct netmon_provider_id_data provider_id_data;
467
0
  static int * const event_flags[] = {
468
0
    &hf_netmon_event_flags_extended_info,
469
0
    &hf_netmon_event_flags_private_session,
470
0
    &hf_netmon_event_flags_string_only,
471
0
    &hf_netmon_event_flags_trace_message,
472
0
    &hf_netmon_event_flags_no_cputime,
473
0
    &hf_netmon_event_flags_32bit_header,
474
0
    &hf_netmon_event_flags_64bit_header,
475
0
    &hf_netmon_event_flags_classic_header,
476
0
    NULL
477
0
  };
478
0
  static int * const event_property[] = {
479
0
    &hf_netmon_event_event_property_xml,
480
0
    &hf_netmon_event_event_property_forwarded_xml,
481
0
    &hf_netmon_event_event_property_legacy_eventlog,
482
0
    NULL
483
0
  };
484
485
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon Event");
486
  /* Clear out stuff in the info column */
487
0
  col_clear(pinfo->cinfo, COL_INFO);
488
489
0
  memset(&provider_id_data, 0, sizeof(provider_id_data));
490
491
0
  ti = proto_tree_add_item(tree, proto_netmon_event, tvb, offset, -1, ENC_NA);
492
0
  event_tree = proto_item_add_subtree(ti, ett_netmon_event);
493
494
0
  proto_tree_add_item(event_tree, hf_netmon_event_size, tvb, offset, 2, ENC_LITTLE_ENDIAN);
495
0
  offset += 2;
496
0
  proto_tree_add_item(event_tree, hf_netmon_event_header_type, tvb, offset, 2, ENC_LITTLE_ENDIAN);
497
0
  offset += 2;
498
0
  provider_id_data.event_flags = tvb_get_letohs(tvb, offset);
499
0
  proto_tree_add_bitmask(event_tree, tvb, offset, hf_netmon_event_flags, ett_netmon_event_flags, event_flags, ENC_LITTLE_ENDIAN);
500
0
  offset += 2;
501
0
  proto_tree_add_bitmask(event_tree, tvb, offset, hf_netmon_event_event_property, ett_netmon_event_property, event_property, ENC_LITTLE_ENDIAN);
502
0
  offset += 2;
503
0
  proto_tree_add_item_ret_uint(event_tree, hf_netmon_event_thread_id, tvb, offset, 4, ENC_LITTLE_ENDIAN, &thread_id);
504
0
  offset += 4;
505
0
  proto_tree_add_item_ret_uint(event_tree, hf_netmon_event_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN, &process_id);
506
0
  offset += 4;
507
508
0
  proto_tree_add_item(event_tree, hf_netmon_event_timestamp, tvb, offset, 8, ENC_TIME_WINDOWS|ENC_LITTLE_ENDIAN);
509
0
  offset += 8;
510
511
0
  proto_tree_add_item(event_tree, hf_netmon_event_provider_id, tvb, offset, 16, ENC_LITTLE_ENDIAN);
512
  /* Save the GUID to use in dissector table */
513
0
  tvb_memcpy(tvb, &provider_guid.guid, offset, 16);
514
0
  provider_guid.ver = 0; //version field not used
515
0
  offset += 16;
516
517
0
  col_add_fstr(pinfo->cinfo, COL_INFO, "Thread ID: %d, Process ID: %d, Provider ID: %s",
518
0
                    thread_id, process_id, guid_to_str(pinfo->pool, &provider_guid.guid));
519
520
0
  event_desc_tree = proto_tree_add_subtree(event_tree, tvb, offset, 16, ett_netmon_event_desc, NULL, "Event Descriptor");
521
0
  proto_tree_add_item_ret_uint(event_desc_tree, hf_netmon_event_event_desc_id, tvb, offset, 2, ENC_LITTLE_ENDIAN, &provider_id_data.event_id);
522
0
  offset += 2;
523
0
  provider_id_data.event_version = tvb_get_uint8(tvb, offset);
524
0
  proto_tree_add_item(event_desc_tree, hf_netmon_event_event_desc_version, tvb, offset, 1, ENC_LITTLE_ENDIAN);
525
0
  offset += 1;
526
0
  proto_tree_add_item(event_desc_tree, hf_netmon_event_event_desc_channel, tvb, offset, 1, ENC_LITTLE_ENDIAN);
527
0
  offset += 1;
528
0
  proto_tree_add_item(event_desc_tree, hf_netmon_event_event_desc_level, tvb, offset, 1, ENC_LITTLE_ENDIAN);
529
0
  offset += 1;
530
0
  provider_id_data.opcode = tvb_get_uint8(tvb, offset);
531
0
  proto_tree_add_item(event_desc_tree, hf_netmon_event_event_desc_opcode, tvb, offset, 1, ENC_LITTLE_ENDIAN);
532
0
  offset += 1;
533
0
  proto_tree_add_item(event_desc_tree, hf_netmon_event_event_desc_task, tvb, offset, 2, ENC_LITTLE_ENDIAN);
534
0
  offset += 2;
535
0
  proto_tree_add_item_ret_uint64(event_desc_tree, hf_netmon_event_event_desc_keyword, tvb, offset, 8, ENC_LITTLE_ENDIAN, &provider_id_data.keyword);
536
0
  offset += 8;
537
538
0
  if (provider_id_data.event_flags & (EVENT_HEADER_FLAG_PRIVATE_SESSION | EVENT_HEADER_FLAG_NO_CPUTIME))
539
0
  {
540
    /* Kernel and User time are a union with processor time */
541
0
    proto_tree_add_item(event_tree, hf_netmon_event_kernel_time, tvb, offset, 4, ENC_LITTLE_ENDIAN);
542
0
    offset += 4;
543
0
    proto_tree_add_item(event_tree, hf_netmon_event_user_time, tvb, offset, 4, ENC_LITTLE_ENDIAN);
544
0
    offset += 4;
545
0
  }
546
0
  else
547
0
  {
548
0
    proto_tree_add_item(event_tree, hf_netmon_event_processor_time, tvb, offset, 8, ENC_LITTLE_ENDIAN);
549
0
    offset += 8;
550
0
  }
551
552
0
  proto_tree_add_item(event_tree, hf_netmon_event_activity_id, tvb, offset, 16, ENC_LITTLE_ENDIAN);
553
0
  offset += 16;
554
555
0
  buffer_context_tree = proto_tree_add_subtree(event_tree, tvb, offset, 4, ett_netmon_event_buffer_context, NULL, "BufferContext");
556
0
  proto_tree_add_item(buffer_context_tree, hf_netmon_event_processor_number, tvb, offset, 1, ENC_LITTLE_ENDIAN);
557
0
  offset += 1;
558
0
  proto_tree_add_item(buffer_context_tree, hf_netmon_event_alignment, tvb, offset, 1, ENC_LITTLE_ENDIAN);
559
0
  offset += 1;
560
0
  proto_tree_add_item(buffer_context_tree, hf_netmon_event_logger_id, tvb, offset, 2, ENC_LITTLE_ENDIAN);
561
0
  offset += 2;
562
563
0
  proto_tree_add_item_ret_uint(event_tree, hf_netmon_event_extended_data_count, tvb, offset, 2, ENC_LITTLE_ENDIAN, &extended_data_count);
564
0
  offset += 2;
565
0
  proto_tree_add_item_ret_uint(event_tree, hf_netmon_event_user_data_length, tvb, offset, 2, ENC_LITTLE_ENDIAN, &user_data_size);
566
0
  offset += 2;
567
0
  proto_tree_add_item(event_tree, hf_netmon_event_reassembled, tvb, offset, 1, ENC_LITTLE_ENDIAN);
568
0
  offset += 1;
569
570
0
  for (i = 1; i <= extended_data_count; i++)
571
0
  {
572
0
    extended_data_count_offset = offset;
573
0
    extended_data_tree = proto_tree_add_subtree_format(event_tree, tvb, offset, 4, ett_netmon_event_extended_data, &extended_data_item, "Extended Data Item #%d", i);
574
0
    proto_tree_add_item(extended_data_tree, hf_netmon_event_extended_data_reserved, tvb, offset, 2, ENC_LITTLE_ENDIAN);
575
0
    offset += 2;
576
0
    proto_tree_add_item(extended_data_tree, hf_netmon_event_extended_data_type, tvb, offset, 2, ENC_LITTLE_ENDIAN);
577
0
    offset += 2;
578
0
    proto_tree_add_item(extended_data_tree, hf_netmon_event_extended_data_linkage, tvb, offset, 2, ENC_LITTLE_ENDIAN);
579
0
    proto_tree_add_item(extended_data_tree, hf_netmon_event_extended_data_reserved2, tvb, offset, 2, ENC_LITTLE_ENDIAN);
580
0
    offset += 2;
581
0
    proto_tree_add_item_ret_uint(extended_data_tree, hf_netmon_event_extended_data_size, tvb, offset, 2, ENC_LITTLE_ENDIAN, &extended_data_size);
582
0
    offset += 2;
583
0
    proto_tree_add_item(extended_data_tree, hf_netmon_event_extended_data, tvb, offset, extended_data_size, ENC_NA);
584
0
    offset += extended_data_size;
585
0
    proto_item_set_len(extended_data_item, offset-extended_data_count_offset);
586
0
  }
587
588
0
  provider_id_tvb = tvb_new_subset_remaining(tvb, offset);
589
0
  if (!dissector_try_guid_with_data(provider_id_table, &provider_guid, provider_id_tvb, pinfo, tree, true, &provider_id_data))
590
0
  {
591
0
    proto_tree_add_item(event_tree, hf_netmon_event_user_data, tvb, offset, user_data_size, ENC_NA);
592
0
    offset += user_data_size;
593
0
  }
594
0
  proto_item_set_len(ti, offset);
595
0
  return tvb_captured_length(tvb);
596
0
}
597
598
599
static int
600
dissect_netmon_filter(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
601
0
{
602
0
  proto_item *ti;
603
0
  proto_tree *filter_tree;
604
0
  unsigned offset = 0;
605
0
  unsigned length;
606
0
  const uint8_t* filter;
607
608
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon Filter");
609
  /* Clear out stuff in the info column */
610
0
  col_clear(pinfo->cinfo, COL_INFO);
611
612
0
  ti = proto_tree_add_item(tree, proto_netmon_filter, tvb, offset, -1, ENC_NA);
613
0
  filter_tree = proto_item_add_subtree(ti, ett_netmon_filter);
614
615
0
  proto_tree_add_item(filter_tree, hf_netmon_filter_version, tvb, offset, 2, ENC_BIG_ENDIAN);
616
0
  offset += 2;
617
0
  proto_tree_add_item(filter_tree, hf_netmon_filter_type, tvb, offset, 4, ENC_BIG_ENDIAN);
618
0
  offset += 4;
619
0
  proto_tree_add_item(filter_tree, hf_netmon_filter_app_major_version, tvb, offset, 4, ENC_BIG_ENDIAN);
620
0
  offset += 4;
621
0
  proto_tree_add_item(filter_tree, hf_netmon_filter_app_minor_version, tvb, offset, 4, ENC_BIG_ENDIAN);
622
0
  offset += 4;
623
0
  length = tvb_unicode_strsize(tvb, offset);
624
0
  proto_tree_add_item(filter_tree, hf_netmon_filter_app_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
625
0
  offset += length;
626
0
  length = tvb_unicode_strsize(tvb, offset);
627
0
  proto_tree_add_item_ret_string(filter_tree, hf_netmon_filter_filter, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16,
628
0
                  pinfo->pool, &filter);
629
0
  col_add_fstr(pinfo->cinfo, COL_INFO, "Filter: %s", filter);
630
631
0
  return tvb_captured_length(tvb);
632
0
}
633
634
635
static int
636
dissect_netmon_network_info(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
637
0
{
638
0
  proto_item *ti, *list_item, *adapter_item;
639
0
  proto_tree *network_info_tree, *list_tree, *adapter_tree;
640
0
  int offset = 0, list_start_offset, adapter_start_offset;
641
0
  unsigned adapter, adapter_count, length;
642
0
  uint64_t link_speed;
643
644
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon Network Info");
645
  /* Clear out stuff in the info column */
646
0
  col_clear(pinfo->cinfo, COL_INFO);
647
648
0
  ti = proto_tree_add_item(tree, proto_netmon_network_info, tvb, offset, -1, ENC_NA);
649
0
  network_info_tree = proto_item_add_subtree(ti, ett_netmon_network_info);
650
651
0
  proto_tree_add_item(network_info_tree, hf_netmon_network_info_version, tvb, offset, 2, ENC_BIG_ENDIAN);
652
0
  offset += 2;
653
654
0
  proto_tree_add_item_ret_uint(network_info_tree, hf_netmon_network_info_adapter_count, tvb, offset, 2, ENC_BIG_ENDIAN, &adapter_count);
655
0
  offset += 2;
656
0
  col_add_fstr(pinfo->cinfo, COL_INFO, "Adapter count: %d", adapter_count);
657
658
0
  length = tvb_unicode_strsize(tvb, offset);
659
0
  proto_tree_add_item(network_info_tree, hf_netmon_network_info_computer_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
660
0
  offset += length;
661
0
  if (adapter_count > 0)
662
0
  {
663
0
    list_start_offset = offset;
664
0
    list_tree = proto_tree_add_subtree(network_info_tree, tvb, offset, 1, ett_netmon_network_info_list, &list_item, "NetworkInfo");
665
0
    for (adapter = 1; adapter <= adapter_count; adapter++)
666
0
    {
667
0
      uint32_t loop, ipv4_count, ipv6_count, gateway_count, dhcp_server_count, dns_ipv4_count, dns_ipv6_count;
668
669
0
      adapter_start_offset = offset;
670
0
      adapter_tree = proto_tree_add_subtree_format(list_tree, tvb, offset, 1, ett_netmon_network_info_adapter, &adapter_item, "Adapter #%d", adapter);
671
672
0
      length = tvb_unicode_strsize(tvb, offset);
673
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_friendly_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
674
0
      offset += length;
675
0
      length = tvb_unicode_strsize(tvb, offset);
676
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_description, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
677
0
      offset += length;
678
0
      length = tvb_unicode_strsize(tvb, offset);
679
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_miniport_guid, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
680
0
      offset += length;
681
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_media_type, tvb, offset, 4, ENC_BIG_ENDIAN);
682
0
      offset += 4;
683
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_mtu, tvb, offset, 4, ENC_BIG_ENDIAN);
684
0
      offset += 4;
685
0
      link_speed = tvb_get_ntoh64(tvb, offset);
686
0
      if (link_speed == 0xFFFFFFFFFFFFFFFF)
687
0
      {
688
0
          proto_tree_add_uint64_format_value(adapter_tree, hf_netmon_network_info_link_speed, tvb, offset, 8, link_speed, "(Unknown)");
689
0
      }
690
0
      else if (link_speed >= 1000 * 1000 * 1000)
691
0
      {
692
0
          proto_tree_add_uint64_format_value(adapter_tree, hf_netmon_network_info_link_speed, tvb, offset, 8, link_speed, "%" PRIu64 " Gbps", link_speed/(1000*1000*1000));
693
0
      }
694
0
      else if (link_speed >= 1000 * 1000)
695
0
      {
696
0
          proto_tree_add_uint64_format_value(adapter_tree, hf_netmon_network_info_link_speed, tvb, offset, 8, link_speed, "%" PRIu64 " Mbps", link_speed/(1000*1000));
697
0
      }
698
0
      else if (link_speed >= 1000)
699
0
      {
700
0
          proto_tree_add_uint64_format_value(adapter_tree, hf_netmon_network_info_link_speed, tvb, offset, 8, link_speed, "%" PRIu64 " Kbps", link_speed/1000);
701
0
      }
702
0
      else
703
0
      {
704
0
          proto_tree_add_uint64_format_value(adapter_tree, hf_netmon_network_info_link_speed, tvb, offset, 8, link_speed, "%" PRIu64 " bps", link_speed);
705
0
      }
706
0
      offset += 8;
707
0
      proto_tree_add_item(adapter_tree, hf_netmon_network_info_mac_address, tvb, offset, 6, ENC_NA);
708
0
      offset += 6;
709
710
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_ipv4_count, tvb, offset, 2, ENC_BIG_ENDIAN, &ipv4_count);
711
0
      offset += 2;
712
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_ipv6_count, tvb, offset, 2, ENC_BIG_ENDIAN, &ipv6_count);
713
0
      offset += 2;
714
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_gateway_count, tvb, offset, 2, ENC_BIG_ENDIAN, &gateway_count);
715
0
      offset += 2;
716
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_dhcp_server_count, tvb, offset, 2, ENC_BIG_ENDIAN, &dhcp_server_count);
717
0
      offset += 2;
718
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_dns_ipv4_count, tvb, offset, 2, ENC_BIG_ENDIAN, &dns_ipv4_count);
719
0
      offset += 2;
720
0
      proto_tree_add_item_ret_uint(adapter_tree, hf_netmon_network_info_dns_ipv6_count, tvb, offset, 2, ENC_BIG_ENDIAN, &dns_ipv6_count);
721
0
      offset += 2;
722
723
0
      for (loop = 0; loop < ipv4_count; loop++)
724
0
      {
725
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_ipv4, tvb, offset, 4, ENC_BIG_ENDIAN);
726
0
        offset += 4;
727
0
      }
728
0
      for (loop = 0; loop < ipv4_count; loop++)
729
0
      {
730
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_subnet, tvb, offset, 4, ENC_BIG_ENDIAN);
731
0
        offset += 4;
732
0
      }
733
0
      for (loop = 0; loop < ipv6_count; loop++)
734
0
      {
735
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_ipv6, tvb, offset, 16, ENC_NA);
736
0
        offset += 16;
737
0
      }
738
0
      for (loop = 0; loop < gateway_count; loop++)
739
0
      {
740
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_gateway, tvb, offset, 4, ENC_BIG_ENDIAN);
741
0
        offset += 4;
742
0
      }
743
0
      for (loop = 0; loop < dhcp_server_count; loop++)
744
0
      {
745
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_dhcp_server, tvb, offset, 4, ENC_BIG_ENDIAN);
746
0
        offset += 4;
747
0
      }
748
0
      for (loop = 0; loop < dns_ipv4_count; loop++)
749
0
      {
750
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_dns_ipv4, tvb, offset, 4, ENC_BIG_ENDIAN);
751
0
        offset += 4;
752
0
      }
753
0
      for (loop = 0; loop < dns_ipv6_count; loop++)
754
0
      {
755
0
        proto_tree_add_item(adapter_tree, hf_netmon_network_info_dns_ipv6, tvb, offset, 16, ENC_NA);
756
0
        offset += 16;
757
0
      }
758
759
0
      proto_item_set_len(adapter_item, offset-adapter_start_offset);
760
0
    }
761
762
0
    proto_item_set_len(list_item, offset-list_start_offset);
763
0
  }
764
765
0
  return tvb_captured_length(tvb);
766
0
}
767
768
static int
769
dissect_netmon_system_trace(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
770
0
{
771
0
  proto_item *ti;
772
0
  proto_tree *system_tree;
773
0
  unsigned offset = 0;
774
0
  struct netmon_provider_id_data *provider_id_data = (struct netmon_provider_id_data*)data;
775
0
  unsigned length;
776
0
  nstime_t timestamp = NSTIME_INIT_ZERO;
777
0
  uint64_t raw_timestamp;
778
779
0
  DISSECTOR_ASSERT(provider_id_data != NULL);
780
781
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon System Trace");
782
0
  col_clear(pinfo->cinfo, COL_INFO);
783
784
0
  ti = proto_tree_add_item(tree, proto_netmon_system_trace, tvb, 0, -1, ENC_NA);
785
0
  system_tree = proto_item_add_subtree(ti, ett_netmon_system_trace);
786
787
0
  switch (provider_id_data->opcode)
788
0
  {
789
0
  case 0:
790
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_buffer_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
791
0
    offset += 4;
792
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_version, tvb, offset, 4, ENC_LITTLE_ENDIAN);
793
0
    offset += 4;
794
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_provider_version, tvb, offset, 4, ENC_LITTLE_ENDIAN);
795
0
    offset += 4;
796
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_num_processors, tvb, offset, 4, ENC_LITTLE_ENDIAN);
797
0
    offset += 4;
798
799
    // TODO: Replace with a time_value_string
800
0
    raw_timestamp = tvb_get_letoh64(tvb, offset);
801
0
    if (raw_timestamp != 0)
802
0
    {
803
0
      proto_tree_add_item(system_tree, hf_netmon_system_trace_end_time, tvb, offset, 8, ENC_TIME_WINDOWS|ENC_LITTLE_ENDIAN);
804
0
    }
805
0
    else
806
0
    {
807
0
      proto_tree_add_time_format_value(system_tree, hf_netmon_system_trace_end_time, tvb, offset, 8, &timestamp, "(None)");
808
0
    }
809
0
    offset += 8;
810
811
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_timer_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
812
0
    offset += 4;
813
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_max_file_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
814
0
    offset += 4;
815
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_log_file_mode, tvb, offset, 4, ENC_LITTLE_ENDIAN);
816
0
    offset += 4;
817
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_buffers_written, tvb, offset, 4, ENC_LITTLE_ENDIAN);
818
0
    offset += 4;
819
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_start_buffers, tvb, offset, 4, ENC_LITTLE_ENDIAN);
820
0
    offset += 4;
821
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_pointers_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
822
0
    offset += 4;
823
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_events_lost, tvb, offset, 4, ENC_LITTLE_ENDIAN);
824
0
    offset += 4;
825
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_cpu_speed, tvb, offset, 4, ENC_LITTLE_ENDIAN);
826
0
    offset += 4;
827
0
    netmon_etl_field(system_tree, tvb, &offset, hf_netmon_system_trace_logger_name, provider_id_data->event_flags);
828
0
    netmon_etl_field(system_tree, tvb, &offset, hf_netmon_system_trace_log_file_name_ptr, provider_id_data->event_flags);
829
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_time_zone_info, tvb, offset, 176, ENC_NA);
830
0
    offset += 176;
831
832
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_boot_time, tvb, offset, 8, ENC_TIME_WINDOWS|ENC_LITTLE_ENDIAN);
833
0
    offset += 8;
834
835
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_perf_freq, tvb, offset, 8, ENC_LITTLE_ENDIAN);
836
0
    offset += 8;
837
838
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_start_time, tvb, offset, 8, ENC_TIME_WINDOWS|ENC_LITTLE_ENDIAN);
839
0
    offset += 8;
840
841
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_reserved_flags, tvb, offset, 4, ENC_LITTLE_ENDIAN);
842
0
    offset += 4;
843
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_buffers_lost, tvb, offset, 4, ENC_LITTLE_ENDIAN);
844
0
    offset += 4;
845
0
    length = tvb_unicode_strsize(tvb, offset);
846
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_session_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
847
0
    offset += length;
848
0
    length = tvb_unicode_strsize(tvb, offset);
849
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_log_file_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
850
0
    break;
851
0
  case 5:
852
0
  case 32:
853
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask1, tvb, offset, 4, ENC_LITTLE_ENDIAN);
854
0
    offset += 4;
855
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask2, tvb, offset, 4, ENC_LITTLE_ENDIAN);
856
0
    offset += 4;
857
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask3, tvb, offset, 4, ENC_LITTLE_ENDIAN);
858
0
    offset += 4;
859
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask4, tvb, offset, 4, ENC_LITTLE_ENDIAN);
860
0
    offset += 4;
861
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask5, tvb, offset, 4, ENC_LITTLE_ENDIAN);
862
0
    offset += 4;
863
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask6, tvb, offset, 4, ENC_LITTLE_ENDIAN);
864
0
    offset += 4;
865
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask7, tvb, offset, 4, ENC_LITTLE_ENDIAN);
866
0
    offset += 4;
867
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_group_mask8, tvb, offset, 4, ENC_LITTLE_ENDIAN);
868
0
    offset += 4;
869
0
    proto_tree_add_item(system_tree, hf_netmon_system_trace_kernel_event_version, tvb, offset, 4, ENC_LITTLE_ENDIAN);
870
0
    offset += 4;
871
0
    break;
872
0
  case 8: // EventTrace_RDComplete
873
0
    break;
874
0
  }
875
876
0
  return tvb_captured_length(tvb);
877
0
}
878
879
static int
880
dissect_netmon_system_config(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
881
0
{
882
0
  proto_item *ti;
883
0
  proto_tree *system_tree;
884
0
  unsigned offset = 0;
885
0
  struct netmon_provider_id_data *provider_id_data = (struct netmon_provider_id_data*)data;
886
0
  unsigned length;
887
0
  uint32_t field1, field2;
888
0
  const uint8_t *str_field1, *str_field2, *str_field3, *str_field4;
889
890
0
  DISSECTOR_ASSERT(provider_id_data != NULL);
891
892
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon System Config");
893
0
  col_clear(pinfo->cinfo, COL_INFO);
894
895
0
  ti = proto_tree_add_item(tree, proto_netmon_system_config, tvb, 0, -1, ENC_NA);
896
0
  system_tree = proto_item_add_subtree(ti, ett_netmon_system_config);
897
898
0
  switch (provider_id_data->event_version)
899
0
  {
900
  // SystemConfig_V0
901
0
  case 0:
902
0
    switch (provider_id_data->opcode)
903
0
    {
904
0
    case 10:
905
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_mhz, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
906
0
      offset += 4;
907
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_num_processors, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field2);
908
0
      offset += 4;
909
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Processors: %u, (%u MHz)", field2, field1);
910
911
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_mem_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
912
0
      offset += 4;
913
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_page_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
914
0
      offset += 4;
915
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_allocation_granularity, tvb, offset, 4, ENC_LITTLE_ENDIAN);
916
0
      offset += 4;
917
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_computer_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
918
0
      offset += 512;
919
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_domain_name, tvb, offset, 264, ENC_LITTLE_ENDIAN|ENC_UTF_16);
920
0
      offset += 264;
921
0
      netmon_etl_field(system_tree, tvb, &offset, hf_netmon_system_config_hyper_threading_flag, provider_id_data->event_flags);
922
0
      break;
923
0
    case 11:
924
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
925
0
      offset += 4;
926
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
927
0
      offset += 4;
928
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_track, tvb, offset, 4, ENC_LITTLE_ENDIAN);
929
0
      offset += 4;
930
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_tracks_per_cylinder, tvb, offset, 4, ENC_LITTLE_ENDIAN);
931
0
      offset += 4;
932
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_cylinders, tvb, offset, 8, ENC_LITTLE_ENDIAN);
933
0
      offset += 8;
934
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_port, tvb, offset, 4, ENC_LITTLE_ENDIAN);
935
0
      offset += 4;
936
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_path, tvb, offset, 4, ENC_LITTLE_ENDIAN);
937
0
      offset += 4;
938
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_target, tvb, offset, 4, ENC_LITTLE_ENDIAN);
939
0
      offset += 4;
940
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_lun, tvb, offset, 4, ENC_LITTLE_ENDIAN);
941
0
      offset += 4;
942
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_manufacturer, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
943
0
      offset += 512;
944
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
945
0
      offset += 4;
946
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_write_cache_enabled, tvb, offset, 1, ENC_LITTLE_ENDIAN);
947
0
      offset += 1;
948
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 1, ENC_NA);
949
0
      offset += 1;
950
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_boot_drive_letter, tvb, offset, 6, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
951
0
      offset += 6;
952
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_spare, tvb, offset, 4, ENC_LITTLE_ENDIAN|ENC_UTF_16);
953
0
      offset += 4;
954
955
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Manufacturer: %s, BootDriveLetter: %s", str_field1, str_field2);
956
0
      break;
957
0
    case 12:
958
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_start_offset, tvb, offset, 8, ENC_LITTLE_ENDIAN);
959
0
      offset += 8;
960
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_size, tvb, offset, 8, ENC_LITTLE_ENDIAN);
961
0
      offset += 8;
962
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
963
0
      offset += 4;
964
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
965
0
      offset += 4;
966
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_drive_type, tvb, offset, 4, ENC_LITTLE_ENDIAN);
967
0
      offset += 4;
968
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_drive_letter, tvb, offset, 8, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
969
0
      offset += 8;
970
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
971
0
      offset += 4;
972
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
973
0
      offset += 4;
974
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_cluster, tvb, offset, 4, ENC_LITTLE_ENDIAN);
975
0
      offset += 4;
976
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
977
0
      offset += 4;
978
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
979
0
      offset += 4;
980
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_num_free_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
981
0
      offset += 8;
982
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_total_num_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
983
0
      offset += 8;
984
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_file_system, tvb, offset, 32, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
985
0
      offset += 32;
986
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Drive: %s, FileSystem: %s", str_field1, str_field2);
987
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_volume_ext, tvb, offset, 4, ENC_LITTLE_ENDIAN);
988
0
      offset += 4;
989
0
      break;
990
0
    case 13:
991
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_nic_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
992
0
      offset += 512;
993
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_index, tvb, offset, 4, ENC_LITTLE_ENDIAN);
994
0
      offset += 4;
995
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
996
0
      offset += 4;
997
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr_str, tvb, offset, 16, ENC_LITTLE_ENDIAN|ENC_UTF_16);
998
0
      offset += 16;
999
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1000
0
      offset += 4;
1001
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_ip_address, tvb, offset, 4, ENC_BIG_ENDIAN);
1002
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "NIC: %s, Address: %s", str_field1, tvb_ip_to_str(pinfo->pool, tvb, offset));
1003
0
      offset += 4;
1004
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_subnet_mask, tvb, offset, 4, ENC_BIG_ENDIAN);
1005
0
      offset += 4;
1006
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dhcp_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1007
0
      offset += 4;
1008
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_gateway, tvb, offset, 4, ENC_BIG_ENDIAN);
1009
0
      offset += 4;
1010
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_primary_wins_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1011
0
      offset += 4;
1012
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_secondary_wins_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1013
0
      offset += 4;
1014
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server1, tvb, offset, 4, ENC_BIG_ENDIAN);
1015
0
      offset += 4;
1016
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server2, tvb, offset, 4, ENC_BIG_ENDIAN);
1017
0
      offset += 4;
1018
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server3, tvb, offset, 4, ENC_BIG_ENDIAN);
1019
0
      offset += 4;
1020
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server4, tvb, offset, 4, ENC_BIG_ENDIAN);
1021
0
      offset += 4;
1022
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_data, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1023
0
      offset += 4;
1024
0
      break;
1025
0
    case 14:
1026
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_memory_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1027
0
      offset += 4;
1028
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_x_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1029
0
      offset += 4;
1030
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_y_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1031
0
      offset += 4;
1032
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bits_per_pixel, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1033
0
      offset += 4;
1034
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_vrefresh, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1035
0
      offset += 4;
1036
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_chip_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1037
0
      offset += 512;
1038
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dac_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1039
0
      offset += 512;
1040
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_adapter_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1041
0
      offset += 512;
1042
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_bios_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field3);
1043
0
      offset += 512;
1044
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Chip: %s, Adapter: %s, Bios: %s", str_field1, str_field2, str_field3);
1045
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1046
0
      offset += 512;
1047
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_state_flags, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1048
0
      offset += 4;
1049
0
      break;
1050
0
    case 15:
1051
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_service_name, tvb, offset, 68, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1052
0
      offset += 68;
1053
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_display_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1054
0
      offset += 512;
1055
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_process_name, tvb, offset, 68, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1056
0
      offset += 68;
1057
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Service: %s, Process: %s", str_field1, str_field2);
1058
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1059
0
      offset += 4;
1060
0
      break;
1061
0
    case 16:
1062
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s1, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1063
0
      offset += 1;
1064
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s2, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1065
0
      offset += 1;
1066
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s3, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1067
