How to Use Multisplit Desync for DPI Bypass in zapret-discord-youtube

Multisplit desync fragments TLS ClientHello packets into overlapping TCP segments, causing deep packet inspection engines to fail signature matching while the legitimate endpoint reassembles the stream correctly.

The zapret-discord-yououtube repository distributes WinWS (winws.exe), a WinDivert-based traffic interceptor that rewrites TCP streams on-the-fly. Its multisplit desync capability represents one of the most robust methods for evading DPI-based blocking, particularly against firewalls that expect contiguous TLS handshake signatures.

How Multisplit Desync Bypasses DPI

Deep packet inspection engines typically perform single-pass pattern matching on the first few hundred bytes of a TCP stream. Multisplit desync exploits this limitation by cutting the TLS ClientHello into multiple fragments with sequence overlaps.

The algorithm operates as follows:

  1. Load a binary pattern from bin/tls_clienthello_www_google_com.bin (or similar files) containing a raw TLS ClientHello packet.
  2. Split the byte stream at the position specified by --dpi-desync-split-pos.
  3. Create overlapping fragments where the second packet starts seqovl bytes before the first packet ends, generating redundant data that confuses stateful inspection.
  4. Transmit fragments with minimal inter-packet delay, allowing the receiving server to reassemble the valid handshake while the DPI engine sees only disjointed, non-matching segments.

Because the target server reconstructs the full TLS handshake from the overlapping fragments, the connection establishes normally. The DPI device, however, fails to locate its blocking signature across the fragmented boundary.

Source Files and Architecture

Implementing multisplit desync for DPI bypass requires three core components from the repository:

  • bin/winws.exe – The WinDivert driver interface that performs the actual packet interception and fragmentation.
  • general.bat (and variants like general (ALT2).bat, general (ALT6).bat) – Batch scripts that assemble the command-line arguments, referenced at line 19 in the base file.
  • bin/*.bin pattern files – Pre-generated TLS ClientHello blobs (e.g., tls_clienthello_www_google_com.bin, tls_clienthello_4pda_to.bin) used as the fragmentation template.

Essential Command Line Parameters

To activate multisplit mode, launch winws.exe with the following flags:

  • --dpi-desync=multisplit – Required flag that enables the multisplit algorithm.
  • --dpi-desync-split-seqovl=<bytes> – Defines the sequence overlap length between fragments. Common values include 568, 652, and 681.
  • --dpi-desync-split-pos=<offset> – Specifies the byte position from the packet start where the first split occurs. Typically set to 1 or 2.
  • --dpi-desync-split-seqovl-pattern=<path> – Absolute or relative path to the binary pattern file used as the fragmentation source.

Practical Configuration Examples

The repository provides working implementations in the general*.bat scripts. The following examples demonstrate how to configure multisplit desync for different scenarios:

Basic Google Services Bypass

start "zapret: multisplit-google" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443 ^
  --dpi-desync=multisplit ^
  --dpi-desync-split-seqovl=681 ^
  --dpi-desync-split-pos=1 ^
  --dpi-desync-split-seqovl-pattern="%BIN%tls_clienthello_www_google_com.bin" ^
  --new

This configuration corresponds to the parameters found at general.bat line 19, using a 681-byte overlap to target Google-hosted services.

Alternative Pattern for Russian Services

start "zapret: multisplit-4pda" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443 ^
  --dpi-desync=multisplit ^
  --dpi-desync-split-seqovl=568 ^
  --dpi-desync-split-pos=1 ^
  --dpi-desync-split-seqovl-pattern="%BIN%tls_clienthello_4pda_to.bin" ^
  --new

This variant uses the tls_clienthello_4pda_to.bin pattern with a smaller 568-byte overlap, optimized for bypassing restrictions on Russian platforms.

Tuning Parameters for Your Network

Adjust these three variables to optimize multisplit desync against specific DPI implementations:

Parameter Typical Values Effect
--dpi-desync-split-seqovl 568, 652, 681 Larger overlaps increase redundancy, helping against DPI systems that discard out-of-order packets. Smaller values reduce bandwidth overhead.
--dpi-desync-split-pos 1, 2 Moving the split position deeper into the packet can evade middle-box inspection that examines only the first few bytes.
--dpi-desync-split-seqovl-pattern tls_clienthello_www_google_com.bin, tls_clienthello_4pda_to.bin Select a pattern matching your target service's TLS fingerprint to ensure the fragments resemble legitimate traffic.

When one configuration fails, cycle through the general (ALT*).bat variants—each contains pre-tuned combinations of these parameters for different ISP filtering behaviors.

Step-by-Step Activation

Follow these steps to deploy multisplit desync for DPI bypass:

  1. Download and extract the latest release archive from the Flowseal/zapret-discord-youtube repository.
  2. Review the general*.bat files in the root directory to identify which variant matches your target service (Google, Discord, YouTube, or regional alternatives).
  3. Execute the batch file by double-clicking it—this launches winws.exe with the configured multisplit flags minimized to the system tray.
  4. Verify operation by checking Task Manager for a running winws.exe process with a lock icon.
  5. Test connectivity to the blocked service. If access remains restricted, terminate the process and try an alternative ALT script or manually adjust the seqovl and pos values.

Summary

  • Multisplit desync fragments TLS handshakes using configurable sequence overlaps to defeat signature-based DPI.
  • The technique relies on winws.exe (located in bin/winws.exe) and pre-generated pattern files (.bin) shipped with the repository.
  • Key parameters include --dpi-desync-split-seqovl for overlap size and --dpi-desync-split-pos for fragmentation offset.
  • The general.bat script and its variants provide ready-to-use configurations; modify them or create custom batches to tune the bypass for specific networks.
  • Unlike simple splitting, multisplit maintains protocol validity through overlapping fragments that servers reassemble correctly while DPI engines fail to match patterns.

Frequently Asked Questions

What is the difference between multisplit and other desync methods?

Multisplit specifically refers to fragmenting a single packet into multiple overlapping TCP segments using sequence number manipulation. Other methods like fake or disorder may inject fake packets or simply send segments out of order without the precise overlap control that multisplit provides. The overlap ensures that even if the DPI drops one fragment, the server still receives sufficient data to reconstruct the handshake.

Why does the overlap size matter for DPI bypass?

The sequence overlap (seqovl) determines how many bytes each fragment shares with its neighbor. Larger overlaps (e.g., 681 bytes) force the DPI to process more redundant data, increasing the chance that its stateful tracking buffer overflows or fails to reassemble the stream for inspection. However, excessive overlap may degrade performance, so values between 568 and 681 bytes represent the typical effective range found in the repository's batch files.

Can I use custom binary patterns instead of the provided .bin files?

Yes. The --dpi-desync-split-seqovl-pattern parameter accepts any file path containing a raw binary TLS ClientHello packet. You can generate custom patterns by capturing legitimate handshake packets to your target service using tools like Wireshark, saving the payload bytes, and referencing that file in your batch script. Ensure the pattern matches the specific TLS version and cipher suites expected by your target server.

Why does my connection fail even with multisplit enabled?

If multisplit desync fails to establish a connection, your ISP may employ DPI that reassembles TCP streams before inspection or uses stateful tracking that tolerates fragmentation. Try increasing the seqovl value to 652 or 681, moving the split-pos to 2, or switching to an alternative pattern file. Additionally, combining multisplit with other WinWS flags (such as --dpi-desync=fake) or testing different general (ALT*).bat variants often resolves compatibility issues with aggressive filtering systems.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →