awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

20 repository-uri

Awesome GitHub RepositoriesTraffic Obfuscation

Techniques for masking network traffic to bypass deep packet inspection and restrictive firewalls.

Distinguishing note: Focuses on packet header modification for connectivity rather than general encryption.

Explore 20 awesome GitHub repositories matching networking & communication · Traffic Obfuscation. Refine with filters or upvote what's useful.

Awesome Traffic Obfuscation GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • qiuyuzhou/shadowsocksx-ngAvatar qiuyuzhou

    qiuyuzhou/ShadowsocksX-NG

    32,888Vezi pe GitHub↗

    ShadowsocksX-NG is a macOS application that functions as a Shadowsocks proxy client to establish encrypted tunnels for bypassing network censorship. It operates as an encrypted tunnel manager that allows for the configuration of secure ciphers and the import of proxy server profiles. The client includes a proxy converter that transforms SOCKS5 traffic into HTTP proxy traffic to provide compatibility for applications that do not support SOCKS. It also integrates a traffic steering system using Proxy Auto-Configuration files to automatically determine which network requests bypass the proxy. T

    Supports traffic obfuscation plugins to mask encrypted data and evade deep packet inspection.

    Swift
    Vezi pe GitHub↗32,888
  • wg-easy/wg-easyAvatar wg-easy

    wg-easy/wg-easy

    24,645Vezi pe GitHub↗

    This project provides a self-hosted, containerized WireGuard VPN server that simplifies network administration through a web-based management interface. It allows users to deploy and manage VPN tunnels, configure peer identities, and monitor connection status without the need for manual configuration file editing. By bundling the VPN stack into a portable container, it ensures consistent deployment and persistent state management across diverse host environments. A key differentiator is the built-in support for traffic obfuscation, which modifies packet headers and handshake patterns to help

    Implements traffic obfuscation to bypass deep packet inspection and restrictive network filtering.

    TypeScript
    Vezi pe GitHub↗24,645
  • streisandeffect/streisandAvatar StreisandEffect

    StreisandEffect/streisand

    23,464Vezi pe GitHub↗

    Streisand is an orchestration system for deploying multi-protocol tunneling services and traffic obfuscation tools designed to circumvent regional network restrictions. It functions as a deployment utility and manager for various VPN and proxy services on remote cloud servers. The system distinguishes itself through a network obfuscation toolkit that wraps traffic in layers to evade deep packet inspection and bandwidth throttling. It automates the setup of multiple protocols, including WireGuard, OpenVPN, Shadowsocks, OpenConnect, OpenSSH, and Tor bridges. The project also includes utilities

    Masks network traffic to bypass deep packet inspection and prevent bandwidth throttling.

    Shellansibleanyconnectcensorship
    Vezi pe GitHub↗23,464
  • ginuerzh/gostAvatar ginuerzh

    ginuerzh/gost

    18,019Vezi pe GitHub↗

    gost is a multi-protocol proxy tunnel and secure tunneling server designed to route network traffic through encrypted connections. It functions as a traffic obfuscation gateway and a transparent proxy server capable of intercepting TCP and UDP traffic at the IP level. The project also includes a virtual network interface manager for creating TUN and TAP devices to intercept operating system packets. The system distinguishes itself through a chain-based request routing model, allowing traffic to pass through an ordered sequence of proxy nodes. It provides extensive transport-layer encapsulatio

    Masks network traffic using WebSocket, HTTP/2, and QUIC to bypass firewalls and deep packet inspection.

    Godnsgogolang
    Vezi pe GitHub↗18,019
  • signalapp/signal-desktopAvatar signalapp

    signalapp/Signal-Desktop

    16,376Vezi pe GitHub↗

    Signal-Desktop is a cross-platform messaging application that provides end-to-end encrypted communication. It implements the Signal Protocol to secure messages and voice calls, ensuring that only intended recipients can access content. The application manages asynchronous key exchange and session initialization to maintain secure communication channels between parties who are not online simultaneously. The project distinguishes itself through advanced cryptographic protections, including hybrid post-quantum security that combines classical elliptic curve cryptography with lattice-based algori

    Protects message metadata by encrypting packet headers with rotating keys to prevent traffic analysis.

    TypeScript
    Vezi pe GitHub↗16,376
  • bol-van/zapretAvatar bol-van

    bol-van/zapret

    15,555Vezi pe GitHub↗

    Zapret is a deep packet inspection bypass tool and packet manipulation framework designed to circumvent network censorship. It operates as a transparent network proxy and TCP traffic obfuscator that modifies packets to deceive network inspection systems. The project distinguishes itself through advanced desynchronization strategies, including the modification of TLS client hello handshakes and the use of fake packet injection. It utilizes a combination of TCP stream segmentation, sequence overlapping, and TTL adjustment to hide prohibited requests from firewalls while ensuring the destination

    Hides prohibited requests from network firewalls using TCP segmentation and fragmentation.

    Canti-dpicensorship-circumventionfreebsd
    Vezi pe GitHub↗15,555
  • getlantern/lanternAvatar getlantern

    getlantern/lantern

    15,227Vezi pe GitHub↗

    Lantern is a network utility designed to provide access to restricted internet content by tunneling traffic through encrypted connections. It functions as a censorship circumvention tool that enables private web browsing and ensures reliable connectivity in environments where standard network access is blocked or monitored. The application employs a decentralized infrastructure that routes data through a network of distributed proxy nodes. To maintain connectivity in the face of interference, it utilizes dynamic proxy discovery and adaptive fallback mechanisms that automatically switch betwee

    Implements traffic obfuscation techniques to hide network patterns from deep packet inspection and firewalls.

    Dartacceleratorcensorshipcircumvention
    Vezi pe GitHub↗15,227
  • bia-pain-bache/bpb-worker-panelAvatar bia-pain-bache

    bia-pain-bache/BPB-Worker-Panel

    11,997Vezi pe GitHub↗

    BPB-Worker-Panel is a control panel designed for deploying and managing VLESS and Trojan proxies hosted on Cloudflare Workers. It functions as a proxy subscription generator and a manager for secure DNS over HTTPS servers and WireGuard configuration provisioning. The project distinguishes itself through network traffic obfuscation capabilities, utilizing packet fragmentation and SNI spoofing to evade detection. It provides specialized administration for Cloudflare Warp and Warp Pro connections, including the ability to optimize endpoints and export WireGuard configurations. The system covers

    Modifies data packet fragments and injects noise strings to disguise proxy traffic and bypass deep packet inspection.

    TypeScriptamneziaandroidchain
    Vezi pe GitHub↗11,997
  • amnezia-vpn/amnezia-clientAvatar amnezia-vpn

    amnezia-vpn/amnezia-client

    10,108Vezi pe GitHub↗

    Amnezia Client is a cross-platform VPN client application and server orchestrator designed to manage secure tunnels and automate the deployment of containerized VPN services on remote self-hosted servers. It functions as a multi-protocol VPN manager that supports various tunneling standards to ensure connectivity across restrictive network environments. The project distinguishes itself through network traffic obfuscation, which disguises VPN traffic as common web protocols or DNS requests to bypass deep packet inspection and censorship. It further enables the automation of remote server admin

    Hides encrypted tunnel signatures by mimicking common network protocols to bypass deep packet inspection.

    C++cloakgfwikev2
    Vezi pe GitHub↗10,108
  • p4gefau1t/trojan-goAvatar p4gefau1t

    p4gefau1t/trojan-go

    8,385Vezi pe GitHub↗

    Trojan-go is a network proxy implementation that uses the Trojan protocol to disguise internet traffic as standard TLS to bypass censorship and deep packet inspection. It functions as a tunneling gateway that encapsulates network data within encrypted tunnels to mimic ordinary web browsing. The project distinguishes itself through advanced obfuscation techniques, including TLS fingerprint mimicry to avoid detection by client signature identification and the use of WebSockets to relay encrypted traffic through content delivery networks. It also supports UDP forwarding through the Trojan protoc

    Wraps protocol traffic in WebSockets to relay encrypted data through content delivery networks for obfuscation.

    Goanticensorshipchinagfw
    Vezi pe GitHub↗8,385
  • xtls/realityAvatar XTLS

    XTLS/REALITY

    5,272Vezi pe GitHub↗

    REALITY este un instrument de evitare a cenzurii și un obfuscator de trafic de rețea conceput pentru a ocoli filtrele de internet. Funcționează ca un protocol de tunelare securizat care maschează tiparele de conexiune și identitatea prin imitarea handshake-urilor TLS ale site-urilor web țintă legitime. Sistemul elimină amprentele TLS de pe partea de server pentru a ascunde traficul criptat de instrumentele de monitorizare a rețelei și de inspecția profundă a pachetelor (DPI). Utilizează un proxy de imitare a site-urilor web pentru a prezenta handshake-uri valide și a redirecționa traficul către serverele de destinație, mascând conexiunea ca pe o vizită legitimă pe site. Proiectul încorporează un strat TLS rezistent la atacuri cuantice, care utilizează semnături criptografice post-cuantice pentru a proteja handshake-urile și certificatele de viitoare amenințări de decriptare. Include, de asemenea, capabilități pentru verificarea temporară a certificatelor și redirecționarea transparentă a traficului.

    Eliminates server-side TLS fingerprints to hide encrypted tunnels from deep packet inspection and network monitoring tools.

    Gorealityvlessxray
    Vezi pe GitHub↗5,272
  • dovecoteescapee/byedpiandroidAvatar dovecoteescapee

    dovecoteescapee/ByeDPIAndroid

    5,043Vezi pe GitHub↗

    ByeDPIAndroid is a deep packet inspection bypass tool for Android that functions as a local SOCKS5 proxy. It modifies TCP packets to evade network censorship and bypass regional internet restrictions on mobile devices. The project operates as a network traffic obfuscator and TCP packet fragmenter. It splits network data into smaller pieces and hides the nature of internet requests to prevent automated blocking and traffic shaping by internet service providers. The system covers a range of capabilities including host-based traffic interception and dynamic packet modification. It utilizes non-

    Masks network requests to prevent automated censorship blocks and traffic shaping by ISPs.

    Kotlinanticensorshipcensorship-circumventiondeep-packet-inspection
    Vezi pe GitHub↗5,043
  • xvzc/spoofdpiAvatar xvzc

    xvzc/spoofdpi

    4,794Vezi pe GitHub↗

    SpoofDPI este o aplicație de rețea și un server proxy local conceput ca un instrument anti-cenzură. Acesta funcționează ca un proxy de ocolire a inspecției profunde a pachetelor (DPI) care fragmentează și modifică cererile HTTP de ieșire pentru a evita filtrele de rețea și cenzura. Proiectul realizează acest lucru prin implementarea fragmentării cererilor HTTP, împărțind cererile unice în mai multe pachete mai mici pentru a induce în eroare firewall-urile. De asemenea, efectuează manipularea fluxului TCP și obfuscare a traficului de rețea pentru a ascunde natura cererilor web și a ocoli blocajele de conținut regionale. Sistemul include capabilități pentru redirecționarea transparentă a rețelei și gestionarea configurației bazată pe fișiere pentru a coordona modul în care este gestionat traficul de rețea.

    Masks network traffic patterns to prevent firewalls from identifying and blocking specific web requests.

    Goanti-censorshipcensorship-circumventioncensorship-free
    Vezi pe GitHub↗4,794
  • bluscreenofjeff/red-team-infrastructure-wikiAvatar bluscreenofjeff

    bluscreenofjeff/Red-Team-Infrastructure-Wiki

    4,498Vezi pe GitHub↗

    Acest proiect este o colecție de resurse tehnice, planuri și ghiduri pentru construirea unei infrastructuri red team reziliente și discrete. Oferă un framework cuprinzător pentru proiectarea mediilor de securitate ofensivă care rezistă detectării și rămân operaționale pe parcursul angajamentelor de securitate. Repository-ul se distinge prin manuale detaliate pentru simularea adversarilor și manuale de hardening. Acoperă tehnici avansate de ofuscare, cum ar fi domain fronting, utilizarea redirectoarelor platform-as-a-service și valorificarea site-urilor de conținut terțe pentru a moșteni reputația domeniului și a evita filtrele de securitate. Suprafața tehnică se extinde la automatizarea securității operaționale, inclusiv distribuția activelor de infrastructură pe mai mulți furnizori cloud și regiuni geografice. Include capabilități pentru capturarea credențialelor prin proxy-uri adversary-in-the-middle, agregarea centralizată a log-urilor și implementarea hardening-ului fișierelor de sistem imutabile pentru a securiza serverele operaționale. Proiectul include, de asemenea, utilitare pentru analiza domeniului, cum ar fi verificarea categorisirilor furnizorilor și identificarea domeniilor expirate reputate pentru a se integra mai bine în rețelele țintă.

    Hides command and control communications using redirectors and domain fronting to blend into network traffic.

    Vezi pe GitHub↗4,498
  • shadowsocksr-backup/shadowsocks-rssAvatar shadowsocksr-backup

    shadowsocksr-backup/shadowsocks-rss

    4,439Vezi pe GitHub↗

    Shadowsocks-rss is an RSS feed generator and version tracker designed to automate the distribution of update notifications and download links for ShadowsocksR clients. It functions as a distribution system that monitors specific software branches to ensure encrypted proxy clients can track the latest stable releases. The project focuses on automated release tracking for network obfuscation software, publishing structured XML feeds that provide version notifications and direct download links for various client versions. The system supports software release monitoring and the distribution of u

    Masks encrypted communication patterns by mimicking standard web traffic to bypass deep packet inspection.

    Vezi pe GitHub↗4,439
  • clown-coding/vpnAvatar clown-coding

    clown-coding/vpn

    4,424Vezi pe GitHub↗

    This project is a toolset for automated VPN installation, proxy server management, and server-side network throughput optimization. It provides a Shadowsocks proxy server manager used to deploy and configure proxy servers on virtual private servers. The system utilizes automated deployment scripts to handle the installation of encryption methods, ports, and passwords on remote servers. It includes a VPS network optimizer that activates BBR congestion control to reduce latency and increase throughput for high-bandwidth streaming. The software covers remote proxy configuration and client confi

    Wraps payload data in ciphers like AES-256-GCM to prevent deep packet inspection and censorship detection.

    Vezi pe GitHub↗4,424
  • beichendream/godzillaAvatar BeichenDream

    BeichenDream/Godzilla

    4,333Vezi pe GitHub↗

    Godzilla is a post-exploitation toolkit and webshell management framework designed for remote administration, credential extraction, and memory shell injection. It provides a centralized platform to deploy, control, and monitor encrypted remote access scripts across multiple server environments. The project differentiates itself through a memory shell injector that loads binaries and shellcode directly into server memory to avoid disk-based detection. It also employs polyglot payload injection, deploying encrypted scripts across various language environments to maintain persistent connections

    Encodes traffic between operator and injected payloads using AES or XOR ciphers to evade network detection.

