dilluti0n/dpibreak

System-wide DPI circumvention with minimal configuration (Linux, Windows)

Rust

139

486 commits

updated Oct 2, 2026

See the code

README

DPIBreak

GitHub Release

DPIBreak allows you to access blocked HTTPS sites by manipulating a tiny bit of outgoing packets.

The goal is to provide system-wide circumvention with the minimal configuration interface.

All you have to do is just start the program, and it will start working. If the bypass doesn't work, you can try applying other flags like -o 0,5 -a.

winget install dpibreak  # Windows
curl -fsSL https://raw.githubusercontent.com/dilluti0n/dpibreak/master/install.sh | sh   # Linux

Press Win+R and type dpibreak on Windows, sudo dpibreak on Linux. dpibreak -h for options.

Packaging status

Usage

dpibreak
dpibreak -d               # run as daemon
dpibreak -o 0,5           # if a site breaks that worked before
dpibreak -a               # if bypass does not work
dpibreak -o 0,5 -a        # combined

dpibreak --help

See dpibreak(1) for full manual. If site still blocked, don't hesitate to open an issue.

Features

Segmentation (default)

Split the TLS ClientHello into smaller pieces so that stateless DPI equipment cannot classify.

Configured via -o, --segment-order. (Default: -o 0,1)

Out-of-order splits like -o 5,0 are also available.

See #14 for examples that help illustrate the rules.

Fake

Enable fake ClientHello packet (with SNI www.microsoft.com) injection to fool stateful DPI equipment.

For typical usage, use -a, --fake-autottl.

I live in South Korea, and Korean ISP-level DPI was bypassable without this feature. However, the internal DPI at my university was not. With this feature enabled, the university's DPI was also successfully bypassed, so I expect it to be helpful in many other use cases as well.

Troubleshooting

Winget upgrade fails (#21)

Run sc stop windivert in administrator cmd.exe and rerun the upgrade command.

A site that worked before stops working with dpibreak (#23)

Try -o 0,5.

-a, --fake-autottl make things worse (#20)

Try --fake-ttl 6, if that fails, see the workaround on issue.

Traffic forwarded through a WireGuard/VPN server is not handled (#31)

Run DPIBreak with the script in #31.

Built upon

See also


Copyright 2025-2026 Dilluti0n.

This program is free software, released under the GNU General Public License, version 3 or later.

anticensorship
deep-packet-inspection
netfilter-queue
rust

Significant stargazers

Itamar Turner-Trauring

405 followers · starred Feb 2026

ignoramous

282 followers · starred Jun 2026

Ryan Zoeller

32 followers · starred Feb 2026

Kim Myeongseop

8 followers · starred Apr 2026

dilluti0n/dpibreak

System-wide DPI circumvention with minimal configuration (Linux, Windows)

Rust

139

486 commits

updated Oct 2, 2026

See the code

README

DPIBreak

GitHub Release

DPIBreak allows you to access blocked HTTPS sites by manipulating a tiny bit of outgoing packets.

The goal is to provide system-wide circumvention with the minimal configuration interface.

All you have to do is just start the program, and it will start working. If the bypass doesn't work, you can try applying other flags like -o 0,5 -a.

winget install dpibreak  # Windows
curl -fsSL https://raw.githubusercontent.com/dilluti0n/dpibreak/master/install.sh | sh   # Linux

Press Win+R and type dpibreak on Windows, sudo dpibreak on Linux. dpibreak -h for options.

Packaging status

Usage

dpibreak
dpibreak -d               # run as daemon
dpibreak -o 0,5           # if a site breaks that worked before
dpibreak -a               # if bypass does not work
dpibreak -o 0,5 -a        # combined

dpibreak --help

See dpibreak(1) for full manual. If site still blocked, don't hesitate to open an issue.

Features

Segmentation (default)

Split the TLS ClientHello into smaller pieces so that stateless DPI equipment cannot classify.

Configured via -o, --segment-order. (Default: -o 0,1)

Out-of-order splits like -o 5,0 are also available.

See #14 for examples that help illustrate the rules.

Fake

Enable fake ClientHello packet (with SNI www.microsoft.com) injection to fool stateful DPI equipment.

For typical usage, use -a, --fake-autottl.

I live in South Korea, and Korean ISP-level DPI was bypassable without this feature. However, the internal DPI at my university was not. With this feature enabled, the university's DPI was also successfully bypassed, so I expect it to be helpful in many other use cases as well.

Troubleshooting

Winget upgrade fails (#21)

Run sc stop windivert in administrator cmd.exe and rerun the upgrade command.

A site that worked before stops working with dpibreak (#23)

Try -o 0,5.

-a, --fake-autottl make things worse (#20)

Try --fake-ttl 6, if that fails, see the workaround on issue.

Traffic forwarded through a WireGuard/VPN server is not handled (#31)

Run DPIBreak with the script in #31.

Built upon

See also


Copyright 2025-2026 Dilluti0n.

This program is free software, released under the GNU General Public License, version 3 or later.

anticensorship
deep-packet-inspection
netfilter-queue
rust

Significant stargazers

Itamar Turner-Trauring

405 followers · starred Feb 2026

ignoramous

282 followers · starred Jun 2026

Ryan Zoeller

32 followers · starred Feb 2026

Kim Myeongseop

8 followers · starred Apr 2026

Languages

Rust

79.4%

Roff

8.1%

PowerShell

4.1%

Shell

3.9%

Makefile

2.3%

Batchfile

1.1%