// the find
ValdikSS/GoodbyeDPI
GoodbyeDPI — Deep Packet Inspection circumvention utility (for Windows)
GoodbyeDPI is a Windows command-line tool that gets past ISP Deep Packet Inspection by fragmenting the TLS ClientHello and HTTP Host header, and by sending decoy packets with low TTL, bad checksums, or wrong sequence numbers. It uses the WinDivert driver to intercept packets in userspace. It is for Windows users whose ISP blocks sites by inspecting traffic, and the defaults were tuned around Russian ISPs.
The fragmentation modes are split into two sends with --native-frag and --reverse-frag without shrinking the TCP window, so throughput holds up where the older -f and -e options slowed connections down. The --blacklist flag limits the tricks to hostnames listed in a text file, which keeps the more aggressive fake-packet modes away from unrelated traffic. The legacy and modern modesets are labelled, and the README says which flags can break sites, which is more candid than most circumvention projects. The whole thing is plain C with a small source tree, so a reader can follow the packet path without a build system.
It is Windows-only and needs administrator rights, with a console window that has to stay open. Running it as a service means editing .cmd scripts by hand, not using an installer. The default modeset and the recommended DNS redirect script assume Russian ISP behavior, and the guidance for other countries is a single line that leaves users to work out which DPI they are fighting. The option surface is large and the modesets overlap, so finding what works on a given network means trial and error, and the --set-ttl and --auto-ttl modes can break sites in ways that are hard to diagnose. Everything also depends on the third-party WinDivert driver, and the README's own known-issues list (ESET, Killer NICs, QUIK) shows how much that integration can conflict with other software.