Zapret Strategy Variants: Differences Between General, FAKE, and ALT

Both FAKE and ALT Zapret strategies launch winws.exe with DPI-desynchronisation options, but FAKE relies on high-repeat classic fake-TLS payloads while ALT introduces fake-split segmentation, diversified binary files, and extended protocol coverage to evade advanced DPI filters.

The Flowseal/zapret-discord-youtube repository provides Windows Batch wrappers that configure the winws.exe engine to circumvent Deep Packet Inspection (DPI) blocking. Understanding the differences between Zapret strategy variants—General, FAKE, and ALT—is essential for selecting the optimal obfuscation pattern for your specific network restrictions.

Shared Foundation Across All Variants

All strategy variants execute from the same initialization logic defined in service.bat and share common networking parameters. They target identical TCP and UDP port whitelists (--wf-tcp=80,443,2053,2083,2087,2096,8443…) and reference the same binary payloads stored in the bin/ directory. Both variants load IP-set filters from lists/ipset-all.txt and apply Windows Filtering Platform (WFP) rules through winws.exe to intercept traffic before it reaches the ISP's inspection points.

General FAKE Strategy: Classic Desynchronisation

The FAKE variant focuses on straightforward fake-TLS injection with minimal pattern variation and high repetition rates.

High-Repeat Fake Mode

In general (FAKE TLS AUTO).bat, the primary desync method uses --dpi-desync=fake with --dpi-desync-repeats=11. This elevated repeat count sends nearly double the fake packets compared to ALT variants, overwhelming simpler DPI state tracking mechanisms that rely on session continuity checks.

TLS Payload Configuration

The strategy loads tls_clienthello_max_ru.bin for HTTP fake payloads and passes a dummy TLS value (0x00000000) combined with override flags (^!). It primarily targets QUIC traffic using --dpi-desync-fake-quic with Google-specific binaries, applying multidisorder modes only to select TCP rules rather than the entire rule set.

start "zapret: %~n0" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443,2053,2083,2087,2096,8443,%GameFilterTCP% ^
  --wf-udp=443,19294-19344,50000-50100,%GameFilterUDP% ^
  --filter-udp=443 ^
  --hostlist="%LISTS%list-general.txt" ^
  --dpi-desync=fake ^
  --dpi-desync-repeats=11 ^
  --dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin" ^
  --dpi-desync-fake-tls=0x00000000 --dpi-desync-fake-tls=^! ^
  --dpi-desync-fake-tls-mod=rnd,dupsid,sni=www.google.com ^
  --dpi-desync-fake-http="%BIN%tls_clienthello_max_ru.bin"

General ALT Strategy: Advanced Obfuscation

The ALT variant introduces fake-split technology and payload diversification to counter DPI systems that recognize and filter single-pattern fake handshakes.

Dual-Mode Desynchronisation

general (ALT).bat replaces the single fake mode with --dpi-desync=fake,fakedsplit and reduces repeats to --dpi-desync-repeats=6. It adds --dpi-desync-fakedsplit-pattern=0x00 to split packet streams at null-byte boundaries, disrupting signature matching that expects continuous TLS handshakes across the full session duration.

Diversified Binary Payloads

Instead of relying on a single TLS binary, ALT alternates between tls_clienthello_www_google_com.bin, stun.bin, and tls_clienthello_max_ru.bin across different rule blocks. This payload rotation prevents DPI filters from blacklisting a specific fake signature after observing it repeatedly, distributing the obfuscation footprint across multiple recognizable patterns.

Extended Protocol Coverage

Beyond standard QUIC fakes, ALT enables --dpi-desync-fake-discord, --dpi-desync-fake-stun, and --dpi-desync-fake-unknown-udp for application-specific UDP checks. It applies --dpi-desync-any-protocol=1 on final game-filter rules, expanding the interception scope beyond predefined Layer-7 filters to catch proprietary gaming protocols.

start "zapret: %~n0" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443,2053,2083,2087,2096,8443,%GameFilterTCP% ^
  --wf-udp=443,19294-19344,50000-50100,%GameFilterUDP% ^
  --filter-udp=443 ^
  --hostlist="%LISTS%list-general.txt" ^
  --dpi-desync=fake,fakedsplit ^
  --dpi-desync-repeats=6 ^
  --dpi-desync-fakedsplit-pattern=0x00 ^
  --dpi-desync-fake-tls="%BIN%stun.bin" ^
  --dpi-desync-fake-tls="%BIN%tls_clienthello_www_google_com.bin" ^
  --dpi-desync-fake-http="%BIN%tls_clienthello_max_ru.bin"

Key Technical Differences

Feature General FAKE General ALT
Primary desync mode --dpi-desync=fake --dpi-desync=fake,fakedsplit
Repeat count 11 cycles 6 cycles
Fake-split pattern Not implemented 0x00 byte pattern
TLS binaries tls_clienthello_max_ru.bin (primary) Multiple: stun.bin, tls_clienthello_www_google_com.bin, tls_clienthello_max_ru.bin
UDP protocols QUIC only QUIC, Discord, STUN, unknown-UDP
Multidisorder Limited TCP rules Extensive across rule set

Summary

  • General FAKE provides a simpler, high-repetition fake-TLS approach suitable for networks with basic DPI implementation that relies on volume-based evasion.
  • General ALT offers sophisticated fake-split segmentation and payload rotation, making it more resilient against adaptive DPI filters that blacklist single-pattern obfuscation.
  • Both variants execute winws.exe from the shared bin/ directory and respect the whitelist definitions established in service.bat.
  • The ALT variant trades higher configuration complexity for broader protocol support and lower network overhead through reduced repeat counts.

Frequently Asked Questions

Which Zapret strategy variant should I use for Discord?

The ALT variant typically outperforms FAKE for Discord traffic because it includes --dpi-desync-fake-discord and --dpi-desync-fake-stun parameters specifically targeting Discord's voice (UDP) and chat infrastructure. The fake-split segmentation also better handles Discord's aggressive connection pinning that basic fake-TLS repetition struggles to circumvent.

What is the fake-split pattern in the ALT variant?

The --dpi-desync-fakedsplit-pattern=0x00 setting instructs winws.exe to segment packet streams at null-byte boundaries, creating discontinuities in the data flow. This fragmentation forces DPI systems to reassemble packets before inspection, often exceeding their state table limits or buffering timeouts, which causes them to allow the traffic through uninspected.

Why does the FAKE strategy use more repeats than ALT?

FAKE compensates for its singular desync method by overwhelming DPI state tables with repetition (--dpi-desync-repeats=11). The ALT variant achieves equivalent reliability through technique diversity rather than volume, using fewer repeats (--dpi-desync-repeats=6) to minimize packet overhead while maintaining effectiveness through complementary fakedsplit diversification.

Can I combine FAKE and ALT strategy settings?

Yes, advanced users can create hybrid configurations by borrowing parameters from both general (FAKE TLS AUTO).bat and general (ALT).bat. Avoid applying conflicting --dpi-desync modes to identical hostlist matches; instead, combine ALT's fakedsplit patterns with FAKE's specific TLS binaries on separate filter rules to create layered obfuscation without command-line collisions.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →