# What Is WinDivert and How Does It Enable DPI Bypass on Windows: Technical Implementation Guide

> Learn how WinDivert bypasses DPI on Windows. This kernel driver intercepts network packets, letting apps modify TLS handshakes and headers to evade traffic filtering.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: how-to-guide
- Published: 2026-05-02

---

**WinDivert is a Windows kernel-mode driver that intercepts network packets at the IP layer, allowing applications to modify TLS handshakes and headers before Deep Packet Inspection (DPI) systems can analyze them, effectively bypassing traffic filtering on Windows.**

WinDivert powers open-source circumvention tools like **Flowseal/zapret-discord-youtube** by providing low-level packet manipulation capabilities that operate below user-mode firewalls. By installing a lightweight kernel driver (`WinDivert64.sys`) and exposing a user-mode API through `WinDivert.dll`, it enables applications to capture, alter, and reinject network traffic in real-time. Understanding what WinDivert is and how it enables DPI bypass on Windows requires examining its kernel architecture, filter expressions, and the specific traffic modification techniques implemented in the repository's batch scripts.

## How WinDivert Works at the Kernel Level

### The Driver Architecture

WinDivert consists of two core components found in the repository's `bin/` directory: `WinDivert64.sys` (the kernel-mode driver) and `WinDivert.dll` (the user-mode library). According to the Flowseal/zapret-discord-youtube source code, the driver registers at the Windows network layer, creating a filtration point before packets reach the TCP/IP stack or Windows Defender Firewall.

When loaded via administrative installers like `service.bat`, `WinDivert64.sys` attaches to the network driver stack and waits for filter instructions from user-space applications. The DLL exposes functions including `WinDivertOpen`, `WinDivertRecv`, and `WinDivertSend`, which translate high-level API calls into kernel-level packet operations.

### Packet Filtering and Capture

Applications initiate interception by calling `WinDivertOpen` with a **filter expression** that defines which packets to divert. Common filters in DPI bypass scenarios include:

```

outbound && tcp && tcp.DstPort == 443

```

This expression captures all outgoing TCP traffic destined for port 443 (HTTPS). When matching packets arrive, the kernel driver queues them and delivers them to the application through `WinDivertRecv`, including the full IP header, TCP header, and payload (up to 65535 bytes). The application inspects the raw bytes—often parsing TLS ClientHello structures—modifies them as needed, then calls `WinDivertSend` to reinject the packet into the network stack.

## DPI Bypass Techniques Enabled by WinDivert

### TLS SNI Spoofing and ClientHello Modification

Deep Packet Inspection systems frequently block connections based on the **Server Name Indication (SNI)** field in TLS ClientHello messages. WinDivert enables **TLS SNI spoofing** by intercepting the initial handshake packet, replacing the SNI value with a benign domain, and forwarding the modified packet. For example, the Flowseal/zapret-discord-youtube repository stores pre-generated binary blobs like `bin/tls_clienthello_www_google_com.bin` that substitute the entire ClientHello structure, causing DPI engines to see only an allowed destination while the actual connection proceeds to the blocked service.

### Packet Fragmentation and Reordering

By operating at the IP layer, WinDivert allows applications to fragment DPI-sensitive payloads into smaller packets or reorder them before transmission. This **fragmentation** confuses signature-based inspection engines that expect complete protocol frames in sequential order, causing them to miss blocked patterns that span multiple packet boundaries.

### Protocol Masquerading and Port Hopping

WinDivert facilitates **protocol masquerading** by rewriting packet headers—for instance, modifying TCP flags or port numbers to disguise HTTPS traffic as standard HTTP. **Port hopping** dynamically alters source and destination ports on the fly, rendering static port-based filters ineffective. These modifications occur transparently to higher-level applications while evading network-level inspection.

## Implementation in Flowseal/zapret-discord-youtube

### Core Components and File Structure

The repository implements WinDivert through several key files:

- **`bin/WinDivert.dll`**: User-mode library exposing the WinDivert API functions
- **`bin/WinDivert64.sys`**: Kernel driver that performs the actual packet interception
- **`service.bat`**: Administrative script that installs and starts the driver service
- **`general (FAKE TLS AUTO).bat`**: Automated bypass script that injects fake TLS handshakes
- **`bin/tls_clienthello_www_google_com.bin`**: Pre-generated payload used to replace original ClientHello messages

### The Bypass Workflow (Capture → Modify → Reinject)

Scripts in the repository follow a three-phase pattern:

1. **Capture**: Open a WinDivert handle targeting specific traffic (e.g., Discord or YouTube IPs) using `WinDivertOpen` with a filter like `outbound && tcp && tcp.DstPort == 443`
2. **Modify**: Inspect the captured payload via `WinDivertRecv` and substitute the TLS ClientHello with a fake handshake from the `bin/` directory
3. **Reinject**: Call `WinDivertSend` to return the modified packet to the stack, completing the connection while DPI systems only see the substituted data

### Code Examples: PowerShell and Batch Implementation

Below is a PowerShell implementation demonstrating the WinDivert API usage for SNI modification:

```powershell

# Open a WinDivert handle with a filter that captures outbound TLS handshakes

$filter = "outbound && tcp && tcp.DstPort == 443"
$handle = [WinDivert.WinDivert]::Open($filter, [WinDivert.WindivertLayer]::Network, 0, 0)

while ($true) {
    # Receive a matching packet (max 65535 bytes)

    $packet = New-Object Byte[] 65535
    $len = 0
    $addr = New-Object WinDivert.WinDivertAddress
    [WinDivert.WinDivert]::Recv($handle, $packet, [ref]$len, [ref]$addr)

    # Inspect the TLS ClientHello (simplified)

    $clientHello = $packet[0..($len-1)]
    if ($clientHello -match "SNI: blocked.example.com") {
        # Replace the SNI with a benign domain

        $clientHello = $clientHello -replace "blocked.example.com","allowed.com"
        $packet = $clientHello
    }

    # Re‑inject the (possibly modified) packet

    [WinDivert.WinDivert]::Send($handle, $packet, $len, $addr)
}

```

The repository's `general (FAKE TLS AUTO).bat` demonstrates a higher-level batch approach:

```batch
@echo off
rem Load the driver
windivert.exe -i WinDivert64.sys

rem Capture outbound HTTPS traffic and replace the handshake with a pre‑generated blob
winDivert.exe -c "outbound && tcp && tcp.DstPort == 443" -p bin\tls_clienthello_www_google_com.bin

```

## Summary

- WinDivert is a kernel-mode packet driver consisting of `WinDivert64.sys` and `WinDivert.dll` that intercepts network traffic before Windows firewall and DPI systems can process it.
- The `WinDivertOpen` function establishes packet filters (e.g., `outbound && tcp && tcp.DstPort == 443`) to capture specific traffic flows for inspection via `WinDivertRecv`.
- **TLS SNI spoofing** replaces blocked domain indicators with benign alternatives, while **fragmentation** and **protocol masquerading** obscure traffic patterns from signature-based inspection engines.
- The Flowseal/zapret-discord-youtube repository implements these techniques via batch scripts and pre-generated binary payloads stored in `bin/`, using `service.bat` for driver installation and management.
- Bypass workflows follow a **capture → modify → reinject** cycle using `WinDivertSend`, operating transparently at the IP layer to evade user-space detection while maintaining connection integrity.

## Frequently Asked Questions

### Is WinDivert safe to use on Windows systems?

WinDivert itself is a legitimate networking tool, but it requires administrative privileges to install the kernel driver `WinDivert64.sys`. As implemented in Flowseal/zapret-discord-youtube, it modifies network packets to bypass censorship, which may violate network policies or terms of service in some jurisdictions. Always verify the cryptographic signature of the `WinDivert64.sys` file in the `bin/` directory to avoid malicious driver implementations.

### Why does WinDivert bypass DPI when VPNs sometimes fail?

WinDivert operates at the kernel level before packets are processed by Windows networking APIs or user-space firewalls, whereas VPNs typically encapsulate traffic at the transport layer. This low-level positioning allows WinDivert to alter packet headers and payloads—such as modifying the TLS ClientHello SNI—before DPI engines can inspect them, making it effective against stateful inspection that VPN tunnels might still expose through metadata leakage.

### Can WinDivert be detected by antivirus or EDR software?

Yes, because `WinDivert64.sys` is a kernel-mode driver that intercepts all network traffic, many security products flag it as potentially unwanted software or rootkit-like behavior. The Flowseal/zapret-discord-youtube repository includes the driver in its `bin/` directory, and users may need to create exclusions for `WinDivert.dll` and related batch scripts like `service.bat` to prevent security software from blocking the DPI bypass functionality.

### Do I need programming knowledge to use WinDivert with zapret-discord-youtube?

No, the repository provides ready-to-use batch files like `service.bat` and `general (FAKE TLS AUTO).bat` that automate driver installation and packet manipulation. However, understanding basic filter syntax (e.g., `tcp.DstPort == 443`) and the location of payload files in the `bin/` directory helps troubleshoot connection issues when bypassing specific services like Discord or YouTube.