- Socket (& flow) events are now associated with a endpointId/parentEndpointId pair that allows the tracking of socket operations. - A single socket CLOSE event replaces the UNBIND and DISCONNECT events. - A new flag addr.Sniffed indicates if the event was sniffed or not. Some events (CLOSE) are always sniffed, regardless of the flags. - All filter language numbers are now 128bit. - socketdump.exe can now optionally block events.