An L4 reverse proxy with protocol multiplexer, written in Rust
-
Updated
Sep 23, 2026 - Rust
An L4 reverse proxy with protocol multiplexer, written in Rust
为CDN全面开启ECH的DoH服务,基于Cloudflare Workers,适用于Cloudflare CDN / Meta CDN
Encrypted Client Hello with Split Mode Topology; +ECH Resolver, Dialer, RoundTripper, Publisher
Encrypted Client Hello (ECH) config parser and generator.
Multi-listener SNI/Host-routing TLS gateway: dynamic per-SNI certificate issuance on termination, with ECH / TLS / HTTP / raw upstreams.
A tool that runs configurable ECH handshakes without relying on HTTPS RRs.
Discreet end-to-end encrypted handoff for files, messages, and Git, via dead drops or paired devices, with Cloudflare or self-hosted backends.
Discreet HTTPS and WebSocket proxy over an ECH-protected WSS relay, preserving end-to-end application TLS.
ECH (Encrypted Client Hello) compliance scanner — test RFC 9849 deployment
⚡高性能 Cloudflare CDN 边缘节点延迟评测与优选工具,纯标准库零依赖。| Cloudflare Anycast CDN edge IP latency benchmarking & optimization tool. Pure Python stdlib (zero-dependency), 150-thread concurrency, real TLS/ECH handshake & DoH.
Suricata IDS lab — 23 custom detection rules with MITRE ATT&CK metadata, JA4 fingerprinting, Encrypted Client Hello and post-quantum TLS detection, false-positive tuning, and engine-validated detection-as-code CI.
Linux network monitoring, DNS hardening and intrusion investigation suite — DNS leak auditing, DNSSEC/DoT enforcement, Encrypted Client Hello (ECH-capable curl + every browser), Cloudflare WARP install and control, firewalld and ARP monitoring, Wi-Fi recovery. 18 tools that install their own dependencies. Fedora, Debian, Mint, Manjaro, Asahi
Network threat detection lab — Encrypted Client Hello, post-quantum TLS, JA4 fingerprinting, DNS tunneling, C2 beaconing, AI/MCP egress. Sigma rules, SOC playbooks, and CI-validated detection-as-code.
BoringSSL-linked nginx build tooling with HTTP/3, Encrypted Client Hello and post-quantum key exchange, optimised for AMD Zen 2 - plus annotated TLS hardening and L7 anti-DDoS examples
Passive Measurement of QUIC and ECH at the ISP Edge
Server-side ECH for QUIC — in 2 lines.
Browser-based ECH demo — draft-ietf-tls-esni. TLS 1.3 protects every byte except the hostname it announces first. Real HPKE seals the ClientHelloInner; a network observer sees only the outer. Tamper the ECHConfig and watch the real open fail. Metadata is the leak encryption doesn't close. No backends. No simulated math.
To associate your repository with the encrypted-client-hello topic, visit your repo's landing page and select "manage topics."