20 Repos
Techniques for masking network traffic to bypass deep packet inspection and restrictive firewalls.
Distinguishing note: Focuses on packet header modification for connectivity rather than general encryption.
Explore 20 awesome GitHub repositories matching networking & communication · Traffic Obfuscation. Refine with filters or upvote what's useful.
ShadowsocksX-NG is a macOS application that functions as a Shadowsocks proxy client to establish encrypted tunnels for bypassing network censorship. It operates as an encrypted tunnel manager that allows for the configuration of secure ciphers and the import of proxy server profiles. The client includes a proxy converter that transforms SOCKS5 traffic into HTTP proxy traffic to provide compatibility for applications that do not support SOCKS. It also integrates a traffic steering system using Proxy Auto-Configuration files to automatically determine which network requests bypass the proxy. T
Supports traffic obfuscation plugins to mask encrypted data and evade deep packet inspection.
This project provides a self-hosted, containerized WireGuard VPN server that simplifies network administration through a web-based management interface. It allows users to deploy and manage VPN tunnels, configure peer identities, and monitor connection status without the need for manual configuration file editing. By bundling the VPN stack into a portable container, it ensures consistent deployment and persistent state management across diverse host environments. A key differentiator is the built-in support for traffic obfuscation, which modifies packet headers and handshake patterns to help
Implements traffic obfuscation to bypass deep packet inspection and restrictive network filtering.
Streisand is an orchestration system for deploying multi-protocol tunneling services and traffic obfuscation tools designed to circumvent regional network restrictions. It functions as a deployment utility and manager for various VPN and proxy services on remote cloud servers. The system distinguishes itself through a network obfuscation toolkit that wraps traffic in layers to evade deep packet inspection and bandwidth throttling. It automates the setup of multiple protocols, including WireGuard, OpenVPN, Shadowsocks, OpenConnect, OpenSSH, and Tor bridges. The project also includes utilities
Masks network traffic to bypass deep packet inspection and prevent bandwidth throttling.
gost is a multi-protocol proxy tunnel and secure tunneling server designed to route network traffic through encrypted connections. It functions as a traffic obfuscation gateway and a transparent proxy server capable of intercepting TCP and UDP traffic at the IP level. The project also includes a virtual network interface manager for creating TUN and TAP devices to intercept operating system packets. The system distinguishes itself through a chain-based request routing model, allowing traffic to pass through an ordered sequence of proxy nodes. It provides extensive transport-layer encapsulatio
Masks network traffic using WebSocket, HTTP/2, and QUIC to bypass firewalls and deep packet inspection.
Signal-Desktop is a cross-platform messaging application that provides end-to-end encrypted communication. It implements the Signal Protocol to secure messages and voice calls, ensuring that only intended recipients can access content. The application manages asynchronous key exchange and session initialization to maintain secure communication channels between parties who are not online simultaneously. The project distinguishes itself through advanced cryptographic protections, including hybrid post-quantum security that combines classical elliptic curve cryptography with lattice-based algori
Protects message metadata by encrypting packet headers with rotating keys to prevent traffic analysis.
Zapret is a deep packet inspection bypass tool and packet manipulation framework designed to circumvent network censorship. It operates as a transparent network proxy and TCP traffic obfuscator that modifies packets to deceive network inspection systems. The project distinguishes itself through advanced desynchronization strategies, including the modification of TLS client hello handshakes and the use of fake packet injection. It utilizes a combination of TCP stream segmentation, sequence overlapping, and TTL adjustment to hide prohibited requests from firewalls while ensuring the destination
Hides prohibited requests from network firewalls using TCP segmentation and fragmentation.
Lantern is a network utility designed to provide access to restricted internet content by tunneling traffic through encrypted connections. It functions as a censorship circumvention tool that enables private web browsing and ensures reliable connectivity in environments where standard network access is blocked or monitored. The application employs a decentralized infrastructure that routes data through a network of distributed proxy nodes. To maintain connectivity in the face of interference, it utilizes dynamic proxy discovery and adaptive fallback mechanisms that automatically switch betwee
Implements traffic obfuscation techniques to hide network patterns from deep packet inspection and firewalls.
BPB-Worker-Panel is a control panel designed for deploying and managing VLESS and Trojan proxies hosted on Cloudflare Workers. It functions as a proxy subscription generator and a manager for secure DNS over HTTPS servers and WireGuard configuration provisioning. The project distinguishes itself through network traffic obfuscation capabilities, utilizing packet fragmentation and SNI spoofing to evade detection. It provides specialized administration for Cloudflare Warp and Warp Pro connections, including the ability to optimize endpoints and export WireGuard configurations. The system covers
Modifies data packet fragments and injects noise strings to disguise proxy traffic and bypass deep packet inspection.