0
      offset += 1;
1068
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s4, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1069
0
      offset += 1;
1070
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s5, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1071
0
      offset += 1;
1072
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 3, ENC_NA);
1073
0
      offset += 3;
1074
0
      break;
1075
0
    case 21:
1076
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_irq_affinity, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1077
0
      offset += 8;
1078
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_irq_num, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1079
0
      offset += 4;
1080
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "IRQ: %u", field1);
1081
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1082
0
      offset += 4;
1083
      /* XXX - can we trust size above? */
1084
0
      length = tvb_unicode_strsize(tvb, offset);
1085
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1086
0
      offset += length;
1087
0
      break;
1088
0
    case 22:
1089
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1090
0
      offset += 4;
1091
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1092
0
      offset += 4;
1093
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_friendly_name_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1094
0
      offset += 4;
1095
      /* XXX - can we trust sizes above? */
1096
0
      length = tvb_unicode_strsize(tvb, offset);
1097
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_device_id, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1098
0
      offset += length;
1099
0
      length = tvb_unicode_strsize(tvb, offset);
1100
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1101
0
      offset += length;
1102
0
      length = tvb_unicode_strsize(tvb, offset);
1103
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_friendly_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1104
0
      offset += length;
1105
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "ID: %s, Name: %s", str_field1, str_field2);
1106
0
      length = tvb_unicode_strsize(tvb, offset);
1107
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pdo_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1108
0
      offset += length;
1109
0
      break;
1110
0
    }
1111
0
    break;
1112
  // SystemConfig_V1
1113
0
  case 1:
1114
0
    switch (provider_id_data->opcode)
1115
0
    {
1116
0
    case 10:
1117
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_mhz, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1118
0
      offset += 4;
1119
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_num_processors, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field2);
1120
0
      offset += 4;
1121
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Processors: %u, (%u MHz)", field2, field1);
1122
1123
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_mem_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1124
0
      offset += 4;
1125
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_page_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1126
0
      offset += 4;
1127
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_allocation_granularity, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1128
0
      offset += 4;
1129
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_computer_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1130
0
      offset += 512;
1131
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_domain_name, tvb, offset, 264, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1132
0
      offset += 264;
1133
0
      netmon_etl_field(system_tree, tvb, &offset, hf_netmon_system_config_hyper_threading_flag, provider_id_data->event_flags);
1134
0
      break;
1135
0
    case 11:
1136
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1137
0
      offset += 4;
1138
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1139
0
      offset += 4;
1140
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_track, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1141
0
      offset += 4;
1142
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_tracks_per_cylinder, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1143
0
      offset += 4;
1144
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_cylinders, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1145
0
      offset += 8;
1146
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_port, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1147
0
      offset += 4;
1148
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_path, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1149
0
      offset += 4;
1150
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_target, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1151
0
      offset += 4;
1152
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_lun, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1153
0
      offset += 4;
1154
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_manufacturer, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1155
0
      offset += 512;
1156
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1157
0
      offset += 4;
1158
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_write_cache_enabled, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1159
0
      offset += 1;
1160
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 1, ENC_NA);
1161
0
      offset += 1;
1162
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_boot_drive_letter, tvb, offset, 6, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1163
0
      offset += 6;
1164
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_spare, tvb, offset, 4, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1165
0
      offset += 4;
1166
1167
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Manufacturer: %s, BootDriveLetter: %s", str_field1, str_field2);
1168
0
      break;
1169
0
    case 12:
1170
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_start_offset, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1171
0
      offset += 8;
1172
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_size, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1173
0
      offset += 8;
1174
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1175
0
      offset += 4;
1176
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1177
0
      offset += 4;
1178
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_drive_type, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1179
0
      offset += 4;
1180
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_drive_letter, tvb, offset, 8, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1181
0
      offset += 8;
1182
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
1183
0
      offset += 4;
1184
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1185
0
      offset += 4;
1186
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_cluster, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1187
0
      offset += 4;
1188
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1189
0
      offset += 4;
1190
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
1191
0
      offset += 4;
1192
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_num_free_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1193
0
      offset += 8;
1194
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_total_num_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1195
0
      offset += 8;
1196
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_file_system, tvb, offset, 32, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1197
0
      offset += 32;
1198
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Drive: %s, FileSystem: %s", str_field1, str_field2);
1199
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_volume_ext, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1200
0
      offset += 4;
1201
0
      break;
1202
0
    case 13:
1203
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_nic_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1204
0
      offset += 512;
1205
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_index, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1206
0
      offset += 4;
1207
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1208
0
      offset += 4;
1209
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr_str, tvb, offset, 16, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1210
0
      offset += 16;
1211
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1212
0
      offset += 4;
1213
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_ip_address, tvb, offset, 4, ENC_BIG_ENDIAN);
1214
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "NIC: %s, Address: %s", str_field1, tvb_ip_to_str(pinfo->pool, tvb, offset));
1215
0
      offset += 4;
1216
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_subnet_mask, tvb, offset, 4, ENC_BIG_ENDIAN);
1217
0
      offset += 4;
1218
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dhcp_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1219
0
      offset += 4;
1220
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_gateway, tvb, offset, 4, ENC_BIG_ENDIAN);
1221
0
      offset += 4;
1222
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_primary_wins_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1223
0
      offset += 4;
1224
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_secondary_wins_server, tvb, offset, 4, ENC_BIG_ENDIAN);
1225
0
      offset += 4;
1226
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server1, tvb, offset, 4, ENC_BIG_ENDIAN);
1227
0
      offset += 4;
1228
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server2, tvb, offset, 4, ENC_BIG_ENDIAN);
1229
0
      offset += 4;
1230
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server3, tvb, offset, 4, ENC_BIG_ENDIAN);
1231
0
      offset += 4;
1232
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server4, tvb, offset, 4, ENC_BIG_ENDIAN);
1233
0
      offset += 4;
1234
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_data, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1235
0
      offset += 4;
1236
0
      break;
1237
0
    case 14:
1238
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_memory_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1239
0
      offset += 4;
1240
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_x_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1241
0
      offset += 4;
1242
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_y_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1243
0
      offset += 4;
1244
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bits_per_pixel, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1245
0
      offset += 4;
1246
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_vrefresh, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1247
0
      offset += 4;
1248
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_chip_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1249
0
      offset += 512;
1250
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dac_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1251
0
      offset += 512;
1252
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_adapter_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1253
0
      offset += 512;
1254
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_bios_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field3);
1255
0
      offset += 512;
1256
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Chip: %s, Adapter: %s, Bios: %s", str_field1, str_field2, str_field3);
1257
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1258
0
      offset += 512;
1259
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_state_flags, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1260
0
      offset += 4;
1261
0
      break;
1262
0
    case 15:
1263
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_service_name, tvb, offset, 68, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1264
0
      offset += 68;
1265
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_display_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1266
0
      offset += 512;
1267
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_process_name, tvb, offset, 68, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1268
0
      offset += 68;
1269
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Service: %s, Process: %s", str_field1, str_field2);
1270
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1271
0
      offset += 4;
1272
0
      break;
1273
0
    case 16:
1274
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s1, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1275
0
      offset += 1;
1276
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s2, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1277
0
      offset += 1;
1278
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s3, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1279
0
      offset += 1;
1280
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s4, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1281
0
      offset += 1;
1282
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s5, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1283
0
      offset += 1;
1284
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 3, ENC_NA);
1285
0
      offset += 3;
1286
0
      break;
1287
0
    case 21:
1288
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_irq_affinity, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1289
0
      offset += 8;
1290
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_irq_num, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1291
0
      offset += 4;
1292
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "IRQ: %u", field1);
1293
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1294
0
      offset += 4;
1295
      /* XXX - can we trust size above? */
1296
0
      length = tvb_unicode_strsize(tvb, offset);
1297
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1298
0
      offset += length;
1299
0
      break;
1300
0
    case 22:
1301
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1302
0
      offset += 4;
1303
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1304
0
      offset += 4;
1305
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_friendly_name_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1306
0
      offset += 4;
1307
      /* XXX - can we trust sizes above? */
1308
0
      length = tvb_unicode_strsize(tvb, offset);
1309
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_device_id, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1310
0
      offset += length;
1311
0
      length = tvb_unicode_strsize(tvb, offset);
1312
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1313
0
      offset += length;
1314
0
      length = tvb_unicode_strsize(tvb, offset);
1315
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_friendly_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1316
0
      offset += length;
1317
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "ID: %s, Name: %s", str_field1, str_field2);
1318
0
      length = tvb_unicode_strsize(tvb, offset);
1319
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pdo_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1320
0
      offset += length;
1321
0
      break;
1322
0
    }
1323
0
    break;
1324
  // SystemConfig_V2
1325
0
  case 2:
1326
0
    switch (provider_id_data->opcode)
1327
0
    {
1328
0
    case 10:
1329
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_mhz, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1330
0
      offset += 4;
1331
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_num_processors, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field2);
1332
0
      offset += 4;
1333
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Processors: %u, (%u MHz)", field2, field1);
1334
1335
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_mem_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1336
0
      offset += 4;
1337
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_page_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1338
0
      offset += 4;
1339
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_allocation_granularity, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1340
0
      offset += 4;
1341
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_computer_name, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1342
0
      offset += 512;
1343
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_domain_name, tvb, offset, 268, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1344
0
      offset += 268;
1345
0
      netmon_etl_field(system_tree, tvb, &offset, hf_netmon_system_config_hyper_threading_flag, provider_id_data->event_flags);
1346
0
      break;
1347
0
    case 11:
1348
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1349
0
      offset += 4;
1350
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1351
0
      offset += 4;
1352
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_track, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1353
0
      offset += 4;
1354
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_tracks_per_cylinder, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1355
0
      offset += 4;
1356
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_cylinders, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1357
0
      offset += 8;
1358
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_port, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1359
0
      offset += 4;
1360
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_path, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1361
0
      offset += 4;
1362
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_target, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1363
0
      offset += 4;
1364
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_scsi_lun, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1365
0
      offset += 4;
1366
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_manufacturer, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1367
0
      offset += 512;
1368
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1369
0
      offset += 4;
1370
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_write_cache_enabled, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1371
0
      offset += 1;
1372
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 1, ENC_NA);
1373
0
      offset += 1;
1374
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_boot_drive_letter, tvb, offset, 6, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1375
0
      offset += 6;
1376
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_spare, tvb, offset, 4, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1377
0
      offset += 4;
1378
1379
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Manufacturer: %s, BootDriveLetter: %s", str_field1, str_field2);
1380
0
      break;
1381
0
    case 12:
1382
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_start_offset, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1383
0
      offset += 8;
1384
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_size, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1385
0
      offset += 8;
1386
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_disk_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1387
0
      offset += 4;
1388
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1389
0
      offset += 4;
1390
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_drive_type, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1391
0
      offset += 4;
1392
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_drive_letter, tvb, offset, 8, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1393
0
      offset += 8;
1394
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
1395
0
      offset += 4;
1396
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_partition_number, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1397
0
      offset += 4;
1398
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sectors_per_cluster, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1399
0
      offset += 4;
1400
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bytes_per_sector, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1401
0
      offset += 4;
1402
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
1403
0
      offset += 4;
1404
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_num_free_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1405
0
      offset += 8;
1406
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_total_num_clusters, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1407
0
      offset += 8;
1408
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_file_system, tvb, offset, 32, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1409
0
      offset += 32;
1410
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Drive: %s, FileSystem: %s", str_field1, str_field2);
1411
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_volume_ext, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1412
0
      offset += 4;
1413
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 4, ENC_NA);
1414
0
      offset += 4;
1415
0
      break;
1416
0
    case 13:
1417
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1418
0
      offset += 8;
1419
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_physical_addr_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1420
0
      offset += 4;
1421
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_ipv4_index, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1422
0
      offset += 4;
1423
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_ipv6_index, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1424
0
      offset += 4;
1425
0
      length = tvb_unicode_strsize(tvb, offset);
1426
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_nic_description, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1427
0
      offset += length;
1428
0
      length = tvb_unicode_strsize(tvb, offset);
1429
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_ipaddresses, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1430
0
      offset += length;
1431
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "IP Addresses: %s", str_field1);
1432
0
      length = tvb_unicode_strsize(tvb, offset);
1433
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dns_server_addresses, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1434
0
      offset += length;
1435
0
      break;
1436
0
    case 14:
1437
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_memory_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1438
0
      offset += 4;
1439
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_x_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1440
0
      offset += 4;
1441
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_y_resolution, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1442
0
      offset += 4;
1443
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_bits_per_pixel, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1444
0
      offset += 4;
1445
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_vrefresh, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1446
0
      offset += 4;
1447
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_chip_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1448
0
      offset += 512;
1449
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_dac_type, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1450
0
      offset += 512;
1451
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_adapter_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1452
0
      offset += 512;
1453
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_bios_string, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field3);
1454
0
      offset += 512;
1455
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Chip: %s, Adapter: %s, Bios: %s", str_field1, str_field2, str_field3);
1456
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id, tvb, offset, 512, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1457
0
      offset += 512;
1458
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_state_flags, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1459
0
      offset += 4;
1460
0
      break;
1461
0
    case 15:
1462
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1463
0
      offset += 4;
1464
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_service_state, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1465
0
      offset += 4;
1466
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sub_process_tag, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1467
0
      offset += 4;
1468
0
      length = tvb_unicode_strsize(tvb, offset);
1469
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_service_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1470
0
      offset += length;
1471
0
      length = tvb_unicode_strsize(tvb, offset);
1472
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_display_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1473
0
      offset += length;
1474
0
      length = tvb_unicode_strsize(tvb, offset);
1475
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_process_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1476
0
      offset += length;
1477
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Service: %s, Process: %s", str_field1, str_field2);
1478
0
      break;
1479
0
    case 16:
1480
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s1, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1481
0
      offset += 1;
1482
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s2, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1483
0
      offset += 1;
1484
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s3, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1485
0
      offset += 1;
1486
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s4, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1487
0
      offset += 1;
1488
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_s5, tvb, offset, 1, ENC_LITTLE_ENDIAN);
1489
0
      offset += 1;
1490
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 3, ENC_NA);
1491
0
      offset += 3;
1492
0
      break;
1493
0
    case 17:
1494
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_tcb_table_partitions, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1495
0
      offset += 4;
1496
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_max_hash_table_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1497
0
      offset += 4;
1498
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_max_user_port, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1499
0
      offset += 4;
1500
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_tcp_timed_wait_delay, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1501
0
      offset += 4;
1502
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "MaxUserPort: %u", field1);
1503
0
      break;
1504
0
    case 21:
1505
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_irq_affinity, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1506
0
      offset += 8;
1507
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_irq_num, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1508
0
      offset += 4;
1509
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "IRQ: %u", field1);
1510
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1511
0
      offset += 4;
1512
      /* XXX - can we trust size above? */
1513
0
      length = tvb_unicode_strsize(tvb, offset);
1514
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1515
0
      offset += length;
1516
0
      break;
1517
0
    case 22:
1518
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1519
0
      offset += 4;
1520
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1521
0
      offset += 4;
1522
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_friendly_name_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1523
0
      offset += 4;
1524
      /* XXX - can we trust sizes above? */
1525
0
      length = tvb_unicode_strsize(tvb, offset);
1526
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_device_id, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1527
0
      offset += length;
1528
0
      length = tvb_unicode_strsize(tvb, offset);
1529
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1530
0
      offset += length;
1531
0
      length = tvb_unicode_strsize(tvb, offset);
1532
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_friendly_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1533
0
      offset += length;
1534
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "ID: %s, Name: %s", str_field1, str_field2);
1535
0
      break;
1536
0
    case 23:
1537
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_target_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1538
0
      offset += 4;
1539
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_type, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1540
0
      offset += 4;
1541
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_timing_mode, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1542
0
      offset += 4;
1543
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_location_information_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1544
0
      offset += 4;
1545
0
      length = tvb_unicode_strsize(tvb, offset);
1546
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_location_information, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1547
0
      offset += length;
1548
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Location: %s", str_field1);
1549
0
      break;
1550
0
    case 25:
1551
0
      length = tvb_unicode_strsize(tvb, offset);
1552
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_system_manufacturer, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1553
0
      offset += length;
1554
0
      length = tvb_unicode_strsize(tvb, offset);
1555
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_system_product_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1556
0
      offset += length;
1557
0
      length = tvb_unicode_strsize(tvb, offset);
1558
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_bios_date, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field3);
1559
0
      offset += length;
1560
0
      length = tvb_unicode_strsize(tvb, offset);
1561
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_bios_version, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field4);
1562
0
      offset += length;
1563
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Manufacturer: %s, ProductName: %s, BiosDate: %s, BiosVersion: %s", str_field1, str_field2, str_field3, str_field4);
1564
0
      break;
1565
0
    }
1566
0
    break;
1567
  // SystemConfig_V3
1568
0
  case 3:
1569
0
    switch (provider_id_data->opcode)
1570
0
    {
1571
0
    case 15:
1572
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1573
0
      offset += 4;
1574
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_service_state, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1575
0
      offset += 4;
1576
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_sub_process_tag, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1577
0
      offset += 4;
1578
0
      length = tvb_unicode_strsize(tvb, offset);
1579
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_service_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1580
0
      offset += length;
1581
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Service: %s, (PID=%d)", str_field1, field1);
1582
0
      length = tvb_unicode_strsize(tvb, offset);
1583
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_display_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1584
0
      offset += length;
1585
0
      length = tvb_unicode_strsize(tvb, offset);
1586
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_process_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1587
0
      offset += length;
1588
0
      length = tvb_unicode_strsize(tvb, offset);
1589
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_load_order_group, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1590
0
      offset += length;
1591
0
      length = tvb_unicode_strsize(tvb, offset);
1592
