WinDivert 1.3: Windows Packet Divert
Windows Packet Divert (WinDivert) is a user-mode packet capture-and-divert package for Windows 2008, Windows 7, Windows 8, Windows 10 and Windows 2016.
WinDivert allows user-mode applications to capture/modify/drop network packets sent to/from the Windows network stack. In summary, WinDivert can:
- capture network packets
- filter/drop network packets
- sniff network packets
- (re)inject network packets
- modify network packets
WinDivert can be used to implement user-mode packet filters, packet sniffers, firewalls, NAT, VPNs, tunneling applications, etc.
The main features of WinDivert include:
- packet interception, sniffing, or dropping modes
- supports loopback (localhost) traffic
- full IPv6 support
- network layer
- simple yet powerful API
- high-level filtering language
- filter priorities
- silent installation
- freely available under the terms of the GNU Lesser General Public License (LGPL)
➢ Documentation and Samples
- WinDivert Documentation: The WinDivert manual.
- WinDivert README.
- WinDivert ChangeLog.
- WinDivert FAQ.
- WinDivert sample applications including:
➢ Source Repository
The source code for WinDivert is hosted on GitHub:
Note that the repository version of WinDivert should generally be considered unstable.
The following stable source packages for WinDivert are available:
- WinDivert-1.3.0-Source.zip (Source zipfile)
The following stable binary packages for WinDivert are available. Choose the package that matches your compiler:
NEW (Jan 2018): The following release candidate binary packages are also available via Github:
- WinDivert-1.4.0-rc. Note that the WinDivert1.4 API differs from older versions, so please refer to the 1.4 documentation included in the release package(s).
- To use WinDivert please ensure that you use the correct version (i.e. 32-bit WinDivert for 32-bit system, etc.) and that you are running with Administrator privileges. Otherwise WinDivert will fail to load.
- As of version 1.3.0, the binary WinDivert drivers are signed by
(Ars Nova Systems, also see here
for the English site).
We thank ParentsDansLesParages for their support.
Commercial users of WinDivert should sign the
driver with their own certificate if possible.
Note that the current driver signature has some caveats:
- Windows 7 systems must be up-to-date or at least have KB3033929 installed.
- Windows Server 2016 systems must have secure boot disabled.
The following projects use WinDivert:
- ReQrypt: A HTTP request tunneling tool.
- TcpCrypt (github): Encrypt (almost) all of your network traffic.
- GoodbyeDPI: Deep Packet Inspection (DPI) circumvention utility.
- BarbaTunnel (old link): Tunnel VPN traffic through HTTP.
- PyDivert: A WinDivert Python binding.
- jdivert: A WinDivert Java binding.
- Stahp It: HTTP/S content filter (see also HttpFilteringEngine).
- Divert.Net: A WinDivert C# binding.
- Tallow (github): Transparent Tor for Windows.
- Clumsy (github): A utility for simulating a broken network for Windows.
- Inssidious (github): A mobile app network testing tool.
- SnoopSpy (github): A packet capturing/manipulation tool.
- mitmproxy (dev version): An interactive SSL-capable intercepting HTTP proxy.
- A PureBasic interface to WinDivert.
Send feedback and/or questions to: