{"_id":"@bun-win32/fltlib","_rev":"4-f9ca8e1c7249177dfc97907964c4b443","name":"@bun-win32/fltlib","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"@bun-win32/fltlib","version":"1.0.0","keywords":["bun","ffi","win32","windows","fltlib","minifilter","filter-manager","bindings","typescript","dll"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/fltlib@1.0.0","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"18b4186a979bf2461dcb3da6d8f31dc7e3efced9","tarball":"https://registry.npmjs.org/@bun-win32/fltlib/-/fltlib-1.0.0.tgz","fileCount":6,"integrity":"sha512-6lueTd+H6G6QHklF+UY2PDNts2HEEqZZFPVUSvJORRA10SRjNsTfJ6EYLKibnFUz40ERWgW7t4isi2VQxbJAVg==","signatures":[{"sig":"MEYCIQDpcNbgvCZChUajLh8AlFk1IYGjrde7lC5oym+VbQxJwgIhAMHmR6pVyp+f9rv8LPA/UiyMFtHdcbsPLlFINzLr8SLJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22679},"main":"./index.ts","type":"module","module":"index.ts","shasum":"18b4186a979bf2461dcb3da6d8f31dc7e3efced9","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:filter-radar":"bun ./example/filter-radar.ts","example:minifilter-census":"bun ./example/minifilter-census.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-6lueTd+H6G6QHklF+UY2PDNts2HEEqZZFPVUSvJORRA10SRjNsTfJ6EYLKibnFUz40ERWgW7t4isi2VQxbJAVg==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/fltlib"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 Fltlib bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.2"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/fltlib_1.0.0_1779150541768_0.5806709843583149","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bun-win32/fltlib","version":"1.0.1","keywords":["bun","ffi","win32","windows","fltlib","minifilter","filter-manager","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/fltlib@1.0.1","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"4aaf5d2d41f956dfcd1660cd829719d1f1075a7d","tarball":"https://registry.npmjs.org/@bun-win32/fltlib/-/fltlib-1.0.1.tgz","fileCount":6,"integrity":"sha512-nfzlUjquI3E6LxMOF/0O3Ke4/vWIdql7udwlCxWuQ9I4ZU9SZZtdzX5boOC9X7ageE6M+YgIG4uuTHRzlvc3HA==","signatures":[{"sig":"MEQCIG+pLEg5sUfBv3EuVOInHTHpWH7JAPM9JTyVn800v5MxAiBO2YPG0DqyC5VRGatx1wHdAp+9L9e9BtkNTOeS7I3YvA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22684},"main":"./index.ts","type":"module","module":"index.ts","shasum":"4aaf5d2d41f956dfcd1660cd829719d1f1075a7d","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:filter-radar":"bun ./example/filter-radar.ts","example:minifilter-census":"bun ./example/minifilter-census.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-nfzlUjquI3E6LxMOF/0O3Ke4/vWIdql7udwlCxWuQ9I4ZU9SZZtdzX5boOC9X7ageE6M+YgIG4uuTHRzlvc3HA==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/fltlib"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 Fltlib bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.4"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/fltlib_1.0.1_1781130832253_0.053003440747199315","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@bun-win32/fltlib","version":"2.0.0","keywords":["bun","ffi","win32","windows","fltlib","minifilter","filter-manager","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/fltlib@2.0.0","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"286512f477066678ec1ff9a4cc979fd4bd6d6508","tarball":"https://registry.npmjs.org/@bun-win32/fltlib/-/fltlib-2.0.0.tgz","fileCount":6,"integrity":"sha512-ZCEEQGoMyfBa/OQUx+V5ZvQ6kDtXqC4e5sUtz1t4cAt4G6iFLnA6a8pWhQCQ5kBZqDeJk36KNDllfTtWz/dMBw==","signatures":[{"sig":"MEUCIQDj/qJrcMcgsTq6se8vOYWDZYM14EWZuu6lHfe6kvQuRQIgSwVV/JdETWlaMJB0Uf0OmldE1MV1jKeEDoXqhm9ZJHE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24239},"main":"./index.ts","type":"module","module":"index.ts","shasum":"286512f477066678ec1ff9a4cc979fd4bd6d6508","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:filter-radar":"bun ./example/filter-radar.ts","example:minifilter-census":"bun ./example/minifilter-census.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"_integrity":"sha512-ZCEEQGoMyfBa/OQUx+V5ZvQ6kDtXqC4e5sUtz1t4cAt4G6iFLnA6a8pWhQCQ5kBZqDeJk36KNDllfTtWz/dMBw==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/fltlib"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 Fltlib bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"26.3.0","dependencies":{"@bun-win32/core":"2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/fltlib_2.0.0_1782435310278_0.02192511755400539","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"author":"Stev Peifer <stev.p@outlook.com>","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dependencies":{"@bun-win32/core":"2.0.1"},"description":"Zero-dependency, zero-overhead Win32 Fltlib bindings for Bun (FFI) on Windows.","devDependencies":{"@types/bun":"latest"},"exports":{".":"./index.ts"},"license":"MIT","module":"index.ts","name":"@bun-win32/fltlib","peerDependencies":{"typescript":"^5"},"private":false,"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/fltlib"},"type":"module","version":"2.0.1","main":"./index.ts","keywords":["bun","ffi","win32","windows","fltlib","minifilter","filter-manager","bindings","typescript","dll"],"sideEffects":false,"engines":{"bun":">=1.1.0"},"scripts":{"example:minifilter-census":"bun ./example/minifilter-census.ts","example:filter-radar":"bun ./example/filter-radar.ts"},"_id":"@bun-win32/fltlib@2.0.1","_integrity":"sha512-c1mudQ8MGERPhyMZI2IQqlQRcpliiOWZcySHbGZmF9LlFRjJnczqQczcAoZ+XbvUzRpr50QLLM5b10/W2M+rfw==","_nodeVersion":"26.3.0","_npmVersion":"10.8.3","shasum":"da5e322fbc0aaae892a8f43f3b14510e501aaa82","dist":{"integrity":"sha512-c1mudQ8MGERPhyMZI2IQqlQRcpliiOWZcySHbGZmF9LlFRjJnczqQczcAoZ+XbvUzRpr50QLLM5b10/W2M+rfw==","shasum":"da5e322fbc0aaae892a8f43f3b14510e501aaa82","tarball":"https://registry.npmjs.org/@bun-win32/fltlib/-/fltlib-2.0.1.tgz","fileCount":6,"unpackedSize":24239,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC9QxCqM0oVy1F/XbfECVsz1IPHBmNm3nHZFovhEtil4QIhAP+ytC0PqAe5Fo/KZtuR4+0yyyc0W7uWbnZo8ZNBzLfN"}]},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"directories":{},"maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/fltlib_2.0.1_1782437771642_0.5526654211402413"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T00:29:01.700Z","modified":"2026-06-26T01:36:11.945Z","1.0.0":"2026-05-19T00:29:01.928Z","1.0.1":"2026-06-10T22:33:52.378Z","2.0.0":"2026-06-26T00:55:10.402Z","2.0.1":"2026-06-26T01:36:11.792Z"},"bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","homepage":"https://github.com/ObscuritySRL/bun-win32#readme","keywords":["bun","ffi","win32","windows","fltlib","minifilter","filter-manager","bindings","typescript","dll"],"repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/fltlib"},"description":"Zero-dependency, zero-overhead Win32 Fltlib bindings for Bun (FFI) on Windows.","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"readme":"# @bun-win32/Fltlib\n\nZero-dependency, zero-overhead Win32 Fltlib bindings for [Bun](https://bun.sh) on Windows.\n\n## Overview\n\n`@bun-win32/Fltlib` exposes the `fltlib.dll` exports using [Bun](https://bun.sh)'s FFI. It provides a single class, `Fltlib`, which lazily binds native symbols on first use. You can optionally preload a subset or all symbols up-front via `Preload()`.\n\n`fltlib.dll` is the user-mode library for the Windows **Filter Manager** (`fltuser.h`) — the subsystem `fltmc.exe` drives. It covers minifilter / instance / volume / volume-instance enumeration, per-filter and per-instance information queries, MS-DOS volume-name resolution, dynamic minifilter load/unload, attach/detach, handle creation, and the kernel minifilter communication-port message channel.\n\nThe bindings are strongly typed for a smooth DX in TypeScript.\n\n## Features\n\n- [Bun](https://bun.sh)-first ergonomics on Windows 10/11.\n- Direct FFI to `fltlib.dll` (Filter Manager minifilter/instance/volume enumeration and minifilter communication ports).\n- In-source docs in `structs/Fltlib.ts` with links to Microsoft Docs.\n- Lazy binding on first call; optional eager preload (`Fltlib.Preload()`).\n- No wrapper overhead; calls map 1:1 to native APIs.\n- Strongly-typed Win32 aliases (see `types/Fltlib.ts`).\n\n## Requirements\n\n- [Bun](https://bun.sh) runtime\n- Windows 10 or later\n- Enumeration/management calls require an **elevated** (Administrator) process — the same restriction `fltmc` carries. Unelevated, calls execute and return `HRESULT_FROM_WIN32(ERROR_ACCESS_DENIED)` (`0x80070005`).\n\n## Installation\n\n```sh\nbun add @bun-win32/fltlib\n```\n\n## Quick Start\n\n```ts\nimport Fltlib, { FILTER_INFORMATION_CLASS } from '@bun-win32/fltlib';\n\n// Enumerate every registered minifilter (run elevated).\nconst buf = Buffer.alloc(64 * 1024);\nconst bytes = Buffer.alloc(4);\nconst hFind = Buffer.alloc(8);\n\nlet hr = Fltlib.FilterFindFirst(FILTER_INFORMATION_CLASS.FilterFullInformation, buf.ptr!, buf.length, bytes.ptr!, hFind.ptr!);\nwhile (hr === 0) {\n  // FILTER_FULL_INFORMATION: FrameID@4, NumberOfInstances@8, FilterNameLength@12, name@14\n  const nameLen = buf.readUInt16LE(12);\n  console.log(buf.subarray(14, 14 + nameLen).toString('utf16le'));\n  hr = Fltlib.FilterFindNext(hFind.readBigUInt64LE(0), FILTER_INFORMATION_CLASS.FilterFullInformation, buf.ptr!, buf.length, bytes.ptr!);\n}\nFltlib.FilterFindClose(hFind.readBigUInt64LE(0));\n```\n\n> [!NOTE]\n> AI agents: see `AI.md` for the package binding contract and source-navigation guidance. It explains how to use the package without scanning the entire implementation.\n\n## Examples\n\nRun the included examples (run elevated for the live data):\n\n```sh\nbun run example/filter-radar.ts\nbun run example/minifilter-census.ts\n```\n\n- **`filter-radar.ts`** — a live animated ANSI radar of the file-system filter stack: every minifilter rendered as a vendor-tinted bar at its real altitude with a sweeping scan line. Unelevated, it honestly animates an access gate.\n- **`minifilter-census.ts`** — a complete aligned forensic enumeration of every minifilter, its instances (volume + altitude + instance name), and every volume known to the Filter Manager — the picture `fltmc` paints, pure FFI.\n\n## Notes\n\n- Either rely on lazy binding or call `Fltlib.Preload()`.\n- Windows only. Bun runtime required.\n- **SAL types & naming:** nullability is in the **type** — `Optional<T>` (formally optional, SAL `_*opt_`) and `Nullable<T>` (plain `[in]`/`[out]` the docs say can be NULL), the null sentinel derived from `T` (`null` for pointers `LP*`/`P*`, `0n` for handles/by-value addresses); direction is in the **parameter name** — `_out` (`_Out_`), `_in_out` (`_Inout_`), `_In_` bare. See `AI.md` and the repo `AGENTS.md`.\n","readmeFilename":"README.md"}