Windows Networking & Kernel Technology Since 2002

Packet filtering and network engineering technology for Windows

High-performance NDIS packet processing frameworks, user-mode developer SDKs, and transparent network redirection tools. Engineered for systems programmers, network developers, and technical enterprises.

Primary Engine: WinpkFilter 3.x / NDIS 6.x LWF
Architectures: ARM64 • x64 • x86
Language APIs: C++ • C# / .NET • Rust • Go
Packet I/O: User-mode APIs + optional Fast I/O

Windows Packet Filter (WinpkFilter)

A high-performance packet filtering and injection framework that transparently integrates into the Windows NDIS network stack. Filter, inspect, modify, and inject raw network packets from user space without developing custom kernel-mode drivers.

Interfaces
Physical / Virtual Interfaces
Ethernet • Wi-Fi • Mobile Broadband • Virtual adapters
Kernel Mode
NDIS 6.x LWF Driver
Kernel packet interception & filtering (x64, ARM64, x86)
User Mode
NDISAPI Library
C++ runtime • Optional shared-memory Fast I/O
Developer APIs
Language Bindings
C++ • C# (.NET) • Rust • Go

What Developers Build With WinpkFilter

WinpkFilter provides the raw packet manipulation primitives required to engineer specialized Windows networking solutions without kernel development risks:

VPN Clients & Encrypted Tunnels

Build custom VPN and tunnel implementations using direct packet interception and injection. Architectures without virtual network adapters are possible.

Transparent Proxies & Redirection

Intercept and redirect application TCP and UDP connections as a transparent building block for per-application or system-wide SOCKS5 and HTTPS proxying.

Desktop Firewalls & Protocol Filters

Build user-mode firewall and policy engines over intercepted packets, with optional kernel-side filtering for specialized implementations.

Network Monitoring & Capture

Capture raw Ethernet frames and log PCAP streams for protocol analysis, security telemetry, and network diagnostics without driver development.

Built With Windows Packet Filter

Used in production software and open-source Windows networking projects. For more than two decades, Windows Packet Filter has been used as a building block in commercial Windows networking and security software.

Production VPN

WireSock Secure Connect

A modern WireGuard-based VPN client for Windows built using Cloudflare BoringTun and WinpkFilter. WireSock uses WinpkFilter for transparent packet interception and direct packet injection in transparent mode, without requiring a virtual network adapter.

Integration: Direct NDIS LWF packet injection
Open Source • Windows

ProxiFyre

An open-source Windows traffic redirection utility and SOCKS5 proxifier built with WinpkFilter. ProxiFyre uses WinpkFilter for per-application and system-wide TCP/UDP redirection, routing network traffic through SOCKS5 proxies without modifying application binaries or system-wide proxy settings.

Integration: WinpkFilter TCP/UDP redirection
Ecosystem Topology

NT KERNEL Architectural Map and Technology Boundaries

WinpkFilter Platform vs. Independent Networking Tools
NT KERNEL Ecosystem Architecture Map Diagram showing Windows Packet Filter, WireSock Secure Connect, and ProxiFyre grouped under kernel driver technologies, and Alighieri, WireRelay, AmneziaWG Toolkit, and Cirrusync as independent open-source network tools. WINPKFILTER PLATFORM & DERIVATIVES Kernel Driver Core CORE DRIVER & USER-MODE SDK Windows Packet Filter (WinpkFilter) NDIS 6.x LWF (ndisrd.sys) + NDISAPI User-Mode Library (C++, C#, Rust, Go) VPN CLIENT WireSock Secure Connect BoringTun WireGuard client. Uses WinpkFilter for transparent packet injection mode. WINDOWS PROXIFIER ProxiFyre Transparent SOCKS5 proxifier. Uses WinpkFilter for per-app and system-wide redirection. INDEPENDENT NETWORKING PROJECTS No WinpkFilter Dependency ASYNC SOCKS5 SERVER Alighieri Rust/Tokio SOCKS5 server. Dante ACLs, Argon2id auth, and Let's Encrypt TLS. OPAQUE UDP RELAY WireRelay Bounded UDP forwarder for WireGuard and AmneziaWG. No TPROXY or NAT complexity. DEPLOYMENT TOOLKIT AmneziaWG Toolkit Automated Linux server installer, web management panel, and DPI traffic camouflage proxy. DYNAMIC DNS CLIENT Cirrusync Lightweight Cloudflare DDNS daemon for Linux systemd using scoped API bearer tokens.
Architectural Boundaries: Windows Packet Filter provides the core kernel filtering driver and user-mode SDK used by WireSock (in transparent mode) and ProxiFyre. Alighieri, WireRelay, AmneziaWG Toolkit, and Cirrusync are standalone open-source utilities engineered with no kernel driver dependencies.

Open Source Networking Projects

Specialized networking daemons, proxy servers, and infrastructure utilities developed and maintained across the NT KERNEL and WireSock ecosystem:

Alighieri

Rust / Tokio SOCKS5

Asynchronous SOCKS5 proxy server with Dante-inspired access rules, deny-by-default filtering, Argon2id auth, rate limiting, and Windows RDP egress.

RFC 1928 • Multi-Tenant • Windows / Linux / macOS

AmneziaWG Toolkit

Deployment Toolkit

Automated server installation (AWG 2.0 default, AWG 3.0/3.1 optional), web management panel, and an AWG 2.0 DPI traffic obfuscation proxy.

Installer • Web Panel • AWG 2.0 Proxy

WireRelay

Network Infrastructure

Bounded, payload-opaque UDP traffic relay daemon in Rust for WireGuard and AmneziaWG endpoints, forwarding datagrams without TPROXY.

Rust / Tokio • Non-TPROXY UDP Relay

Cirrusync

Dynamic DNS

Lightweight, auditable Cloudflare Dynamic DNS client in Rust for Linux systemd, using scoped API v4 bearer tokens and differential updates.

Cloudflare API v4 • Linux systemd

Start Developing With WinpkFilter

Comprehensive developer SDK packages, API documentation, and official samples for C++, .NET, Rust, and Go:

Download SDK & Drivers

Official driver runtime installers for ARM64, x64, and x86 with official Microsoft driver signatures. Includes C/C++ development headers, import libraries, and redistribution licenses.

Download SDK Package →

API Documentation

Over 115 technical documentation endpoints covering driver initialization, adapter enumeration, packet filter modes, static filtering rules, and fast I/O control codes.

Browse API Reference →

GitHub Samples & Wrappers

Official open-source language bindings and working samples maintained in native and modern ecosystems:

Windows Network Engineering Since 2002

NT KERNEL has developed low-level Windows networking software and technical research since 2002.

Windows Packet Filter has evolved through four generations of the Windows networking stack: from NDIS 3.1 VxD on Windows 95/98 and NDIS 4 Hooking Filter on Windows NT 4.0/2000, through NDIS 5.1 Intermediate (IM) Filter on Windows XP/2003, to the modern NDIS 6.x Lightweight Filter (LWF) used by current Windows and Windows Server releases.

Throughout that evolution, the focus has remained the same: high-performance packet processing with a simple user-mode API that makes low-level traffic filtering practical to integrate into real applications.

Today, Windows Packet Filter provides a mature and actively maintained foundation for building transparent proxies, VPN clients, traffic inspection tools, security products, and other high-performance Windows networking applications without requiring developers to build their own kernel-mode filtering stack.

Latest from the Blog

Deep dives into Windows kernel networking, NDIS architectures, protocol implementation, and network debugging: