How WinDivert Driver Functions as a Kernel-Level Filter on Windows
WinDivert functions as a kernel-level network filter by installing a signed driver (WinDivert64.sys) that hooks into the Windows NDIS filter stack, intercepting packets before they reach the TCP/IP stack and routing them through a user-mode DLL for inspection, modification, or reinjection.
The Flowseal/zapret-discord-youtube repository utilizes WinDivert to implement transparent packet filtering for circumventing network censorship. Unlike user-mode networking APIs such as Winsock, WinDivert operates at the kernel level, enabling it to capture and manipulate traffic generated by system services and other drivers that would otherwise remain invisible to standard applications.
Kernel-Level Packet Interception Architecture
WinDivert operates as a callout driver in the Windows Filtering Platform (WFP), sitting between the network interface card (NIC) driver and the TCP/IP protocol stack.
The WinDivert64.sys Driver Component
The core filtering logic resides in bin/WinDivert64.sys, a signed kernel-mode driver distributed within the repository. When loaded via the Windows Service Control Manager (sc create), this driver attaches to the NDIS (Network Driver Interface Specification) filter chain at the kernel level. According to the WinDivert architecture, the driver implements FilterSendNetBufferLists and FilterReceiveNetBufferLists callbacks that receive copies of every outbound and inbound packet traversing the network stack.
NDIS Filter Stack Integration
Once the service starts (net start "WinDivert"), the driver inserts itself into the network data path. For outbound traffic, packets flow from applications through the TCP/IP stack, hit the WinDivert filter, and are diverted before reaching the NIC driver. For inbound traffic, packets are intercepted immediately after processing by the NIC driver but before delivery to the TCP/IP stack. This positioning allows the driver to capture packets that bypass user-mode APIs entirely, including those generated by system services, kernel drivers, and other low-level Windows components.
Filtering Engine and Packet Flow
WinDivert employs a BPF-style expression language to determine which packets to divert from the kernel flow to user-mode processing.
BPF-Style Filter Expressions
The driver evaluates packets against filter strings such as "outbound && ip && tcp && dst port 443" defined during handle initialization. When a match occurs, the driver copies the packet into a kernel-mode queue rather than allowing it to continue normal processing. This mechanism ensures that only relevant traffic consumes resources in user mode, while non-matching packets pass through with minimal overhead.
Packet Queue and User-Mode Interaction
The user-mode component, bin/WinDivert.dll, exposes functions including WinDivertOpen, WinDivertRecv, and WinDivertSend. Applications open a handle to the driver with a specific filter, then call WinDivertRecv to dequeue packets from the kernel buffer. After optional inspection or modification—such as rewriting IP headers or changing TCP ports—the application calls WinDivertSend to reinject the packet back into the network stack, or simply drops it by not reinjecting.
Installation and Service Management
The repository provides service.bat to handle driver lifecycle management, ensuring proper registration and avoiding conflicts with existing WinDivert installations.
Installing the Driver
The batch script registers the driver as a Windows service using the sc command. The following excerpt from service.bat (lines 204-209) demonstrates the installation process:
rem Install WinDivert driver as a service
sc create "WinDivert" binPath= "%~dp0\bin\WinDivert64.sys" type= kernel start= auto
net start "WinDivert"
This registration persists across reboots until explicitly removed. The type= kernel parameter specifies that this is a kernel-mode driver service, distinct from user-mode services.
Removing the Driver
Cleanup operations in service.bat (lines 574-605) stop and delete the service:
rem Stop and delete the WinDivert service
net stop "WinDivert" >nul 2>&1
sc delete "WinDivert" >nul 2>&1
These commands ensure the driver unloads from memory and detaches from the NDIS filter chain, restoring normal packet flow without the interception layer.
Practical Implementation in Zapret
The zapret project uses winws.exe (found in bin/winws.exe) as a lightweight wrapper that initializes the WinDivert driver and applies censorship circumvention rules.
Driver Initialization via Batch Scripts
The general (FAKE TLS AUTO).bat and similar scripts invoke winws.exe with specific filter parameters to capture HTTPS traffic destined for blocked IP ranges. The helper executable loads WinDivert.dll, opens the driver with a predefined filter expression, and forwards matching packets to local proxy instances or modifies them directly to evade Deep Packet Inspection (DPI).
Packet Modification Workflow
When winws.exe runs with parameters like -p "outbound && tcp && dst port 443", it performs the following sequence:
- Calls
WinDivertOpenwith the filter expression and layer specifications - Enters a loop calling
WinDivertRecvto receive diverted packets - Examines packet headers against lists stored in
lists/*.txtfiles - Modifies packet headers (such as fragmenting TLS Client Hello or changing TCP window sizes) to bypass detection
- Calls
WinDivertSendto reinject modified packets or drops them if they match blocked criteria
Because the driver is digitally signed, it loads on 64-bit Windows without requiring the user to disable Driver Signature Enforcement (DSE), though Windows 7 users require a specific driver variant as noted in the repository documentation.
Summary
- WinDivert64.sys (
bin/WinDivert64.sys) functions as a kernel-mode driver that hooks into the NDIS filter stack viaFilterSendNetBufferListsandFilterReceiveNetBufferListscallbacks. - BPF-style filters determine which packets divert to user mode, minimizing performance impact on non-target traffic.
- service.bat manages the driver lifecycle through Windows Service Control Manager commands (
sc create,net start,sc delete). - WinDivert.dll provides the API surface for applications to receive, modify, and reinject packets using
WinDivertRecvandWinDivertSend. - The signed driver architecture allows operation on modern 64-bit Windows systems without disabling security features, enabling transparent filtering for anti-censorship tools like
zapret.
Frequently Asked Questions
What is the difference between WinDivert64.sys and WinDivert.dll?
WinDivert64.sys is the kernel-mode driver that performs actual packet interception in the NDIS stack, while WinDivert.dll is the user-mode library that applications link against to communicate with the driver. The DLL handles opening handles, receiving diverted packets, and sending modified packets, whereas the SYS file executes in kernel space with elevated privileges to access all network traffic.
Why does WinDivert require installation as a Windows service?
Windows requires kernel-mode drivers to be registered as services through the Service Control Manager (sc create) to ensure proper lifecycle management, security validation, and system integration. This registration allows the operating system to verify the driver's digital signature, control loading at boot time, and ensure cleanup during shutdown through service dependencies.
Can WinDivert capture packets from all applications, including system services?
Yes. Because WinDivert operates at the kernel level within the NDIS filter stack, it captures packets before they reach user-mode APIs like Winsock. This allows it to intercept traffic generated by system services, other kernel drivers, and privileged processes that would be invisible to conventional packet capture libraries running in user mode.
Is it safe to use WinDivert on Windows 11 with driver signature enforcement enabled?
Yes. The WinDivert64.sys driver included in the repository is digitally signed with a valid Windows driver signature, allowing it to load on 64-bit Windows 10 and Windows 11 systems without disabling Driver Signature Enforcement (DSE). However, some antivirus software may flag the driver as suspicious due to its packet interception capabilities, requiring users to add an exclusion for the bin\WinDivert64.sys file.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →