WinDivert 1.4: Windows Packet Divert

Windows Packet Divert (WinDivert) is a user-mode packet capture-and-divert package for Windows 2008, Windows 7, Windows 8, Windows 10 and Windows 2016.

WinDivert allows user-mode applications to capture/modify/drop network packets sent to/from the Windows network stack. In summary, WinDivert can:

  • capture network packets
  • filter/drop network packets
  • sniff network packets
  • (re)inject network packets
  • modify network packets

WinDivert can be used to implement user-mode packet filters, packet sniffers, firewalls, NAT, VPNs, tunneling applications, etc.

The main features of WinDivert include:

  • packet interception, sniffing, or dropping modes
  • supports loopback (localhost) traffic
  • full IPv6 support
  • network layer
  • simple yet powerful API
  • high-level filtering language
  • filter priorities
  • silent installation
  • freely available under the terms of the GNU Lesser General Public License (LGPL)

➢ Documentation and Samples

➢ Source Repository

The source code for WinDivert is hosted on GitHub:

Note that the repository version of WinDivert should generally be considered unstable.

➢ Download

The following stable source packages for WinDivert are available:

The following stable binary packages for WinDivert are available.


  1. The WinDivert 1.4 API differs from older versions. Compared to the WinDivert 1.3 API:
    • The WINDIVERT_ADDRESS layout has changed.
    • The WinDivertHelperCalcChecksums interface has changed.
    • It is no longer necessary to calculate checksums when re-injecting unmodified packets.
    Please see the WinDivert 1.4 documentation for more information.
  2. To use WinDivert please ensure that you use the correct version (i.e. 32-bit WinDivert for 32-bit system, etc.) and that you are running with Administrator privileges, otherwise WinDivert will fail to load.
  3. As of version 1.0.4, the binary WinDivert drivers are signed by one or more of our sponsors. We would like to thank ParentsDansLesParages (Ars Nova Systems, also see here for the English site) for their support. Commercial users of WinDivert should sign the driver with their own certificate if possible. Note that the current driver signature has some caveats:
    • Windows 7 systems must be up-to-date or at least have KB3033929 installed.
    • Windows Server 2016 systems must have secure boot disabled.
  4. The WinDivert A and B variants are identical aside from the driver signatures. For most applications it does not matter which variant is used.

➢ Projects

The following projects use WinDivert:

Disclaimer: Links are provided purely for information only---basil does not endorse nor provide any guarantee regarding software quality, fitness for purpose, etc. Furthermore, basil accepts no liability for loss or damages, etc.

Contact basil if you want to add a link to your WinDivert-related project.

➢ Contact

Send feedback and/or questions to:

Copyright © 2018 basil