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_svc_host_group, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1593
0
      offset += length;
1594
0
      break;
1595
0
    case 21:
1596
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_irq_affinity, tvb, offset, 8, ENC_LITTLE_ENDIAN);
1597
0
      offset += 8;
1598
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_irq_group, tvb, offset, 2, ENC_LITTLE_ENDIAN);
1599
0
      offset += 2;
1600
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pad, tvb, offset, 2, ENC_NA);
1601
0
      offset += 2;
1602
0
      proto_tree_add_item_ret_uint(system_tree, hf_netmon_system_config_irq_num, tvb, offset, 4, ENC_LITTLE_ENDIAN, &field1);
1603
0
      offset += 4;
1604
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "IRQ: %u", field1);
1605
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1606
0
      offset += 4;
1607
      /* XXX - can we trust size above? */
1608
0
      length = tvb_unicode_strsize(tvb, offset);
1609
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1610
0
      offset += length;
1611
0
      break;
1612
0
    case 22:
1613
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_id_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1614
0
      offset += 4;
1615
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1616
0
      offset += 4;
1617
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_friendly_name_len, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1618
0
      offset += 4;
1619
      /* XXX - can we trust sizes above? */
1620
0
      length = tvb_unicode_strsize(tvb, offset);
1621
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_device_id, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field1);
1622
0
      offset += length;
1623
0
      length = tvb_unicode_strsize(tvb, offset);
1624
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_device_desc, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1625
0
      offset += length;
1626
0
      length = tvb_unicode_strsize(tvb, offset);
1627
0
      proto_tree_add_item_ret_string(system_tree, hf_netmon_system_config_friendly_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16, pinfo->pool, &str_field2);
1628
0
      offset += length;
1629
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "ID: %s, Name: %s", str_field1, str_field2);
1630
0
      length = tvb_unicode_strsize(tvb, offset);
1631
0
      proto_tree_add_item(system_tree, hf_netmon_system_config_pdo_name, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1632
0
      offset += length;
1633
0
      break;
1634
0
    }
1635
0
    break;
1636
0
  }
1637
1638
0
  return offset;
1639
0
}
1640
1641
static int
1642
dissect_netmon_process(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
1643
0
{
1644
0
  proto_item *ti;
1645
0
  proto_tree *process_tree;
1646
0
  unsigned offset = 0;
1647
0
  struct netmon_provider_id_data *provider_id_data = (struct netmon_provider_id_data*)data;
1648
0
  unsigned length;
1649
0
  const uint8_t *filename;
1650
1651
0
  DISSECTOR_ASSERT(provider_id_data != NULL);
1652
1653
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "NetMon Process");
1654
0
  col_clear(pinfo->cinfo, COL_INFO);
1655
1656
0
  ti = proto_tree_add_item(tree, proto_netmon_process, tvb, 0, -1, ENC_NA);
1657
0
  process_tree = proto_item_add_subtree(ti, ett_netmon_process);
1658
1659
0
  switch (provider_id_data->event_version)
1660
0
  {
1661
0
  case 0:
1662
0
    switch (provider_id_data->opcode)
1663
0
    {
1664
0
    case 1:
1665
0
    case 2:
1666
0
    case 3:
1667
0
    case 4:
1668
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1669
0
      offset += 4;
1670
0
      proto_tree_add_item(process_tree, hf_netmon_process_parent_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1671
0
      offset += 4;
1672
0
      netmon_sid_field(process_tree, tvb, &offset, pinfo, hf_netmon_process_user_sid_revision,
1673
0
              hf_netmon_process_user_sid_subauth_count, hf_netmon_process_user_sid_id, hf_netmon_process_user_sid_authority,
1674
0
              &ei_netmon_process_user_sid, false);
1675
0
      length = tvb_strsize(tvb, offset);
1676
0
      proto_tree_add_item_ret_string(process_tree, hf_netmon_process_image_file_name, tvb, offset, length, ENC_NA|ENC_ASCII,
1677
0
              pinfo->pool, &filename);
1678
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Filename: %s", filename);
1679
0
      offset += length;
1680
0
      break;
1681
1682
0
    }
1683
0
    break;
1684
0
  case 1:
1685
0
    switch (provider_id_data->opcode)
1686
0
    {
1687
0
    case 1:
1688
0
    case 2:
1689
0
    case 3:
1690
0
    case 4:
1691
0
      netmon_etl_field(process_tree, tvb, &offset, hf_netmon_process_page_directory_base, provider_id_data->event_flags);
1692
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1693
0
      offset += 4;
1694
0
      proto_tree_add_item(process_tree, hf_netmon_process_parent_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1695
0
      offset += 4;
1696
0
      proto_tree_add_item(process_tree, hf_netmon_process_session_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1697
0
      offset += 4;
1698
0
      proto_tree_add_item(process_tree, hf_netmon_process_exit_status, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1699
0
      offset += 4;
1700
0
      netmon_sid_field(process_tree, tvb, &offset, pinfo, hf_netmon_process_user_sid_revision,
1701
0
              hf_netmon_process_user_sid_subauth_count, hf_netmon_process_user_sid_id, hf_netmon_process_user_sid_authority,
1702
0
              &ei_netmon_process_user_sid, false);
1703
0
      length = tvb_strsize(tvb, offset);
1704
0
      proto_tree_add_item_ret_string(process_tree, hf_netmon_process_image_file_name, tvb, offset, length, ENC_NA|ENC_ASCII,
1705
0
              pinfo->pool, &filename);
1706
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Filename: %s", filename);
1707
0
      offset += length;
1708
0
      break;
1709
0
    }
1710
0
    break;
1711
0
  case 2:
1712
0
    switch (provider_id_data->opcode)
1713
0
    {
1714
0
    case 1:
1715
0
    case 2:
1716
0
    case 3:
1717
0
    case 4:
1718
0
    case 39:
1719
0
      netmon_etl_field(process_tree, tvb, &offset, hf_netmon_process_unique_process_key, provider_id_data->event_flags);
1720
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1721
0
      offset += 4;
1722
0
      proto_tree_add_item(process_tree, hf_netmon_process_parent_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1723
0
      offset += 4;
1724
0
      proto_tree_add_item(process_tree, hf_netmon_process_session_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1725
0
      offset += 4;
1726
0
      proto_tree_add_item(process_tree, hf_netmon_process_exit_status, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1727
0
      offset += 4;
1728
0
      if (provider_id_data->event_flags & EVENT_HEADER_FLAG_64_BIT_HEADER)
1729
0
      {
1730
0
        proto_tree_add_item(process_tree, hf_netmon_process_unknown, tvb, offset, 16, ENC_NA);
1731
0
        offset += 16;
1732
0
      }
1733
0
      else
1734
0
      {
1735
0
        proto_tree_add_item(process_tree, hf_netmon_process_unknown, tvb, offset, 8, ENC_NA);
1736
0
        offset += 8;
1737
0
      }
1738
0
      netmon_sid_field(process_tree, tvb, &offset, pinfo, hf_netmon_process_user_sid_revision,
1739
0
              hf_netmon_process_user_sid_subauth_count, hf_netmon_process_user_sid_id, hf_netmon_process_user_sid_authority,
1740
0
              &ei_netmon_process_user_sid, false);
1741
0
      length = tvb_strsize(tvb, offset);
1742
0
      proto_tree_add_item_ret_string(process_tree, hf_netmon_process_image_file_name, tvb, offset, length, ENC_NA|ENC_ASCII,
1743
0
              pinfo->pool, &filename);
1744
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Filename: %s", filename);
1745
0
      offset += length;
1746
1747
0
      length = tvb_unicode_strsize(tvb, offset);
1748
0
      proto_tree_add_item(process_tree, hf_netmon_process_command_line, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1749
0
      offset += length;
1750
0
      break;
1751
1752
0
    case 32:
1753
0
    case 33:
1754
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1755
0
      offset += 4;
1756
0
      proto_tree_add_item(process_tree, hf_netmon_process_page_fault_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1757
0
      offset += 4;
1758
0
      proto_tree_add_item(process_tree, hf_netmon_process_handle_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1759
0
      offset += 4;
1760
0
      proto_tree_add_item(process_tree, hf_netmon_process_reserved, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1761
0
      offset += 4;
1762
0
      proto_tree_add_item(process_tree, hf_netmon_process_peak_virtual_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1763
0
      offset += 4;
1764
0
      proto_tree_add_item(process_tree, hf_netmon_process_peak_working_set_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1765
0
      offset += 4;
1766
0
      proto_tree_add_item(process_tree, hf_netmon_process_peak_page_file_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1767
0
      offset += 4;
1768
0
      proto_tree_add_item(process_tree, hf_netmon_process_quota_peak_paged_pool_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1769
0
      offset += 4;
1770
0
      proto_tree_add_item(process_tree, hf_netmon_process_quota_peak_non_paged_pool_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1771
0
      offset += 4;
1772
0
      proto_tree_add_item(process_tree, hf_netmon_process_virtual_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1773
0
      offset += 4;
1774
0
      proto_tree_add_item(process_tree, hf_netmon_process_workingset_size, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1775
0
      offset += 4;
1776
0
      proto_tree_add_item(process_tree, hf_netmon_process_pagefile_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1777
0
      offset += 4;
1778
0
      proto_tree_add_item(process_tree, hf_netmon_process_quota_paged_pool_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1779
0
      offset += 4;
1780
0
      proto_tree_add_item(process_tree, hf_netmon_process_quota_non_paged_pool_usage, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1781
0
      offset += 4;
1782
0
      proto_tree_add_item(process_tree, hf_netmon_process_private_page_count, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1783
0
      offset += 4;
1784
0
      break;
1785
0
    case 35:
1786
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1787
0
      offset += 4;
1788
0
      proto_tree_add_item(process_tree, hf_netmon_process_directory_table_base32, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1789
0
      offset += 4;
1790
0
      break;
1791
0
    }
1792
0
    break;
1793
0
  case 3:
1794
0
    switch (provider_id_data->opcode)
1795
0
    {
1796
0
    case 1:
1797
0
    case 2:
1798
0
    case 3:
1799
0
    case 4:
1800
0
    case 39:
1801
0
      netmon_etl_field(process_tree, tvb, &offset, hf_netmon_process_unique_process_key, provider_id_data->event_flags);
1802
0
      proto_tree_add_item(process_tree, hf_netmon_process_process_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1803
0
      offset += 4;
1804
0
      proto_tree_add_item(process_tree, hf_netmon_process_parent_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1805
0
      offset += 4;
1806
0
      proto_tree_add_item(process_tree, hf_netmon_process_session_id, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1807
0
      offset += 4;
1808
0
      proto_tree_add_item(process_tree, hf_netmon_process_exit_status, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1809
0
      offset += 4;
1810
0
      netmon_etl_field(process_tree, tvb, &offset, hf_netmon_process_directory_table_base, provider_id_data->event_flags);
1811
0
      if (provider_id_data->event_flags & EVENT_HEADER_FLAG_64_BIT_HEADER)
1812
0
      {
1813
0
        proto_tree_add_item(process_tree, hf_netmon_process_unknown, tvb, offset, 16, ENC_NA);
1814
0
        offset += 16;
1815
0
      }
1816
0
      else
1817
0
      {
1818
0
        proto_tree_add_item(process_tree, hf_netmon_process_unknown, tvb, offset, 8, ENC_NA);
1819
0
        offset += 8;
1820
0
      }
1821
0
      netmon_sid_field(process_tree, tvb, &offset, pinfo, hf_netmon_process_user_sid_revision,
1822
0
              hf_netmon_process_user_sid_subauth_count, hf_netmon_process_user_sid_id, hf_netmon_process_user_sid_authority,
1823
0
              &ei_netmon_process_user_sid, false);
1824
0
      length = tvb_strsize(tvb, offset);
1825
0
      proto_tree_add_item_ret_string(process_tree, hf_netmon_process_image_file_name, tvb, offset, length, ENC_NA|ENC_ASCII,
1826
0
              pinfo->pool, &filename);
1827
0
      col_add_fstr(pinfo->cinfo, COL_INFO, "Filename: %s", filename);
1828
0
      offset += length;
1829
1830
0
      length = tvb_unicode_strsize(tvb, offset);
1831
0
      proto_tree_add_item(process_tree, hf_netmon_process_command_line, tvb, offset, length, ENC_LITTLE_ENDIAN|ENC_UTF_16);
1832
0
      offset += length;
1833
0
      break;
1834
0
    }
1835
0
    break;
1836
0
  }
1837
1838
0
  return tvb_captured_length(tvb);
1839
0
}
1840
1841
void proto_register_netmon(void)
1842
16
{
1843
16
  static hf_register_info hf_header[] = {
1844
16
    { &hf_netmon_header_title_comment,
1845
16
      { "Comment title", "netmon_header.title_comment",
1846
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
1847
16
    },
1848
16
    { &hf_netmon_header_description_comment,
1849
16
      { "Comment description", "netmon_header.description_comment",
1850
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
1851
16
    },
1852
16
  };
1853
1854
1855
16
  static hf_register_info hf_event[] = {
1856
16
    { &hf_netmon_event_size,
1857
16
      { "Size", "netmon_event.size",
1858
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
1859
16
    },
1860
16
    { &hf_netmon_event_header_type,
1861
16
      { "Header type", "netmon_event.header_type",
1862
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
1863
16
    },
1864
16
    { &hf_netmon_event_flags,
1865
16
      { "Flags", "netmon_event.flags",
1866
16
      FT_UINT16, BASE_HEX, NULL, 0x0, NULL, HFILL }
1867
16
    },
1868
16
    { &hf_netmon_event_flags_extended_info,
1869
16
      { "Extended Info", "netmon_event.flags.extended_info",
1870
16
      FT_BOOLEAN, 16, TFS(&tfs_present_not_present), EVENT_HEADER_FLAG_EXTENDED_INFO, NULL, HFILL }
1871
16
    },
1872
16
    { &hf_netmon_event_flags_private_session,
1873
16
      { "Private Sessions", "netmon_event.flags.private_session",
1874
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_PRIVATE_SESSION, NULL, HFILL }
1875
16
    },
1876
16
    { &hf_netmon_event_flags_string_only,
1877
16
      { "Null-terminated Unicode string", "netmon_event.flags.string_only",
1878
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_STRING_ONLY, NULL, HFILL }
1879
16
    },
1880
16
    { &hf_netmon_event_flags_trace_message,
1881
16
      { "TraceMessage logged", "netmon_event.flags.trace_message",
1882
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_TRACE_MESSAGE, NULL, HFILL }
1883
16
    },
1884
16
    { &hf_netmon_event_flags_no_cputime,
1885
16
      { "Use ProcessorTime", "netmon_event.flags.no_cputime",
1886
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_NO_CPUTIME, NULL, HFILL }
1887
16
    },
1888
16
    { &hf_netmon_event_flags_32bit_header,
1889
16
      { "Provider running on 32-bit computer", "netmon_event.flags.32bit_header",
1890
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_32_BIT_HEADER, NULL, HFILL }
1891
16
    },
1892
16
    { &hf_netmon_event_flags_64bit_header,
1893
16
      { "Provider running on 64-bit computer", "netmon_event.flags.64bit_header",
1894
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_64_BIT_HEADER, NULL, HFILL }
1895
16
    },
1896
16
    { &hf_netmon_event_flags_classic_header,
1897
16
      { "Use TraceEvent", "netmon_event.flags.classic_header",
1898
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_FLAG_CLASSIC_HEADER, NULL, HFILL }
1899
16
    },
1900
16
    { &hf_netmon_event_event_property,
1901
16
      { "Event property", "netmon_event.event_property",
1902
16
      FT_UINT16, BASE_HEX, NULL, 0x0, NULL, HFILL }
1903
16
    },
1904
16
    { &hf_netmon_event_event_property_xml,
1905
16
      { "Need manifest", "netmon_event.event_property.xml",
1906
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_PROPERTY_XML, NULL, HFILL }
1907
16
    },
1908
16
    { &hf_netmon_event_event_property_forwarded_xml,
1909
16
      { "Event data contains fully-rendered XML", "netmon_event.event_property.forwarded_xml",
1910
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_PROPERTY_FORWARDED_XML, NULL, HFILL }
1911
16
    },
1912
16
    { &hf_netmon_event_event_property_legacy_eventlog,
1913
16
      { "Need WMI MOF class", "netmon_event.event_property.legacy_eventlog",
1914
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), EVENT_HEADER_PROPERTY_LEGACY_EVENTLOG, NULL, HFILL }
1915
16
    },
1916
16
    { &hf_netmon_event_thread_id,
1917
16
      { "Thread ID", "netmon_event.thread_id",
1918
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
1919
16
    },
1920
16
    { &hf_netmon_event_process_id,
1921
16
      { "Process ID", "netmon_event.process_id",
1922
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
1923
16
    },
1924
16
    { &hf_netmon_event_timestamp,
1925
16
      { "Timestamp", "netmon_event.timestamp",
1926
16
      FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0x0, NULL, HFILL }
1927
16
    },
1928
16
    { &hf_netmon_event_provider_id,
1929
16
      { "Provider ID", "netmon_event.provider_id",
1930
16
      FT_GUID, BASE_NONE, NULL, 0x0, NULL, HFILL }
1931
16
    },
1932
16
    { &hf_netmon_event_event_desc_id,
1933
16
      { "ID", "netmon_event.event_desc.id",
1934
16
      FT_UINT16, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1935
16
    },
1936
16
    { &hf_netmon_event_event_desc_version,
1937
16
      { "Version", "netmon_event.event_desc.version",
1938
16
      FT_UINT8, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1939
16
    },
1940
16
    { &hf_netmon_event_event_desc_channel,
1941
16
      { "Channel", "netmon_event.event_desc.channel",
1942
16
      FT_UINT8, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1943
16
    },
1944
16
    { &hf_netmon_event_event_desc_level,
1945
16
      { "Level", "netmon_event.event_desc.level",
1946
16
      FT_UINT8, BASE_DEC, VALS(event_level_vals), 0x0, NULL, HFILL }
1947
16
    },
1948
16
    { &hf_netmon_event_event_desc_opcode,
1949
16
      { "Opcode", "netmon_event.event_desc.opcode",
1950
16
      FT_UINT8, BASE_HEX, VALS(opcode_vals), 0x0, NULL, HFILL }
1951
16
    },
1952
16
    { &hf_netmon_event_event_desc_task,
1953
16
      { "Task", "netmon_event.event_desc.task",
1954
16
      FT_UINT16, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1955
16
    },
1956
16
    { &hf_netmon_event_event_desc_keyword,
1957
16
      { "Keyword", "netmon_event.event_desc.keyword",
1958
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
1959
16
    },
1960
16
    { &hf_netmon_event_kernel_time,
1961
16
      { "Kernel time", "netmon_event.kernel_time",
1962
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
1963
16
    },
1964
16
    { &hf_netmon_event_user_time,
1965
16
      { "User time", "netmon_event.user_time",
1966
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
1967
16
    },
1968
16
    { &hf_netmon_event_processor_time,
1969
16
      { "Processor time", "netmon_event.processor_time",
1970
16
      FT_UINT64, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1971
16
    },
1972
16
    { &hf_netmon_event_activity_id,
1973
16
      { "Activity ID", "netmon_event.activity_id",
1974
16
      FT_GUID, BASE_NONE, NULL, 0x0, NULL, HFILL }
1975
16
    },
1976
16
    { &hf_netmon_event_processor_number,
1977
16
      { "Processor number", "netmon_event.processor_number",
1978
16
      FT_UINT8, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1979
16
    },
1980
16
    { &hf_netmon_event_alignment,
1981
16
      { "Alignment", "netmon_event.alignment",
1982
16
      FT_UINT8, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1983
16
    },
1984
16
    { &hf_netmon_event_logger_id,
1985
16
      { "Logger ID", "netmon_event.logger_id",
1986
16
      FT_UINT16, BASE_DEC_HEX, NULL, 0x0, NULL, HFILL }
1987
16
    },
1988
16
    { &hf_netmon_event_extended_data_count,
1989
16
      { "Extended data count", "netmon_event.extended_data_count",
1990
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
1991
16
    },
1992
16
    { &hf_netmon_event_user_data_length,
1993
16
      { "User data length", "netmon_event.user_data_length",
1994
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
1995
16
    },
1996
16
    { &hf_netmon_event_reassembled,
1997
16
      { "Reassembled", "netmon_event.reassembled",
1998
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
1999
16
    },
2000
16
    { &hf_netmon_event_extended_data_reserved,
2001
16
      { "Reserved", "netmon_event.extended_data.reserved",
2002
16
      FT_UINT16, BASE_HEX, NULL, 0x0, NULL, HFILL }
2003
16
    },
2004
16
    { &hf_netmon_event_extended_data_type,
2005
16
      { "Extended info type", "netmon_event.extended_data.type",
2006
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2007
16
    },
2008
16
    { &hf_netmon_event_extended_data_linkage,
2009
16
      { "Additional extended data", "netmon_event.extended_data.linkage",
2010
16
      FT_BOOLEAN, 16, TFS(&tfs_yes_no), 0x0001, NULL, HFILL }
2011
16
    },
2012
16
    { &hf_netmon_event_extended_data_reserved2,
2013
16
      { "Reserved", "netmon_event.extended_data.reserved2",
2014
16
      FT_UINT16, BASE_HEX, NULL, 0xFFFE, NULL, HFILL }
2015
16
    },
2016
16
    { &hf_netmon_event_extended_data_size,
2017
16
      { "Extended data size", "netmon_event.extended_data.size",
2018
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2019
16
    },
2020
16
    { &hf_netmon_event_extended_data,
2021
16
      { "Extended data", "netmon_event.extended_data",
2022
16
      FT_BYTES, BASE_NONE|BASE_ALLOW_ZERO, NULL, 0x0, NULL, HFILL }
2023
16
    },
2024
16
    { &hf_netmon_event_user_data,
2025
16
      { "User data", "netmon_event.user_data",
2026
16
      FT_BYTES, BASE_NONE|BASE_ALLOW_ZERO, NULL, 0x0, NULL, HFILL }
2027
16
    },
2028
16
  };
2029
2030
16
  static hf_register_info hf_filter[] = {
2031
16
    { &hf_netmon_filter_version,
2032
16
      { "Version", "netmon_filter.version",
2033
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2034
16
    },
2035
16
    { &hf_netmon_filter_type,
2036
16
      { "Filter type", "netmon_filter.type",
2037
16
      FT_UINT32, BASE_DEC|BASE_RANGE_STRING, RVALS(filter_types), 0x0, NULL, HFILL }
2038
16
    },
2039
16
    { &hf_netmon_filter_app_major_version,
2040
16
      { "App Major Version", "netmon_filter.app_major_version",
2041
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2042
16
    },
2043
16
    { &hf_netmon_filter_app_minor_version,
2044
16
      { "App Minor Version", "netmon_filter.app_minor_version",
2045
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2046
16
    },
2047
16
    { &hf_netmon_filter_app_name,
2048
16
      { "Application Name", "netmon_filter.app_name",
2049
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2050
16
    },
2051
16
    { &hf_netmon_filter_filter,
2052
16
      { "Filter", "netmon_filter.filter",
2053
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2054
16
    },
2055
16
  };
2056
2057
16
  static hf_register_info hf_network_info[] = {
2058
16
    { &hf_netmon_network_info_version,
2059
16
      { "Version", "netmon_network_info.version",
2060
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2061
16
    },
2062
16
    { &hf_netmon_network_info_adapter_count,
2063
16
      { "Adapter count", "netmon_network_info.adapter_count",
2064
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2065
16
    },
2066
16
    { &hf_netmon_network_info_computer_name,
2067
16
      { "Computer name", "netmon_network_info.computer_name",
2068
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2069
16
    },
2070
16
    { &hf_netmon_network_info_friendly_name,
2071
16
      { "Friendly name", "netmon_network_info.friendly_name",
2072
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2073
16
    },
2074
16
    { &hf_netmon_network_info_description,
2075
16
      { "Description", "netmon_network_info.description",
2076
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2077
16
    },
2078
16
    { &hf_netmon_network_info_miniport_guid,
2079
16
      { "Miniport GUID", "netmon_network_info.miniport_guid",
2080
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2081
16
    },
2082
16
    { &hf_netmon_network_info_media_type,
2083
16
      { "Media type", "netmon_network_info.media_type",
2084
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2085
16
    },
2086
16
    { &hf_netmon_network_info_mtu,
2087
16
      { "MTU", "netmon_network_info.mtu",
2088
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2089
16
    },
2090
16
    { &hf_netmon_network_info_link_speed,
2091
16
      { "Link speed", "netmon_network_info.link_speed",
2092
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2093
16
    },
2094
16
    { &hf_netmon_network_info_mac_address,
2095
16
      { "MAC address", "netmon_network_info.mac_address",
2096
16
      FT_ETHER, BASE_NONE, NULL, 0x0, NULL, HFILL }
2097
16
    },
2098
16
    { &hf_netmon_network_info_ipv4_count,
2099
16
      { "IPv4 count", "netmon_network_info.ipv4_count",
2100
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2101
16
    },
2102
16
    { &hf_netmon_network_info_ipv6_count,
2103
16
      { "IPv6 count", "netmon_network_info.ipv6_count",
2104
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2105
16
    },
2106
16
    { &hf_netmon_network_info_gateway_count,
2107
16
      { "Gateway count", "netmon_network_info.gateway_count",
2108
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2109
16
    },
2110
16
    { &hf_netmon_network_info_dhcp_server_count,
2111
16
      { "DHCP server count", "netmon_network_info.dhcp_server_count",
2112
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2113
16
    },
2114
16
    { &hf_netmon_network_info_dns_ipv4_count,
2115
16
      { "DNS IPv4 count", "netmon_network_info.dns_ipv4_count",
2116
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2117
16
    },
2118
16
    { &hf_netmon_network_info_dns_ipv6_count,
2119
16
      { "DNS IPv6 count", "netmon_network_info.dns_ipv6_count",
2120
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2121
16
    },
2122
16
    { &hf_netmon_network_info_ipv4,
2123
16
      { "IPv4 address", "netmon_network_info.ipv4",
2124
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2125
16
    },
2126
16
    { &hf_netmon_network_info_subnet,
2127
16
      { "Subnet mask", "netmon_network_info.subnet",
2128
16
      FT_IPv4, BASE_NETMASK, NULL, 0x0, NULL, HFILL }
2129
16
    },
2130
16
    { &hf_netmon_network_info_ipv6,
2131
16
      { "IPv6 address", "netmon_network_info.ipv6",
2132
16
      FT_IPv6, BASE_NONE, NULL, 0x0, NULL, HFILL }
2133
16
    },
2134
16
    { &hf_netmon_network_info_gateway,
2135
16
      { "Gateway address", "netmon_network_info.gateway",
2136
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2137
16
    },
2138
16
    { &hf_netmon_network_info_dhcp_server,
2139
16
      { "DHCP Server", "netmon_network_info.dhcp_server",
2140
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2141
16
    },
2142
16
    { &hf_netmon_network_info_dns_ipv4,
2143
16
      { "DNS IPv4 address", "netmon_network_info.dns_ipv4",
2144
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2145
16
    },
2146
16
    { &hf_netmon_network_info_dns_ipv6,
2147
16
      { "DNS IPv6 address", "netmon_network_info.dns_ipv6",
2148
16
      FT_IPv6, BASE_NONE, NULL, 0x0, NULL, HFILL }
2149
16
    },
2150
16
  };
2151
2152
16
  static hf_register_info hf_system_trace[] = {
2153
16
    { &hf_netmon_system_trace_buffer_size,
2154
16
      { "Buffer size", "netmon_system_trace.buffer_size",
2155
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2156
16
    },
2157
16
    { &hf_netmon_system_trace_version,
2158
16
      { "Version", "netmon_system_trace.version",
2159
16
      FT_UINT32, BASE_HEX_DEC, NULL, 0x0, NULL, HFILL }
2160
16
    },
2161
16
    { &hf_netmon_system_trace_provider_version,
2162
16
      { "Provider version", "netmon_system_trace.provider_version",
2163
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2164
16
    },
2165
16
    { &hf_netmon_system_trace_num_processors,
2166
16
      { "Number of processors", "netmon_system_trace.num_processors",
2167
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2168
16
    },
2169
16
    { &hf_netmon_system_trace_end_time,
2170
16
      { "End time", "netmon_system_trace.end_time",
2171
16
      FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0x0, NULL, HFILL }
2172
16
    },
2173
16
    { &hf_netmon_system_trace_timer_resolution,
2174
16
      { "Timer resolution", "netmon_system_trace.timer_resolution",
2175
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2176
16
    },
2177
16
    { &hf_netmon_system_trace_max_file_size,
2178
16
      { "Max file size", "netmon_system_trace.max_file_size",
2179
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2180
16
    },
2181
16
    { &hf_netmon_system_trace_log_file_mode,
2182
16
      { "Log file mode", "netmon_system_trace.log_file_mode",
2183
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2184
16
    },
2185
16
    { &hf_netmon_system_trace_buffers_written,
2186
16
      { "Buffers written", "netmon_system_trace.buffers_written",
2187
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2188
16
    },
2189
16
    { &hf_netmon_system_trace_start_buffers,
2190
16
      { "Start buffers", "netmon_system_trace.start_buffers",
2191
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2192
16
    },
2193
16
    { &hf_netmon_system_trace_pointers_size,
2194
16
      { "Pointers size", "netmon_system_trace.pointers_size",
2195
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2196
16
    },
2197
16
    { &hf_netmon_system_trace_events_lost,
2198
16
      { "Events lost", "netmon_system_trace.events_lost",
2199
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2200
16
    },
2201
16
    { &hf_netmon_system_trace_cpu_speed,
2202
16
      { "CPU speed", "netmon_system_trace.cpu_speed",
2203
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2204
16
    },
2205
16
    { &hf_netmon_system_trace_logger_name,
2206
16
      { "Logger name", "netmon_system_trace.logger_name",
2207
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2208
16
    },
2209
16
    { &hf_netmon_system_trace_log_file_name_ptr,
2210
16
      { "Log file name", "netmon_system_trace.log_file_name_ptr",
2211
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2212
16
    },
2213
16
    { &hf_netmon_system_trace_time_zone_info,
2214
16
      { "Time zone info", "netmon_system_trace.time_zone_info",
2215
16
      FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }
2216
16
    },
2217
16
    { &hf_netmon_system_trace_boot_time,
2218
16
      { "Boot time", "netmon_system_trace.boot_time",
2219
16
      FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0x0, NULL, HFILL }
2220
16
    },
2221
16
    { &hf_netmon_system_trace_perf_freq,
2222
16
      { "Perf freq", "netmon_system_trace.pref_freq",
2223
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2224
16
    },
2225
16
    { &hf_netmon_system_trace_start_time,
2226
16
      { "Start time", "netmon_system_trace.start_time",
2227
16
      FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0x0, NULL, HFILL }
2228
16
    },
2229
16
    { &hf_netmon_system_trace_reserved_flags,
2230
16
      { "Reserved Flags", "netmon_system_trace.reserved_flags",
2231
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2232
16
    },
2233
16
    { &hf_netmon_system_trace_buffers_lost,
2234
16
      { "Buffers lost", "netmon_system_trace.buffers_lost",
2235
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2236
16
    },
2237
16
    { &hf_netmon_system_trace_session_name,
2238
16
      { "Session name", "netmon_system_trace.session_name",
2239
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2240
16
    },
2241
16
    { &hf_netmon_system_trace_log_file_name,
2242
16
      { "Log file name", "netmon_system_trace.log_file_name",
2243
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2244
16
    },
2245
16
    { &hf_netmon_system_trace_group_mask1,
2246
16
      { "Group Mask1", "netmon_system_trace.group_mask1",
2247
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2248
16
    },
2249
16
    { &hf_netmon_system_trace_group_mask2,
2250
16
      { "Group Mask2", "netmon_system_trace.group_mask2",
2251
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2252
16
    },
2253
16
    { &hf_netmon_system_trace_group_mask3,
2254
16
      { "Group Mask3", "netmon_system_trace.group_mask3",
2255
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2256
16
    },
2257
16
    { &hf_netmon_system_trace_group_mask4,
2258
16
      { "Group Mask4", "netmon_system_trace.group_mask4",
2259
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2260
16
    },
2261
16
    { &hf_netmon_system_trace_group_mask5,
2262
16
      { "Group Mask5", "netmon_system_trace.group_mask5",
2263
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2264
16
    },
2265
16
    { &hf_netmon_system_trace_group_mask6,
2266
16
      { "Group Mask6", "netmon_system_trace.group_mask6",
2267
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2268
16
    },
2269
16
    { &hf_netmon_system_trace_group_mask7,
2270
16
      { "Group Mask7", "netmon_system_trace.group_mask7",
2271
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2272
16
    },
2273
16
    { &hf_netmon_system_trace_group_mask8,
2274
16
      { "Group Mask8", "netmon_system_trace.group_mask8",
2275
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2276
16
    },
2277
16
    { &hf_netmon_system_trace_kernel_event_version,
2278
16
      { "Kernel event version", "netmon_system_trace.kernel_event_version",
2279
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2280
16
    },
2281
16
  };
2282
2283
16
  static hf_register_info hf_system_config[] = {
2284
16
    { &hf_netmon_system_config_mhz,
2285
16
      { "Mhz", "netmon_system_config.mhz",
2286
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2287
16
    },
2288
16
    { &hf_netmon_system_config_num_processors,
2289
16
      { "Number of processors", "netmon_system_config.num_processors",
2290
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2291
16
    },
2292
16
    { &hf_netmon_system_config_mem_size,
2293
16
      { "Memory size", "netmon_system_config.mem_size",
2294
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2295
16
    },
2296
16
    { &hf_netmon_system_config_page_size,
2297
16
      { "Page size", "netmon_system_config.page_size",
2298
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2299
16
    },
2300
16
    { &hf_netmon_system_config_allocation_granularity,
2301
16
      { "Allocation granularity", "netmon_system_config.allocation_granularity",
2302
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2303
16
    },
2304
16
    { &hf_netmon_system_config_computer_name,
2305
16
      { "Computer name", "netmon_system_config.computer_name",
2306
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2307
16
    },
2308
16
    { &hf_netmon_system_config_domain_name,
2309
16
      { "Domain name", "netmon_system_config.domain_name",
2310
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2311
16
    },
2312
16
    { &hf_netmon_system_config_hyper_threading_flag,
2313
16
      { "Hyper threading flag", "netmon_system_config.hyper_threading_flag",
2314
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2315
16
    },
2316
16
    { &hf_netmon_system_config_disk_number,
2317
16
      { "Disk number", "netmon_system_config.disk_number",
2318
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2319
16
    },
2320
16
    { &hf_netmon_system_config_bytes_per_sector,
2321
16
      { "Bytes per sector", "netmon_system_config.bytes_per_sector",
2322
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2323
16
    },
2324
16
    { &hf_netmon_system_config_sectors_per_track,
2325
16
      { "Sectors per track", "netmon_system_config.sectors_per_track",
2326
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2327
16
    },
2328
16
    { &hf_netmon_system_config_tracks_per_cylinder,
2329
16
      { "Tracks per cylinder", "netmon_system_config.tracks_per_cylinder",
2330
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2331
16
    },
2332
16
    { &hf_netmon_system_config_cylinders,
2333
16
      { "Cylinders", "netmon_system_config.cylinders",
2334
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2335
16
    },
2336
16
    { &hf_netmon_system_config_scsi_port,
2337
16
      { "SCSI port", "netmon_system_config.scsi_port",
2338
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2339
16
    },
2340
16
    { &hf_netmon_system_config_scsi_path,
2341
16
      { "SCSI path", "netmon_system_config.scsi_path",
2342
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2343
16
    },
2344
16
    { &hf_netmon_system_config_scsi_target,
2345
16
      { "SCSI target", "netmon_system_config.csi_target",
2346
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2347
16
    },
2348
16
    { &hf_netmon_system_config_scsi_lun,
2349
16
      { "SCSI lun", "netmon_system_config.scsi_lun",
2350
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2351
16
    },
2352
16
    { &hf_netmon_system_config_manufacturer,
2353
16
      { "Manufacturer", "netmon_system_config.manufacturer",
2354
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2355
16
    },
2356
16
    { &hf_netmon_system_config_partition_count,
2357
16
      { "Partition count", "netmon_system_config.partition_count",
2358
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2359
16
    },
2360
16
    { &hf_netmon_system_config_write_cache_enabled,
2361
16
      { "Write cache enabled", "netmon_system_config.write_cache_enabled",
2362
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2363
16
    },
2364
16
    { &hf_netmon_system_config_pad,
2365
16
      { "Pad", "netmon_system_config.pad",
2366
16
      FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }
2367
16
    },
2368
16
    { &hf_netmon_system_config_boot_drive_letter,
2369
16
      { "Boot drive letter", "netmon_system_config.boot_drive_letter",
2370
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2371
16
    },
2372
16
    { &hf_netmon_system_config_spare,
2373
16
      { "Spare", "netmon_system_config.spare",
2374
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2375
16
    },
2376
16
    { &hf_netmon_system_config_start_offset,
2377
16
      { "Start offset", "netmon_system_config.start_offset",
2378
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2379
16
    },
2380
16
    { &hf_netmon_system_config_partition_size,
2381
16
      { "Partition size", "netmon_system_config.partition_size",
2382
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2383
16
    },
2384
16
    { &hf_netmon_system_config_size,
2385
16
      { "Size", "netmon_system_config.size",
2386
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2387
16
    },
2388
16
    { &hf_netmon_system_config_drive_type,
2389
16
      { "Drive type", "netmon_system_config.drive_type",
2390
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2391
16
    },
2392
16
    { &hf_netmon_system_config_drive_letter,
2393
16
      { "Drive letter", "netmon_system_config.drive_letter",
2394
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2395
16
    },
2396
16
    { &hf_netmon_system_config_partition_number,
2397
16
      { "Partition number", "netmon_system_config.partition_number",
2398
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2399
16
    },
2400
16
    { &hf_netmon_system_config_sectors_per_cluster,
2401
16
      { "Sectors per cluster", "netmon_system_config.sectors_per_cluster",
2402
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2403
16
    },
2404
16
    { &hf_netmon_system_config_num_free_clusters,
2405
16
      { "Number of free clusters", "netmon_system_config.num_free_clusters",
2406
16
      FT_INT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2407
16
    },
2408
16
    { &hf_netmon_system_config_total_num_clusters,
2409
16
      { "Total number of clusters", "netmon_system_config.total_num_clusters",
2410
16
      FT_INT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2411
16
    },
2412
16
    { &hf_netmon_system_config_file_system,
2413
16
      { "File system", "netmon_system_config.file_system",
2414
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2415
16
    },
2416
16
    { &hf_netmon_system_config_volume_ext,
2417
16
      { "Volume ext", "netmon_system_config.volume_ext",
2418
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2419
16
    },
2420
16
    { &hf_netmon_system_config_physical_addr,
2421
16
      { "Physical address", "netmon_system_config.physical_addr",
2422
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2423
16
    },
2424
16
    { &hf_netmon_system_config_physical_addr_len,
2425
16
      { "Physical address length", "netmon_system_config.physical_addr_len",
2426
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2427
16
    },
2428
16
    { &hf_netmon_system_config_ipv4_index,
2429
16
      { "IPv4 index", "netmon_system_config.ipv4_index",
2430
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2431
16
    },
2432
16
    { &hf_netmon_system_config_ipv6_index,
2433
16
      { "IPv6 index", "netmon_system_config.ipv6_index",
2434
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2435
16
    },
2436
16
    { &hf_netmon_system_config_nic_description,
2437
16
      { "File system", "netmon_system_config.file_system",
2438
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2439
16
    },
2440
16
    { &hf_netmon_system_config_ipaddresses,
2441
16
      { "IP addresses", "netmon_system_config.ipaddresses",
2442
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2443
16
    },
2444
16
    { &hf_netmon_system_config_dns_server_addresses,
2445
16
      { "DNS server addresses", "netmon_system_config.dns_server_addresses",
2446
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2447
16
    },
2448
16
    { &hf_netmon_system_config_memory_size,
2449
16
      { "Memory size", "netmon_system_config.memory_size",
2450
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2451
16
    },
2452
16
    { &hf_netmon_system_config_x_resolution,
2453
16
      { "X resolution", "netmon_system_config.x_resolution",
2454
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2455
16
    },
2456
16
    { &hf_netmon_system_config_y_resolution,
2457
16
      { "Y resolution", "netmon_system_config.y_resolution",
2458
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2459
16
    },
2460
16
    { &hf_netmon_system_config_bits_per_pixel,
2461
16
      { "Bits per pixel", "netmon_system_config.bits_per_pixel",
2462
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2463
16
    },
2464
16
    { &hf_netmon_system_config_vrefresh,
2465
16
      { "VRefresh", "netmon_system_config.vrefresh",
2466
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2467
16
    },
2468
16
    { &hf_netmon_system_config_chip_type,
2469
16
      { "Chip type", "netmon_system_config.chip_type",
2470
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2471
16
    },
2472
16
    { &hf_netmon_system_config_dac_type,
2473
16
      { "DAC type", "netmon_system_config.dac_type",
2474
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2475
16
    },
2476
16
    { &hf_netmon_system_config_adapter_string,
2477
16
      { "Adapter string", "netmon_system_config.adapter_string",
2478
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2479
16
    },
2480
16
    { &hf_netmon_system_config_bios_string,
2481
16
      { "BIOS string", "netmon_system_config.bios_string",
2482
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2483
16
    },
2484
16
    { &hf_netmon_system_config_device_id,
2485
16
      { "Device ID", "netmon_system_config.device_id",
2486
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2487
16
    },
2488
16
    { &hf_netmon_system_config_state_flags,
2489
16
      { "State flags", "netmon_system_config.state_flags",
2490
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2491
16
    },
2492
16
    { &hf_netmon_system_config_process_id,
2493
16
      { "Process ID", "netmon_system_config.process_id",
2494
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2495
16
    },
2496
16
    { &hf_netmon_system_config_service_state,
2497
16
      { "Service state", "netmon_system_config.service_state",
2498
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2499
16
    },
2500
16
    { &hf_netmon_system_config_sub_process_tag,
2501
16
      { "Subprocess tag", "netmon_system_config.sub_process_tag",
2502
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2503
16
    },
2504
16
    { &hf_netmon_system_config_service_name,
2505
16
      { "Service name", "netmon_system_config.service_name",
2506
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2507
16
    },
2508
16
    { &hf_netmon_system_config_display_name,
2509
16
      { "Display name", "netmon_system_config.display_name",
2510
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2511
16
    },
2512
16
    { &hf_netmon_system_config_process_name,
2513
16
      { "Process name", "netmon_system_config.process_name",
2514
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2515
16
    },
2516
16
    { &hf_netmon_system_config_s1,
2517
16
      { "S1", "netmon_system_config.s1",
2518
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2519
16
    },
2520
16
    { &hf_netmon_system_config_s2,
2521
16
      { "S2", "netmon_system_config.s2",
2522
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2523
16
    },
2524
16
    { &hf_netmon_system_config_s3,
2525
16
      { "S3", "netmon_system_config.s3",
2526
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2527
16
    },
2528
16
    { &hf_netmon_system_config_s4,
2529
16
      { "S4", "netmon_system_config.s4",
2530
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2531
16
    },
2532
16
    { &hf_netmon_system_config_s5,
2533
16
      { "S5", "netmon_system_config.s5",
2534
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2535
16
    },
2536
16
    { &hf_netmon_system_config_tcb_table_partitions,
2537
16
      { "Tcb table partitions", "netmon_system_config.tcb_table_partitions",
2538
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2539
16
    },
2540
16
    { &hf_netmon_system_config_max_hash_table_size,
2541
16
      { "Max hash table size", "netmon_system_config.max_hash_table_size",
2542
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2543
16
    },
2544
16
    { &hf_netmon_system_config_max_user_port,
2545
16
      { "Max user port", "netmon_system_config.max_user_port",
2546
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2547
16
    },
2548
16
    { &hf_netmon_system_config_tcp_timed_wait_delay,
2549
16
      { "TCP timed wait delay", "netmon_system_config.tcp_timed_wait_delay",
2550
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2551
16
    },
2552
16
    { &hf_netmon_system_config_irq_affinity,
2553
16
      { "IRQ affinity", "netmon_system_config.irq_affinity",
2554
16
      FT_UINT64, BASE_DEC, NULL, 0x0, NULL, HFILL }
2555
16
    },
2556
16
    { &hf_netmon_system_config_irq_num,
2557
16
      { "IRQ", "netmon_system_config.irq_num",
2558
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2559
16
    },
2560
16
    { &hf_netmon_system_config_device_desc_len,
2561
16
      { "Device description length", "netmon_system_config.device_desc_len",
2562
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2563
16
    },
2564
16
    { &hf_netmon_system_config_device_desc,
2565
16
      { "Device description", "netmon_system_config.device_desc",
2566
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2567
16
    },
2568
16
    { &hf_netmon_system_config_friendly_name,
2569
16
      { "Friendly name", "netmon_system_config.friendly_name",
2570
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2571
16
    },
2572
16
    { &hf_netmon_system_config_device_id_len,
2573
16
      { "Device ID length", "netmon_system_config.device_id_len",
2574
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2575
16
    },
2576
16
    { &hf_netmon_system_config_friendly_name_len,
2577
16
      { "Friendly name length", "netmon_system_config.friendly_name_len",
2578
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2579
16
    },
2580
16
    { &hf_netmon_system_config_target_id,
2581
16
      { "Target ID", "netmon_system_config.target_id",
2582
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2583
16
    },
2584
16
    { &hf_netmon_system_config_device_type,
2585
16
      { "Device type", "netmon_system_config.device_type",
2586
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2587
16
    },
2588
16
    { &hf_netmon_system_config_device_timing_mode,
2589
16
      { "Device timing mode", "netmon_system_config.device_timing_mode",
2590
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2591
16
    },
2592
16
    { &hf_netmon_system_config_location_information_len,
2593
16
      { "Location information length", "netmon_system_config.location_information_len",
2594
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2595
16
    },
2596
16
    { &hf_netmon_system_config_location_information,
2597
16
      { "Location information", "netmon_system_config.location_information",
2598
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2599
16
    },
2600
16
    { &hf_netmon_system_config_system_manufacturer,
2601
16
      { "System manufacturer", "netmon_system_config.system_manufacturer",
2602
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2603
16
    },
2604
16
    { &hf_netmon_system_config_system_product_name,
2605
16
      { "System product name", "netmon_system_config.system_product_name",
2606
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2607
16
    },
2608
16
    { &hf_netmon_system_config_bios_date,
2609
16
      { "BIOS date", "netmon_system_config.bios_date",
2610
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2611
16
    },
2612
16
    { &hf_netmon_system_config_bios_version,
2613
16
      { "BIOS version", "netmon_system_config.bios_version",
2614
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2615
16
    },
2616
16
    { &hf_netmon_system_config_load_order_group,
2617
16
      { "Load order group", "netmon_system_config.load_order_group",
2618
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2619
16
    },
2620
16
    { &hf_netmon_system_config_svc_host_group,
2621
16
      { "svchost group", "netmon_system_config.svc_host_group",
2622
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2623
16
    },
2624
16
    { &hf_netmon_system_config_irq_group,
2625
16
      { "IRQ group", "netmon_system_config.irq_group",
2626
16
      FT_UINT16, BASE_DEC, NULL, 0x0, NULL, HFILL }
2627
16
    },
2628
16
    { &hf_netmon_system_config_pdo_name,
2629
16
      { "PDO name", "netmon_system_config.pdo_name",
2630
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2631
16
    },
2632
16
    { &hf_netmon_system_config_nic_name,
2633
16
      { "NIC name", "netmon_system_config.nic_name",
2634
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2635
16
    },
2636
16
    { &hf_netmon_system_config_index,
2637
16
      { "Index", "netmon_system_config.index",
2638
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2639
16
    },
2640
16
    { &hf_netmon_system_config_physical_addr_str,
2641
16
      { "Physical address", "netmon_system_config.physical_addr_str",
2642
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2643
16
    },
2644
16
    { &hf_netmon_system_config_ip_address,
2645
16
      { "IP address", "netmon_system_config.ip_address",
2646
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2647
16
    },
2648
16
    { &hf_netmon_system_config_subnet_mask,
2649
16
      { "Subnet mask", "netmon_system_config.subnet_mask",
2650
16
      FT_IPv4, BASE_NETMASK, NULL, 0x0, NULL, HFILL }
2651
16
    },
2652
16
    { &hf_netmon_system_config_dhcp_server,
2653
16
      { "DHCP server", "netmon_system_config.dhcp_server",
2654
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2655
16
    },
2656
16
    { &hf_netmon_system_config_gateway,
2657
16
      { "Gateway", "netmon_system_config.gateway",
2658
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2659
16
    },
2660
16
    { &hf_netmon_system_config_primary_wins_server,
2661
16
      { "Primary WINS server", "netmon_system_config.primary_wins_server",
2662
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2663
16
    },
2664
16
    { &hf_netmon_system_config_secondary_wins_server,
2665
16
      { "Secondary WINS server", "netmon_system_config.secondary_wins_server",
2666
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2667
16
    },
2668
16
    { &hf_netmon_system_config_dns_server1,
2669
16
      { "DNS server1", "netmon_system_config.dns_server1",
2670
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2671
16
    },
2672
16
    { &hf_netmon_system_config_dns_server2,
2673
16
      { "DNS server2", "netmon_system_config.dns_server2",
2674
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2675
16
    },
2676
16
    { &hf_netmon_system_config_dns_server3,
2677
16
      { "DNS server3", "netmon_system_config.dns_server3",
2678
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2679
16
    },
2680
16
    { &hf_netmon_system_config_dns_server4,
2681
16
      { "DNS server4", "netmon_system_config.dns_server4",
2682
16
      FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }
2683
16
    },
2684
16
    { &hf_netmon_system_config_data,
2685
16
      { "Data", "netmon_system_config.data",
2686
16
      FT_UINT32, BASE_HEX, NULL, 0x0, NULL, HFILL }
2687
16
    },
2688
16
  };
2689
2690
16
  static hf_register_info hf_process[] = {
2691
16
    { &hf_netmon_process_unique_process_key,
2692
16
      { "Unique process key", "netmon_process.unique_process_key",
2693
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2694
16
    },
2695
16
    { &hf_netmon_process_process_id,
2696
16
      { "Process ID", "netmon_process.process_id",
2697
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2698
16
    },
2699
16
    { &hf_netmon_process_parent_id,
2700
16
      { "Parent ID", "netmon_process.parent_id",
2701
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2702
16
    },
2703
16
    { &hf_netmon_process_session_id,
2704
16
      { "Session ID", "netmon_process.session_id",
2705
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2706
16
    },
2707
16
    { &hf_netmon_process_exit_status,
2708
16
      { "Exit status", "netmon_process.exit_status",
2709
16
      FT_INT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2710
16
    },
2711
16
    { &hf_netmon_process_directory_table_base,
2712
16
      { "Directory table base", "netmon_process.directory_table_base",
2713
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2714
16
    },
2715
16
    { &hf_netmon_process_unknown,
2716
16
      { "Unknown", "netmon_process.unknown",
2717
16
      FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }
2718
16
    },
2719
16
    { &hf_netmon_process_user_sid_revision,
2720
16
      { "User SID Revision", "netmon_process.user_sid.revision",
2721
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2722
16
    },
2723
16
    { &hf_netmon_process_user_sid_subauth_count,
2724
16
      { "User SID Subauth count", "netmon_process.user_sid.subauth_count",
2725
16
      FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }
2726
16
    },
2727
16
    { &hf_netmon_process_user_sid_id,
2728
16
      { "User SID Identifier Authority", "netmon_process.user_sid.id",
2729
16
      FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }
2730
16
    },
2731
16
    { &hf_netmon_process_user_sid_authority,
2732
16
      { "User SID Authority", "netmon_process.user_sid.authority",
2733
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2734
16
    },
2735
16
    { &hf_netmon_process_image_file_name,
2736
16
      { "Image file name", "netmon_process.image_file_name",
2737
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2738
16
    },
2739
16
    { &hf_netmon_process_command_line,
2740
16
      { "Commandline", "netmon_process.command_line",
2741
16
      FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }
2742
16
    },
2743
16
    { &hf_netmon_process_page_directory_base,
2744
16
      { "Page directory base", "netmon_process.page_directory_base",
2745
16
      FT_UINT64, BASE_HEX, NULL, 0x0, NULL, HFILL }
2746
16
    },
2747
16
    { &hf_netmon_process_page_fault_count,
2748
16
      { "Page fault count", "netmon_process.page_fault_count",
2749
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2750
16
    },
2751
16
    { &hf_netmon_process_handle_count,
2752
16
      { "Handle count", "netmon_process.handle_count",
2753
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2754
16
    },
2755
16
    { &hf_netmon_process_reserved,
2756
16
      { "Reserved", "netmon_process.reserved",
2757
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2758
16
    },
2759
16
    { &hf_netmon_process_peak_virtual_size,
2760
16
      { "Peak virtual size", "netmon_process.peak_virtual_size",
2761
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2762
16
    },
2763
16
    { &hf_netmon_process_peak_working_set_size,
2764
16
      { "Peak working set size", "netmon_process.peak_working_set_size",
2765
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2766
16
    },
2767
16
    { &hf_netmon_process_peak_page_file_usage,
2768
16
      { "Peak page file usage", "netmon_process.peak_page_file_usage",
2769
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2770
16
    },
2771
16
    { &hf_netmon_process_quota_peak_paged_pool_usage,
2772
16
      { "Quota peak paged pool usage", "netmon_process.quota_peak_paged_pool_usage",
2773
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2774
16
    },
2775
16
    { &hf_netmon_process_quota_peak_non_paged_pool_usage,
2776
16
      { "Quota peak non-paged pool usage", "netmon_process.quota_peak_non_paged_pool_usage",
2777
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2778
16
    },
2779
16
    { &hf_netmon_process_virtual_size,
2780
16
      { "Virtual size", "netmon_process.virtual_size",
2781
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2782
16
    },
2783
16
    { &hf_netmon_process_workingset_size,
2784
16
      { "Working set size", "netmon_process.workingset_size",
2785
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2786
16
    },
2787
16
    { &hf_netmon_process_pagefile_usage,
2788
16
      { "Pagefile usage", "netmon_process.pagefile_usage",
2789
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2790
16
    },
2791
16
    { &hf_netmon_process_quota_paged_pool_usage,
2792
16
      { "Quota paged pool usage", "netmon_process.quota_paged_pool_usage",
2793
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2794
16
    },
2795
16
    { &hf_netmon_process_quota_non_paged_pool_usage,
2796
16
      { "Quota nonpaged pool usage", "netmon_process.quota_non_paged_pool_usage",
2797
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2798
16
    },
2799
16
    { &hf_netmon_process_private_page_count,
2800
16
      { "Private page count", "netmon_process.private_page_count",
2801
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2802
16
    },
2803
16
    { &hf_netmon_process_directory_table_base32,
2804
16
      { "Directory table base", "netmon_process.directory_table_base32",
2805
16
      FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }
2806
16
    },
2807
16
  };
2808
2809
16
  static int *ett[] = {
2810
16
    &ett_netmon_header,
2811
16
    &ett_netmon_event,
2812
16
    &ett_netmon_event_desc,
2813
16
    &ett_netmon_event_flags,
2814
16
    &ett_netmon_event_property,
2815
16
    &ett_netmon_event_extended_data,
2816
16
    &ett_netmon_filter,
2817
16
    &ett_netmon_network_info,
2818
16
    &ett_netmon_network_info_list,
2819
16
    &ett_netmon_network_info_adapter,
2820
16
    &ett_netmon_system_trace,
2821
16
    &ett_netmon_event_buffer_context,
2822
16
    &ett_netmon_process,
2823
16
    &ett_netmon_sid,
2824
16
    &ett_netmon_system_config,
2825
16
  };
2826
2827
16
  static ei_register_info ei_process[] = {
2828
16
    { &ei_netmon_process_user_sid, { "netmon_process.process_user_sid.invalid", PI_MALFORMED, PI_WARN, "Invalid SID", EXPFILL }},
2829
16
  };
2830
2831
16
  expert_module_t *expert_process;
2832
2833
16
  proto_netmon_header = proto_register_protocol ("Network Monitor Header", "NetMon Header", "netmon_header" );
2834
16
  proto_netmon_event = proto_register_protocol ("Network Monitor Event", "NetMon Event", "netmon_event" );
2835
16
  proto_netmon_filter = proto_register_protocol ("Network Monitor Filter", "NetMon Filter", "netmon_filter" );
2836
16
  proto_netmon_network_info = proto_register_protocol ("Network Monitor Network Info", "NetMon Network Info", "netmon_network_info" );
2837
16
  proto_netmon_system_trace = proto_register_protocol ("Network Monitor System Trace", "NetMon System Trace", "netmon_system_trace" );
2838
16
  proto_netmon_system_config = proto_register_protocol ("Network Monitor System Config", "NetMon System Config", "netmon_system_config" );
2839
16
  proto_netmon_process = proto_register_protocol ("Network Monitor Process", "NetMon Process", "netmon_process" );
2840
2841
16
  provider_id_table = register_dissector_table("netmon.provider_id", "NetMon Provider IDs", proto_netmon_event, FT_GUID, BASE_HEX);
2842
2843
16
  proto_register_field_array(proto_netmon_header, hf_header, array_length(hf_header));
2844
16
  proto_register_field_array(proto_netmon_event, hf_event, array_length(hf_event));
2845
16
  proto_register_field_array(proto_netmon_filter, hf_filter, array_length(hf_filter));
2846
16
  proto_register_field_array(proto_netmon_network_info, hf_network_info, array_length(hf_network_info));
2847
16
  proto_register_field_array(proto_netmon_system_trace, hf_system_trace, array_length(hf_system_trace));
2848
16
  proto_register_field_array(proto_netmon_system_config, hf_system_config, array_length(hf_system_config));
2849
16
  proto_register_field_array(proto_netmon_process, hf_process, array_length(hf_process));
2850
16
  proto_register_subtree_array(ett, array_length(ett));
2851
2852
16
  expert_process = expert_register_protocol(proto_netmon_process);
2853
16
  expert_register_field_array(expert_process, ei_process, array_length(ei_process));
2854
16
}
2855
2856
void proto_reg_handoff_netmon(void)
2857
16
{
2858
16
  dissector_handle_t netmon_event_handle, netmon_filter_handle,
2859
16
            netmon_network_info_handle, netmon_header_handle,
2860
16
            system_trace_handle, system_config_handle, process_handle;
2861
2862
16
  static guid_key system_trace_guid = {{ 0x68fdd900, 0x4a3e, 0x11d1, { 0x84, 0xf4, 0x00, 0x00, 0xf8, 0x04, 0x64, 0xe3 }}, 0 };
2863
16
  static guid_key system_config_guid = {{ 0x01853a65, 0x418f, 0x4f36, { 0xae, 0xfc, 0xdc, 0x0f, 0x1d, 0x2f, 0xd2, 0x35 }}, 0 };
2864
16
  static guid_key process_guid = {{ 0x3d6fa8d0, 0xfe05, 0x11d0, { 0x9d, 0xda, 0x00, 0xc0, 0x4f, 0xd7, 0xba, 0x7c }}, 0 };
2865
2866
16
  netmon_event_handle = create_dissector_handle(dissect_netmon_event, proto_netmon_event);
2867
16
  netmon_filter_handle = create_dissector_handle(dissect_netmon_filter, proto_netmon_filter);
2868
16
  netmon_network_info_handle = create_dissector_handle(dissect_netmon_network_info, proto_netmon_network_info);
2869
16
  netmon_header_handle = create_dissector_handle(dissect_netmon_header, proto_netmon_header);
2870
16
  system_trace_handle = create_dissector_handle(dissect_netmon_system_trace, proto_netmon_system_trace);
2871
16
  system_config_handle = create_dissector_handle(dissect_netmon_system_config, proto_netmon_system_config);
2872
16
  process_handle = create_dissector_handle(dissect_netmon_process, proto_netmon_process);
2873
2874
16
  dissector_add_uint("wtap_encap", WTAP_ENCAP_NETMON_NET_NETEVENT, netmon_event_handle);
2875
16
  dissector_add_uint("wtap_encap", WTAP_ENCAP_NETMON_NET_FILTER, netmon_filter_handle);
2876
16
  dissector_add_uint("wtap_encap", WTAP_ENCAP_NETMON_NETWORK_INFO_EX, netmon_network_info_handle);
2877
16
  dissector_add_uint("wtap_encap", WTAP_ENCAP_NETMON_HEADER, netmon_header_handle);
2878
2879
16
  dissector_add_guid( "netmon.provider_id", &system_trace_guid, system_trace_handle);
2880
16
  dissector_add_guid( "netmon.provider_id", &system_config_guid, system_config_handle);
2881
16
  dissector_add_guid( "netmon.provider_id", &process_guid, process_handle);
2882
2883
16
  wtap_encap_table = find_dissector_table("wtap_encap");
2884
16
}
2885
2886
/*
2887
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
2888
 *
2889
 * Local variables:
2890
 * c-basic-offset: 8
2891
 * tab-width: 8
2892
 * indent-tabs-mode: t
2893
 * End:
2894
 *
2895
 * vi: set shiftwidth=8 tabstop=8 noexpandtab:
2896
 * :indentSize=8:tabSize=8:noTabs=false:
2897
 */