Amnezia Client is a cross-platform VPN client application and server orchestrator designed to manage secure tunnels and automate the deployment of containerized VPN services on remote self-hosted servers. It functions as a multi-protocol VPN manager that supports various tunneling standards to ensure connectivity across restrictive network environments. The project distinguishes itself through network traffic obfuscation, which disguises VPN traffic as common web protocols or DNS requests to bypass deep packet inspection and censorship. It further enables the automation of remote server admin
Hides encrypted tunnel signatures by mimicking common network protocols to bypass deep packet inspection.
Trojan-go is a network proxy implementation that uses the Trojan protocol to disguise internet traffic as standard TLS to bypass censorship and deep packet inspection. It functions as a tunneling gateway that encapsulates network data within encrypted tunnels to mimic ordinary web browsing. The project distinguishes itself through advanced obfuscation techniques, including TLS fingerprint mimicry to avoid detection by client signature identification and the use of WebSockets to relay encrypted traffic through content delivery networks. It also supports UDP forwarding through the Trojan protoc
Wraps protocol traffic in WebSockets to relay encrypted data through content delivery networks for obfuscation.
REALITY ist ein Tool zur Umgehung von Zensur und zur Verschleierung von Netzwerkverkehr, das entwickelt wurde, um Internetfilter zu umgehen. Es fungiert als sicheres Tunneling-Protokoll, das Verbindungsmuster und Identität maskiert, indem es die TLS-Handshakes legitimer Ziel-Websites nachahmt. Das System entfernt server-seitige TLS-Fingerabdrücke, um verschlüsselten Datenverkehr vor Netzwerküberwachungstools und Deep Packet Inspection zu verbergen. Es nutzt einen Website-Mimicking-Proxy, um gültige Handshakes vorzutäuschen und den Datenverkehr an Zielserver weiterzuleiten, wodurch die Verbindung als legitimer Website-Besuch getarnt wird. Das Projekt integriert eine quantenresistente TLS-Schicht, die post-quantenkryptografische Signaturen verwendet, um Handshakes und Zertifikate vor zukünftigen Entschlüsselungsbedrohungen zu schützen. Es umfasst zudem Funktionen für die temporäre Zertifikatsprüfung und transparentes Traffic-Forwarding.
Eliminates server-side TLS fingerprints to hide encrypted tunnels from deep packet inspection and network monitoring tools.
ByeDPIAndroid is a deep packet inspection bypass tool for Android that functions as a local SOCKS5 proxy. It modifies TCP packets to evade network censorship and bypass regional internet restrictions on mobile devices. The project operates as a network traffic obfuscator and TCP packet fragmenter. It splits network data into smaller pieces and hides the nature of internet requests to prevent automated blocking and traffic shaping by internet service providers. The system covers a range of capabilities including host-based traffic interception and dynamic packet modification. It utilizes non-
Masks network requests to prevent automated censorship blocks and traffic shaping by ISPs.
SpoofDPI ist eine Netzwerkanwendung und ein lokaler Proxy-Server, der als Anti-Zensur-Tool konzipiert ist. Er fungiert als Proxy zur Umgehung von Deep Packet Inspection, der ausgehende HTTP-Anfragen fragmentiert und modifiziert, um Netzwerkfilter und Zensur zu umgehen. Das Projekt erreicht dies durch die Implementierung von HTTP-Request-Fragmentierung, bei der einzelne Anfragen in mehrere kleinere Pakete aufgeteilt werden, um Firewalls zu verwirren. Es führt zudem TCP-Stream-Manipulation und Netzwerkverkehr-Obfuskation durch, um die Art der Webanfragen zu verbergen und regionale Inhaltsblockaden zu umgehen. Das System enthält Funktionen für transparentes Netzwerk-Forwarding und dateibasiertes Konfigurationsmanagement, um zu koordinieren, wie Netzwerkverkehr gehandhabt wird.
Masks network traffic patterns to prevent firewalls from identifying and blocking specific web requests.
Dieses Projekt ist eine Sammlung technischer Ressourcen, Blueprints und Leitfäden für den Bau resilienter und unauffälliger Red-Team-Infrastruktur. Es bietet ein umfassendes Framework für die Gestaltung offensiver Sicherheitsumgebungen, die Erkennung widerstehen und während Sicherheitsengagements operativ bleiben. Das Repository zeichnet sich durch detaillierte Playbooks für Adversary-Simulation und Härtungshandbücher aus. Es deckt fortgeschrittene Obfuskationstechniken ab, wie Domain-Fronting, die Nutzung von Platform-as-a-Service-Redirectoren und die Nutzung von Drittanbieter-Content-Seiten, um Domain-Reputation zu erben und Sicherheitsfilter zu umgehen. Die technische Oberfläche erstreckt sich auf die Automatisierung der operativen Sicherheit, einschließlich der Verteilung von Infrastruktur-Assets über mehrere Cloud-Anbieter und geografische Regionen hinweg. Es umfasst Funktionen für Credential-Capture via Adversary-in-the-Middle-Proxies, zentralisierte Log-Aggregation und die Implementierung von unveränderlicher Systemdateihärtung zur Sicherung operativer Server. Das Projekt enthält zudem Dienstprogramme für die Domain-Analyse, wie die Verifizierung von Anbieterkategorisierungen und die Identifizierung seriöser abgelaufener Domains, um sich besser in Zielnetzwerke einzufügen.
Hides command and control communications using redirectors and domain fronting to blend into network traffic.
Shadowsocks-rss ist ein RSS-Feed-Generator und Versions-Tracker, der darauf ausgelegt ist, die Verteilung von Update-Benachrichtigungen und Download-Links für ShadowsocksR-Clients zu automatisieren. Es fungiert als Verteilungssystem, das spezifische Software-Branches überwacht, um sicherzustellen, dass verschlüsselte Proxy-Clients die neuesten stabilen Releases verfolgen können. Das Projekt konzentriert sich auf automatisiertes Release-Tracking für Netzwerk-Obfuskationssoftware und veröffentlicht strukturierte XML-Feeds, die Versionsbenachrichtigungen und direkte Download-Links für verschiedene Client-Versionen bereitstellen. Das System unterstützt Software-Release-Monitoring und die Verteilung von Updates für VPN-Clients durch die Verwendung strukturierter Feeds.
Masks encrypted communication patterns by mimicking standard web traffic to bypass deep packet inspection.
This project is a toolset for automated VPN installation, proxy server management, and server-side network throughput optimization. It provides a Shadowsocks proxy server manager used to deploy and configure proxy servers on virtual private servers. The system utilizes automated deployment scripts to handle the installation of encryption methods, ports, and passwords on remote servers. It includes a VPS network optimizer that activates BBR congestion control to reduce latency and increase throughput for high-bandwidth streaming. The software covers remote proxy configuration and client confi
Wraps payload data in ciphers like AES-256-GCM to prevent deep packet inspection and censorship detection.
Godzilla is a post-exploitation toolkit and webshell management framework designed for remote administration, credential extraction, and memory shell injection. It provides a centralized platform to deploy, control, and monitor encrypted remote access scripts across multiple server environments. The project differentiates itself through a memory shell injector that loads binaries and shellcode directly into server memory to avoid disk-based detection. It also employs polyglot payload injection, deploying encrypted scripts across various language environments to maintain persistent connections
Encodes traffic between operator and injected payloads using AES or XOR ciphers to evade network detection.
This project is a censorship circumvention tool and transparent proxy gateway designed to bypass local network restrictions. It functions as a SOCKS5 proxy server, a DNS tunneling tool, and a network traffic obfuscator to help users access blocked websites. The software implements masking protocols to hide the origin and destination of data to evade restrictive firewalls. It provides capabilities for network traffic obfuscation and secure DNS tunneling to protect network privacy and resolve blocked domains. The system handles wide-scale traffic management by intercepting system network traff
Implements masking protocols to hide data origin and destination to evade deep packet inspection.
Cloak ist eine Sammlung von Tools zur Umgehung von Zensur, die für sicheres Proxy-Tunneling und die Verschleierung von Internetverkehr entwickelt wurden. Der Fokus liegt darauf, restriktive Firewalls und staatliche Überwachung zu umgehen, indem Proxy-Verbindungen als normales Web-Browsing getarnt werden. Das Projekt nutzt HTTP-Fingerprint-Masquerading, um gängige Browser-Signaturen zu imitieren, und leitet den Datenverkehr über Content Delivery Networks, um die Identität des Ursprungsservers zu maskieren. Um den Zweck des Servers weiter zu verbergen, enthält es einen Mechanismus, um nicht authentifizierte Verbindungsanfragen auf eine Drittanbieter-Website umzuleiten. Das System implementiert Transport-Payload-Verschlüsselung und authentifizierte Verschlüsselungsalgorithmen, um die Inspektion und Manipulation von Datenströmen zu verhindern. Es unterstützt Zero-Round-Trip-Authentifizierung via Schlüsselaustausch, um Handshake-Verzögerungen zu eliminieren, und nutzt Connection-Multiplexing, um mehrere logische Verbindungen in einer einzigen Sitzung abzubilden. Zusätzliche Funktionen umfassen Netzwerkzugriffsverwaltung zur Steuerung von Benutzerrechten und Bandbreitenbegrenzungen über eine persistente Datenbank.
Masks network traffic by disguising proxy connections as standard web browsing to bypass deep packet inspection.
Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions. The project distinguishes itself through its ability to bypass PowerShell Constrained Language Mode using specialized payload generation. It supports encrypted command and control via TLS certificate injection and provides mechanisms for remote session recovery, allowing a handler to reestablish control over active
Disguises session traffic by using custom HTTP header names to bypass antivirus traffic analysis.