What Is WinDivert and How Does It Enable DPI Bypass on Windows: Technical Implementation Guide
WinDivert is a Windows kernel-mode driver that intercepts network packets at the IP layer, allowing applications to modify TLS handshakes and headers before Deep Packet Inspection (DPI) systems can analyze them, effectively bypassing traffic filtering on Windows.
WinDivert powers open-source circumvention tools like Flowseal/zapret-discord-youtube by providing low-level packet manipulation capabilities that operate below user-mode firewalls. By installing a lightweight kernel driver (WinDivert64.sys) and exposing a user-mode API through WinDivert.dll, it enables applications to capture, alter, and reinject network traffic in real-time. Understanding what WinDivert is and how it enables DPI bypass on Windows requires examining its kernel architecture, filter expressions, and the specific traffic modification techniques implemented in the repository's batch scripts.
How WinDivert Works at the Kernel Level
The Driver Architecture
WinDivert consists of two core components found in the repository's bin/ directory: WinDivert64.sys (the kernel-mode driver) and WinDivert.dll (the user-mode library). According to the Flowseal/zapret-discord-youtube source code, the driver registers at the Windows network layer, creating a filtration point before packets reach the TCP/IP stack or Windows Defender Firewall.
When loaded via administrative installers like service.bat, WinDivert64.sys attaches to the network driver stack and waits for filter instructions from user-space applications. The DLL exposes functions including WinDivertOpen, WinDivertRecv, and WinDivertSend, which translate high-level API calls into kernel-level packet operations.
Packet Filtering and Capture
Applications initiate interception by calling WinDivertOpen with a filter expression that defines which packets to divert. Common filters in DPI bypass scenarios include:
outbound && tcp && tcp.DstPort == 443
This expression captures all outgoing TCP traffic destined for port 443 (HTTPS). When matching packets arrive, the kernel driver queues them and delivers them to the application through WinDivertRecv, including the full IP header, TCP header, and payload (up to 65535 bytes). The application inspects the raw bytes—often parsing TLS ClientHello structures—modifies them as needed, then calls WinDivertSend to reinject the packet into the network stack.
DPI Bypass Techniques Enabled by WinDivert
TLS SNI Spoofing and ClientHello Modification
Deep Packet Inspection systems frequently block connections based on the Server Name Indication (SNI) field in TLS ClientHello messages. WinDivert enables TLS SNI spoofing by intercepting the initial handshake packet, replacing the SNI value with a benign domain, and forwarding the modified packet. For example, the Flowseal/zapret-discord-youtube repository stores pre-generated binary blobs like bin/tls_clienthello_www_google_com.bin that substitute the entire ClientHello structure, causing DPI engines to see only an allowed destination while the actual connection proceeds to the blocked service.
Packet Fragmentation and Reordering
By operating at the IP layer, WinDivert allows applications to fragment DPI-sensitive payloads into smaller packets or reorder them before transmission. This fragmentation confuses signature-based inspection engines that expect complete protocol frames in sequential order, causing them to miss blocked patterns that span multiple packet boundaries.
Protocol Masquerading and Port Hopping
WinDivert facilitates protocol masquerading by rewriting packet headers—for instance, modifying TCP flags or port numbers to disguise HTTPS traffic as standard HTTP. Port hopping dynamically alters source and destination ports on the fly, rendering static port-based filters ineffective. These modifications occur transparently to higher-level applications while evading network-level inspection.
Implementation in Flowseal/zapret-discord-youtube
Core Components and File Structure
The repository implements WinDivert through several key files:
bin/WinDivert.dll: User-mode library exposing the WinDivert API functionsbin/WinDivert64.sys: Kernel driver that performs the actual packet interceptionservice.bat: Administrative script that installs and starts the driver servicegeneral (FAKE TLS AUTO).bat: Automated bypass script that injects fake TLS handshakesbin/tls_clienthello_www_google_com.bin: Pre-generated payload used to replace original ClientHello messages
The Bypass Workflow (Capture → Modify → Reinject)
Scripts in the repository follow a three-phase pattern:
- Capture: Open a WinDivert handle targeting specific traffic (e.g., Discord or YouTube IPs) using
WinDivertOpenwith a filter likeoutbound && tcp && tcp.DstPort == 443 - Modify: Inspect the captured payload via
WinDivertRecvand substitute the TLS ClientHello with a fake handshake from thebin/directory - Reinject: Call
WinDivertSendto return the modified packet to the stack, completing the connection while DPI systems only see the substituted data
Code Examples: PowerShell and Batch Implementation
Below is a PowerShell implementation demonstrating the WinDivert API usage for SNI modification:
# Open a WinDivert handle with a filter that captures outbound TLS handshakes
$filter = "outbound && tcp && tcp.DstPort == 443"
$handle = [WinDivert.WinDivert]::Open($filter, [WinDivert.WindivertLayer]::Network, 0, 0)
while ($true) {
# Receive a matching packet (max 65535 bytes)
$packet = New-Object Byte[] 65535
$len = 0
$addr = New-Object WinDivert.WinDivertAddress
[WinDivert.WinDivert]::Recv($handle, $packet, [ref]$len, [ref]$addr)
# Inspect the TLS ClientHello (simplified)
$clientHello = $packet[0..($len-1)]
if ($clientHello -match "SNI: blocked.example.com") {
# Replace the SNI with a benign domain
$clientHello = $clientHello -replace "blocked.example.com","allowed.com"
$packet = $clientHello
}
# Re‑inject the (possibly modified) packet
[WinDivert.WinDivert]::Send($handle, $packet, $len, $addr)
}
The repository's general (FAKE TLS AUTO).bat demonstrates a higher-level batch approach:
@echo off
rem Load the driver
windivert.exe -i WinDivert64.sys
rem Capture outbound HTTPS traffic and replace the handshake with a pre‑generated blob
winDivert.exe -c "outbound && tcp && tcp.DstPort == 443" -p bin\tls_clienthello_www_google_com.bin
Summary
- WinDivert is a kernel-mode packet driver consisting of
WinDivert64.sysandWinDivert.dllthat intercepts network traffic before Windows firewall and DPI systems can process it. - The
WinDivertOpenfunction establishes packet filters (e.g.,outbound && tcp && tcp.DstPort == 443) to capture specific traffic flows for inspection viaWinDivertRecv. - TLS SNI spoofing replaces blocked domain indicators with benign alternatives, while fragmentation and protocol masquerading obscure traffic patterns from signature-based inspection engines.
- The Flowseal/zapret-discord-youtube repository implements these techniques via batch scripts and pre-generated binary payloads stored in
bin/, usingservice.batfor driver installation and management. - Bypass workflows follow a capture → modify → reinject cycle using
WinDivertSend, operating transparently at the IP layer to evade user-space detection while maintaining connection integrity.
Frequently Asked Questions
Is WinDivert safe to use on Windows systems?
WinDivert itself is a legitimate networking tool, but it requires administrative privileges to install the kernel driver WinDivert64.sys. As implemented in Flowseal/zapret-discord-youtube, it modifies network packets to bypass censorship, which may violate network policies or terms of service in some jurisdictions. Always verify the cryptographic signature of the WinDivert64.sys file in the bin/ directory to avoid malicious driver implementations.
Why does WinDivert bypass DPI when VPNs sometimes fail?
WinDivert operates at the kernel level before packets are processed by Windows networking APIs or user-space firewalls, whereas VPNs typically encapsulate traffic at the transport layer. This low-level positioning allows WinDivert to alter packet headers and payloads—such as modifying the TLS ClientHello SNI—before DPI engines can inspect them, making it effective against stateful inspection that VPN tunnels might still expose through metadata leakage.
Can WinDivert be detected by antivirus or EDR software?
Yes, because WinDivert64.sys is a kernel-mode driver that intercepts all network traffic, many security products flag it as potentially unwanted software or rootkit-like behavior. The Flowseal/zapret-discord-youtube repository includes the driver in its bin/ directory, and users may need to create exclusions for WinDivert.dll and related batch scripts like service.bat to prevent security software from blocking the DPI bypass functionality.
Do I need programming knowledge to use WinDivert with zapret-discord-youtube?
No, the repository provides ready-to-use batch files like service.bat and general (FAKE TLS AUTO).bat that automate driver installation and packet manipulation. However, understanding basic filter syntax (e.g., tcp.DstPort == 443) and the location of payload files in the bin/ directory helps troubleshoot connection issues when bypassing specific services like Discord or YouTube.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →