NetHook

inject · intercept · modify · capture

A Windows network-hooking framework that captures, inspects and rewrites a process's traffic — before it is encrypted.

Free 7-day trial · Windows 10 / 11 · 64-bit

See plaintext, pre-TLS

IAT hooks on WinSock, Schannel/TLS, WinINet, WinHTTP and file I/O surface data before it is encrypted on the wire.

Intercept & modify live

Hold each packet, edit it in hex or text, then forward, drop or rewrite it on the fly — or block a process entirely.

Capture to disk

Record sessions to .pcap and raw dumps for later analysis in your tools of choice.

32- & 64-bit, any target

Inject into either architecture from one UI, auto-attach by process name, and elevate to SYSTEM for privileged targets.

Many processes, in parallel

Inject into and attach to multiple processes at once — each gets its own live session and tab. A licensed install runs unlimited targets in parallel; the trial is limited to one at a time.

Global & per-injection settings

Set capture, intercept, block, size limits and which APIs to hook as global defaults — then override any of them live, per injected process, without re-attaching.

Hooks WinSock Schannel / TLS WinINet WinHTTP File I/O