NetHook
inject · intercept · modify · capture
A Windows network-hooking framework that captures, inspects and rewrites a process's traffic — before it is encrypted.
Free 7-day trial · Windows 10 / 11 · 64-bit
See plaintext, pre-TLS
IAT hooks on WinSock, Schannel/TLS, WinINet, WinHTTP and file I/O surface data before it is encrypted on the wire.
Intercept & modify live
Hold each packet, edit it in hex or text, then forward, drop or rewrite it on the fly — or block a process entirely.
Capture to disk
Record sessions to .pcap and raw dumps for later analysis in
your tools of choice.
32- & 64-bit, any target
Inject into either architecture from one UI, auto-attach by process name, and elevate to SYSTEM for privileged targets.
Many processes, in parallel
Inject into and attach to multiple processes at once — each gets its own live session and tab. A licensed install runs unlimited targets in parallel; the trial is limited to one at a time.
Global & per-injection settings
Set capture, intercept, block, size limits and which APIs to hook as global defaults — then override any of them live, per injected process, without re-attaching.