# Shroudly
Unseen. Unstoppable.
> Break through internet censorship on Windows, macOS and Linux. No VPN, no drivers, no third-party tools, and nothing that permanently changes your network settings.
A Codeshare product
What is Shroudly?
Shroudly runs a tiny local proxy and reshapes the first packet of each
connection — the one that carries the TLS SNI or the HTTP Host header — so that
Deep Packet Inspection (DPI) systems can no longer read which site you are
visiting. Your traffic still goes straight to the real server; only the DPI in
the middle is defeated.
It is built on its own engine, shroudly-core, written from scratch in
portable C. It uses nothing but the operating system's own socket API, so the
exact same technique works unprivileged on every platform. There is no kernel
driver, no WinDivert, no external library.
While Shroudly is active it points the system (or your browser) at its local proxy, and it always restores the previous setting on stop, crash, or logout — so your internet is never left broken.
How it works
Without Shroudly:
[Browser] --> [DPI reads SNI "example.com" -> BLOCKED] --> X
With Shroudly:
[Browser] --> [shroudly-core local proxy]
| splits / reorders the ClientHello so the SNI is never
| readable in a single segment
v
[DPI sees fragments it cannot reassemble -> passes]
v
[Real server reassembles normally -> OK]
The engine inspects the first client payload, finds the exact SNI/Host position (parsing the whole TLS ClientHello, even when it spans several TCP segments — which modern post-quantum Chrome hellos routinely do), and applies a **desync strategy**:
| Technique | What it does |
|-----------|--------------|
| Split at SNI | Sends the ClientHello in separate writes so the SNI is cut across segment boundaries. |
| Disorder | Sends the later segment first; the server's TCP stack reorders it correctly, a stateless DPI cannot. |
| Mid-SNI / double split | Extra split points inside and around the hostname for stubborn DPI. |
| HTTP Host scramble | Rewrites Host: casing for plain HTTP. |
| Anti-poisoning DNS | Resolves names against several independent public resolvers in parallel and drops spoofed / bogon answers, defeating DNS-based blocking without any encrypted-DNS dependency. |
| Auto-probe | Tests strategies against a host with a real handshake and remembers the one that works — like goodbyeDPI/zapret blockcheck, built in. |
Note on "fake packets". Low-TTL decoy packets (as used by driver-based
tools) require raw-socket injection and cannot be done correctly through a
userspace proxy without corrupting the real stream. Shroudly therefore relies
on split/disorder in its default driver-free mode, which is sufficient against
stateless SNI/Host DPI. A raw-socket mode (SHROUDLY_RAW) is reserved for a
future optional elevated build.
Features
- Cross-platform — one engine, native builds for Windows, macOS and Linux (x64 and arm64).
- No elevation, no driver — runs as a normal user; nothing is installed into the kernel.
- Never breaks your connection — system proxy is snapshotted and restored on stop/crash/exit.
- Real auto-probe — finds and learns a working strategy per host.
- Anti-poisoning resolver — optional multi-resolver DNS that filters spoofed answers.
- Honest live stats — connections, bytes, TLS/HTTP seen and desyncs applied are real counters streamed from the engine, not estimates.
- System tray, auto-start, auto mode — per-OS login item on Windows/macOS,
.desktopentry on Linux. - 15 languages with automatic detection.
Languages
English, 中文, हिन्दी, Español, العربية, Русский, Português, Français, فارسی, Türkçe, বাংলা, اردو, Bahasa Indonesia, 日本語, Deutsch
Install
Download the latest build for your OS from Releases:
- Windows —
Shroudly-(NSIS installer)-x64.exe - macOS —
Shroudly-.dmg - Linux —
Shroudly-or.AppImage .deb
Build from source
Requirements: Node.js 20+, plus a C compiler. Any of these works:
- a system compiler (
cc/clang/gcc, or MSVCclon Windows), or zig(npm i -g zigorpip install ziglang) — this also lets one machine cross-build every OS.
git clone https://github.com/umutxyp/Shroudly.git
cd Shroudly
npm install # also compiles shroudly-core for your OS
run in dev
npm run electron:dev
package for your OS
npm run dist:win # or dist:mac / dist:linux
cross-build the engine for every OS/arch from one machine
npm run build:core:all
Project layout
Shroudly/
core/ the engine - portable C, no dependencies
src/
platform.[ch] OS abstraction (Winsock / BSD sockets, threads)
proto.[ch] TLS ClientHello + HTTP request parsing
strategy.[ch] desync strategy spec parser + presets
desync.[ch] applies a strategy to the first payload
doh.[ch] anti-poisoning DNS resolver
probe.[ch] per-host auto-probe
engine.[ch] SOCKS5 listener + relay
main.c CLI + stdin control protocol
test/test_proto.c unit tests
electron/
main.js app shell, tray, IPC, auto-start
engine-manager.js spawns shroudly-core, parses JSON, restarts
system-proxy.js set/restore OS proxy (Win/mac/Linux)
tools/core/<os>-<arch>/ built engine binaries (per platform)
app/ components/ contexts/ Next.js + React UI
translations.js 15-language strings
scripts/build-core.js native + cross compile
Engine control protocol
shroudly-core is a standalone program. The UI drives it over stdin and reads
JSON on stdout, but you can run it directly too:
shroudly-core --port 10808 --strategy "split(sni)" --auto --doh
then point any app at socks5://127.0.0.1:10808
Commands on stdin: STATS, PROBE , STOP.
Strategy syntax: split(sni), disorder(sni), split(sni_mid),
split(1),split(sni), split(2), and so on.
Testing
npm run test:core # unit tests for protocol + strategy parsing
Legal & responsible use
Shroudly exists to help people reach the free and open internet where it is unjustly censored. You are solely responsible for complying with the laws that apply to you. Do not use it to attack systems or to access things you are not entitled to.
License
MIT — see LICENSE.
Credits
- Electron, Next.js, Tailwind CSS
- Desync techniques inspired by the research behind
goodbyeDPIandzapret— reimplemented independently inshroudly-core.
Shroudly — Unseen. Unstoppable.
A Codeshare Technology Ltd product