    Vezi pe GitHub↗4,333
  • fw876/helloworldAvatar fw876

    fw876/helloworld

    4,165Vezi pe GitHub↗

    Acest proiect este un instrument de ocolire a cenzurii și un gateway proxy transparent conceput pentru a ocoli restricțiile rețelei locale. Funcționează ca un server proxy SOCKS5, un instrument de tunelare DNS și un obfuscator de trafic de rețea pentru a ajuta utilizatorii să acceseze site-urile blocate. Software-ul implementează protocoale de mascare pentru a ascunde originea și destinația datelor pentru a evita firewall-urile restrictive. Oferă capabilități pentru obfuscarea traficului de rețea și tunelare DNS securizată pentru a proteja confidențialitatea rețelei și a rezolva domeniile blocate. Sistemul gestionează gestionarea traficului la scară largă prin interceptarea traficului de rețea al sistemului prin reguli de firewall și conversia tabelelor IP. Include o arhitectură modulară pentru dezvoltarea de plugin-uri proxy personalizate pentru a defini reguli de rutare specializate.

    Implements masking protocols to hide data origin and destination to evade deep packet inspection.

    C
    Vezi pe GitHub↗4,165
  • cbeuw/cloakAvatar cbeuw

    cbeuw/Cloak

    4,026Vezi pe GitHub↗

    Cloak este un set de instrumente pentru evitarea cenzurii, conceput pentru tunelare proxy securizată și ofuscarea traficului de internet. Se concentrează pe ocolirea firewall-urilor restrictive și a supravegherii statale prin deghizarea conexiunilor proxy ca navigare web standard. Proiectul utilizează mascarea amprentelor HTTP pentru a imita semnăturile browserelor comune și direcționează traficul prin rețele de livrare de conținut (CDN) pentru a ascunde identitatea serverului de origine. Pentru a masca și mai mult scopul serverului, include un mecanism de redirecționare a cererilor de conexiune neautentificate către un site web terț. Sistemul implementează criptarea sarcinii utile (payload) de transport și cifruri de criptare autentificată pentru a preveni inspecția și manipularea fluxurilor de date. Suportă autentificarea zero round trip prin schimb de chei pentru a elimina întârzierile de handshake și folosește multiplexarea conexiunilor pentru a mapa mai multe conexiuni logice într-o singură sesiune. Capabilitățile suplimentare includ gestionarea accesului la rețea pentru a controla permisiunile utilizatorilor și limitele de lățime de bandă printr-o bază de date persistentă.

    Masks network traffic by disguising proxy connections as standard web browsing to bypass deep packet inspection.

    Gocensorshipcensorship-circumventiongfw
    Vezi pe GitHub↗4,026
  • t3l3machus/hoaxshellAvatar t3l3machus

    t3l3machus/hoaxshell

    3,421Vezi pe GitHub↗

    Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions. The project distinguishes itself through its ability to bypass PowerShell Constrained Language Mode using specialized payload generation. It supports encrypted command and control via TLS certificate injection and provides mechanisms for remote session recovery, allowing a handler to reestablish control over active

    Disguises session traffic by using custom HTTP header names to bypass antivirus traffic analysis.

    Pythonhackingopen-sourcepenetration-testing
    Vezi pe GitHub↗3,421
  1. Home
  2. Networking & Communication
  3. Traffic Obfuscation

Explorează sub-etichetele

  • CDN Relay ObfuscationTechniques to route obfuscated traffic through content delivery networks using WebSockets. **Distinct from Traffic Obfuscation:** Distinct from general traffic obfuscation: specifically utilizes CDN infrastructure as a relay for encrypted traffic.
  • Cipher-Based Payload WrappersTechniques that wrap payload data in configurable ciphers to prevent deep packet inspection and censorship detection. **Distinct from Traffic Obfuscation:** Distinct from Traffic Obfuscation: focuses on cipher-based payload encryption rather than packet header modification.
  • Header Obfuscation1 sub-tagTechniques for encrypting packet headers to prevent traffic analysis and participant correlation. **Distinct from Traffic Obfuscation:** Distinct from Traffic Obfuscation: focuses on metadata/header encryption specifically rather than general network masking.