How to Find Alternative Zapret Strategies When the Default Ones Fail

When the primary Zapret bypass stops working, run the diagnostic suite in service.bat to identify which pre-packaged alternative—such as general (ALT).bat or general (FAKE TLS AUTO).bat—successfully evades your ISP's DPI detection, then install the working strategy as a Windows service.

The Flowseal/zapret-discord-youtube repository distributes the Zapret DPI bypass tool as a collection of Windows batch scripts. Each strategy is a .bat file that launches the WinDivert-based driver (winws.exe) with a specific set of command-line arguments defining packet-filtering rules, TLS-handshake tweaks, and port configurations. When the default strategy fails due to updated DPI signatures or driver conflicts, the repository provides alternative Zapret strategies that modify these parameters to restore connectivity.

Why Alternative Strategies Are Necessary

Modern ISPs deploy Deep Packet Inspection (DPI) systems that detect and block traffic patterns generated by default bypass configurations. When the standard general.bat launches, it loads bin/WinDivert64.sys and bin/WinDivert.dll with original Zapret filtering rules—a signature that anti-cheat software and DPI engines quickly recognize and throttle.

The alternative strategies work by changing the driver’s behavior through different command-line arguments:

  • Modified TLS fingerprints – Altering the Client Hello packets to mimic legitimate browsers.
  • Alternate port handling – Changing which UDP/TCP ports are intercepted (default is typically >1023).
  • Custom IP filtering tables – Pointing to different blocklists or allowlists.

Available Strategy Types in the Repository

The repository ships with dozens of ready-made strategies stored as individual batch files in the root directory.

Standard and ALT Variants (ALT1-ALT11)

The ALT series consists of general (ALT).bat through general (ALT11).bat. These files represent variations of the core driver arguments, each adjusting packet-filtering rules and handshake timing. For example, general (ALT5).bat launches winws.exe with a different --filter-tcp configuration than the standard script, often bypassing DPI blocks that specifically target the default parameters.

TLS Spoofing Strategies (FAKE TLS AUTO)

general (FAKE TLS AUTO).bat activates fake-TLS client-hello spoofing. This strategy instructs winws.exe to send fabricated TLS handshake packets that mimic popular web services, making DPI systems classify the traffic as standard HTTPS rather than a bypass tool.

Minimal Resource Options (SIMPLE FAKE)

general (SIMPLE FAKE).bat provides a minimalistic fake-TLS mode designed for low-resource environments. It uses fewer CPU cycles and smaller memory footprints by reducing the complexity of packet inspection rules, useful on older hardware or when running alongside resource-intensive games.

Locating a Working Strategy Using Built-in Diagnostics

The repository includes automated tools to test which alternative Zapret strategy functions on your network.

Running Service Diagnostics

Execute service.bat and select Run Diagnostics. This checks whether the current strategy is active and confirms that WinDivert64.sys is properly loaded into the network stack. If the driver fails to initialize, the diagnostic output identifies service conflicts or permission errors.

Executing the Test Suite

From the same service.bat menu, select Run Tests to execute the PowerShell harness located at utils/test zapret.ps1. This script performs two critical checks:

  1. Standard tests – Exercises the URLs listed in utils/targets.txt to verify basic connectivity.
  2. DPI checkers – Queries external test services (Cloudflare, Amazon) to determine if traffic modification is active.

The test harness includes functions like Test-ZapretServiceConflict that programmatically verify driver status. Examine the source in utils/test zapret.ps1 to understand how success criteria are evaluated:


# Snippet from utils/test zapret.ps1

function Test-ZapretServiceConflict {
    param ([string]$ServiceName)
    # Checks for existing WinDivert services that might conflict

    $service = Get-Service -Name $ServiceName -ErrorAction SilentlyContinue
    return $service -ne $null
}

Switching Between Alternative Strategies

Once diagnostics identify a working configuration, switching requires only executing the corresponding batch file.

Manual Execution

Double-click any strategy file to launch it interactively:

rem Try the default (may already be running)
general.bat

rem Test ALT5 variant
"general (ALT5).bat"

rem Test TLS spoofing
"general (FAKE TLS AUTO).bat"

Or from PowerShell:


# Launch ALT3 strategy

& ".\general (ALT3).bat"

# Run the service manager

& ".\service.bat"

After launching, verify the WinDivert icon appears in the system tray, indicating the driver is active with the new parameters.

Installing as a Persistent Service

To make a working strategy permanent, use service.bat → Install Service. This creates a Windows service entry visible in services.msc, ensuring the selected strategy launches automatically at boot. You must run this as Administrator, and you should specify a unique service name if you maintain multiple Zapret configurations for different networks.

Creating Custom Strategies When Pre-Made Options Fail

If none of the supplied scripts bypass your ISP's restrictions, create a custom strategy by copying an existing .bat file and modifying the winws.exe arguments.

Key parameters documented in the upstream Zapret project include:

  • --udp-port-list – Defines which ports to intercept (default intercepts >1023).
  • --tls-fake – Enables fake-TLS client-hello generation.
  • --ipset – Points to a custom IP list file, such as ipset-all.txt, defining which destinations receive bypass treatment.

Copy general.bat to custom-strategy.bat, then edit the command line to include your modifications:

@echo off
cd /d "%~dp0"
bin\winws.exe --udp-port-list 53,443,5000-5010 --tls-fake --ipset lists/list-general.txt

After saving, run your custom script and repeat the diagnostic steps from service.bat to confirm functionality.

Summary

  • Alternative Zapret strategies exist because ISPs detect the default WinDivert driver signatures and packet patterns.
  • The repository provides ALT variants (ALT1-ALT11), FAKE TLS AUTO, and SIMPLE FAKE strategies, each adjusting winws.exe parameters to evade detection.
  • Use service.bat to run diagnostics and the test suite (utils/test zapret.ps1) to identify working configurations.
  • Switch strategies by executing the corresponding .bat file, and persist the choice via service.bat → Install Service.
  • For edge cases, create custom strategies by copying existing batch files and modifying flags like --udp-port-list and --tls-fake.

Frequently Asked Questions

What is the difference between ALT5 and FAKE TLS AUTO strategies?

The ALT5 strategy modifies standard packet-filtering rules and port handling without changing the fundamental nature of the TLS handshake, while FAKE TLS AUTO specifically spoofs TLS Client Hello packets to impersonate legitimate HTTPS traffic. ALT5 works better when DPI blocks based on port patterns, whereas FAKE TLS AUTO succeeds when DPI analyzes application-layer signatures.

How do I know if a strategy is actually working?

Run service.bat → Run Tests to execute the PowerShell test harness in utils/test zapret.ps1. This script validates connectivity against the URLs in utils/targets.txt and checks external DPI test services. If the tests return successful connections and you can access previously blocked sites (like Discord or YouTube), the strategy is functioning.

Can I switch strategies without restarting my computer?

Yes. Simply close any running winws.exe processes from the system tray or Task Manager, then double-click the new strategy's .bat file. The WinDivert driver will reload with the new parameters immediately. You do not need to reboot Windows between strategy changes.

Where are the blocked domains and IP lists stored?

The default list of domains to bypass resides in lists/list-general.txt. When creating custom strategies, you can point --ipset to alternative lists like ipset-all.txt. These plain-text files define which traffic routes through the Zapret filter, and you can edit them to add specific game servers or services experiencing blocks.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →