Official SDK & Runtime v3.6.2

Download Windows Packet Filter

Official Windows Packet Filter SDK, pre-compiled kernel-mode drivers, multi-language bindings, sample applications, and developer tooling. Free for personal, academic, and evaluation use.

Official Windows Installers

Pre-compiled Windows Installer (.msi) packages containing the Microsoft-attested NDIS 6 Lightweight Filter driver, C/C++ headers, dynamic runtime libraries, and administrative tools.

Windows ARM64

AArch64 • 64-bit ARM
Supported OS: Windows 11 & 10 on ARM
Driver Type: NDIS 6.x Lightweight Filter (LWF)
Driver Signing: Microsoft Signed
Package: Windows.Packet.Filter.3.6.2.1.ARM64.msi

Windows x86

IA-32 • 32-bit
Supported OS: Windows 10, 8.1, 8, 7, Vista, Server (32-bit)
Driver Type: NDIS 6.x Lightweight Filter (LWF)
Driver Signing: Microsoft Signed
Package: Windows.Packet.Filter.3.6.2.1.x86.msi
Package Contents: Each MSI installer installs the kernel driver (ndisrd.sys), user-mode C/C++ header (ndisapi.h), static link library (ndisapi.lib), dynamic library (ndisapi.dll), and driver registration helper tools into %ProgramFiles%\NT Kernel Resources\Windows Packet Filter.

SDKs & Language Bindings

Develop packet filtering applications in your language of choice. Open-source libraries provide idiomatic APIs over the native NDISAPI interface.

C / C++

Native C/C++ SDK

Official native user-mode library (ndisapi.dll) and C/C++ interface headers. Direct, zero-overhead memory and fast I/O control for performance-critical systems.

  • High-speed shared-memory buffer support
  • Full static and dynamic linking options
  • Includes CLI diagnostic and capture tools
C# / .NET

.NET Managed Wrapper

Idiomatic object-oriented wrapper over the NDISAPI dynamic library. Build packet filtering and inspection applications targeting modern .NET and .NET Framework.

  • Safe managed abstractions over native structures
  • Compatible with .NET Core, .NET 6/7/8/9 & Framework
  • Event-driven packet capture models
Rust

Rust Crate (ndisapi-rs)

Safe, idiomatic Rust bindings published on crates.io. Leverages Rust's memory safety guarantees to build robust network inspection tools and firewalls.

  • Type-safe packet buffers and filter tables
  • Integrated with standard Rust build workflows
  • Published on crates.io with online documentation
Go

Go Library (ndisapi-go)

Idiomatic Go package providing high-performance user-mode interaction with WinpkFilter via direct Windows syscalls without cgo overhead.

  • Cgo-free direct syscall IOCTL communication
  • Multi-adapter capture, filtering, and raw injection
  • Published on pkg.go.dev with standard Go toolchain

Ready-to-Build Example Projects

Explore working examples demonstrating packet capture, dynamic content modification, frame injection, and custom firewall implementations.

PassThrough

Demonstrates transparent bidirectional packet forwarding and inline inspection between network adapter and TCP/IP stack.

Filter

Demonstrates packet inspection, protocol parsing, and programmatic rule-based packet drop or forward decisions.

Redirect

Demonstrates real-time frame manipulation, MAC/IP header rewriting, and redirecting packets to alternate adapters.

Capture

Packet capture and logging to disk in standard libpcap/tcpdump compatible format using Fast I/O.

Evaluation Terms & MTU Limit

Free Evaluation & Commercial Licensing

The downloadable installers above are free of charge for non-commercial personal use, educational instruction, and commercial evaluation.

Standard MTU Limitation: Public evaluation builds enforce a maximum transmission unit (MTU) of 1,500 bytes (standard Ethernet frame). Commercial licensed builds support jumbo frames up to 9,000 bytes and provide custom driver naming to avoid coexistence collisions with third-party software.

Legacy Windows Support (v3.2.x Line)

Historical Compatibility

For legacy industrial systems, embedded devices, or virtualized environments running Windows XP, Windows Server 2003, or requiring Visual C++ 6.0 runtime compatibility, historical builds from the v3.2.x release line (NDIS 5.1 Intermediate Driver architecture) remain archived on GitHub.