Good Old SOCKS5: Why It Finally Needed TLS After Three Decades
Some technologies arrive with a bang, spend a few years at the peak of popularity, and then gradually disappear as something newer takes their…
High-performance NDIS packet processing frameworks, user-mode developer SDKs, and transparent network redirection tools. Engineered for systems programmers, network developers, and technical enterprises.
A high-performance packet filtering and injection framework that transparently integrates into the Windows NDIS network stack. Filter, inspect, modify, and inject raw network packets from user space without developing custom kernel-mode drivers.
WinpkFilter provides the raw packet manipulation primitives required to engineer specialized Windows networking solutions without kernel development risks:
Build custom VPN and tunnel implementations using direct packet interception and injection. Architectures without virtual network adapters are possible.
Intercept and redirect application TCP and UDP connections as a transparent building block for per-application or system-wide SOCKS5 and HTTPS proxying.
Build user-mode firewall and policy engines over intercepted packets, with optional kernel-side filtering for specialized implementations.
Capture raw Ethernet frames and log PCAP streams for protocol analysis, security telemetry, and network diagnostics without driver development.
Used in production software and open-source Windows networking projects. For more than two decades, Windows Packet Filter has been used as a building block in commercial Windows networking and security software.
A modern WireGuard-based VPN client for Windows built using Cloudflare BoringTun and WinpkFilter. WireSock uses WinpkFilter for transparent packet interception and direct packet injection in transparent mode, without requiring a virtual network adapter.
An open-source Windows traffic redirection utility and SOCKS5 proxifier built with WinpkFilter. ProxiFyre uses WinpkFilter for per-application and system-wide TCP/UDP redirection, routing network traffic through SOCKS5 proxies without modifying application binaries or system-wide proxy settings.
Specialized networking daemons, proxy servers, and infrastructure utilities developed and maintained across the NT KERNEL and WireSock ecosystem:
Asynchronous SOCKS5 proxy server with Dante-inspired access rules, deny-by-default filtering, Argon2id auth, rate limiting, and Windows RDP egress.
Automated server installation (AWG 2.0 default, AWG 3.0/3.1 optional), web management panel, and an AWG 2.0 DPI traffic obfuscation proxy.
Bounded, payload-opaque UDP traffic relay daemon in Rust for WireGuard and AmneziaWG endpoints, forwarding datagrams without TPROXY.
Lightweight, auditable Cloudflare Dynamic DNS client in Rust for Linux systemd, using scoped API v4 bearer tokens and differential updates.
Comprehensive developer SDK packages, API documentation, and official samples for C++, .NET, Rust, and Go:
Official driver runtime installers for ARM64, x64, and x86 with official Microsoft driver signatures. Includes C/C++ development headers, import libraries, and redistribution licenses.
Download SDK Package →Over 115 technical documentation endpoints covering driver initialization, adapter enumeration, packet filter modes, static filtering rules, and fast I/O control codes.
Browse API Reference →Official open-source language bindings and working samples maintained in native and modern ecosystems:
NT KERNEL has developed low-level Windows networking software and technical research since 2002.
Windows Packet Filter has evolved through four generations of the Windows networking stack: from NDIS 3.1 VxD on Windows 95/98 and NDIS 4 Hooking Filter on Windows NT 4.0/2000, through NDIS 5.1 Intermediate (IM) Filter on Windows XP/2003, to the modern NDIS 6.x Lightweight Filter (LWF) used by current Windows and Windows Server releases.
Throughout that evolution, the focus has remained the same: high-performance packet processing with a simple user-mode API that makes low-level traffic filtering practical to integrate into real applications.
Today, Windows Packet Filter provides a mature and actively maintained foundation for building transparent proxies, VPN clients, traffic inspection tools, security products, and other high-performance Windows networking applications without requiring developers to build their own kernel-mode filtering stack.
Deep dives into Windows kernel networking, NDIS architectures, protocol implementation, and network debugging:
Some technologies arrive with a bang, spend a few years at the peak of popularity, and then gradually disappear as something newer takes their…
WireGuard quickly became a popular VPN protocol: simple, fast, cleanly designed, and free of heavy legacy baggage. It stood out against monsters like IPsec…
On April 8, 2026, WireSock Secure Connect 3.4.4 was released as the first official version in the 3.x branch. For us, this is more…