Open-source project
SpaceTimee/Sheas-Cealer avatar
SpaceTimee/Sheas-Cealer

Sheas Cealer: A Windows WPF Tool That Fakes SNI to Resist Network Eavesdropping

Just Ceal It (可用于无代理合法抵御网络监听和开展网络研究)

5,158 stars604 forksC#License varies

At a glance

What is it?
Sheas Cealer is a .NET 8 WPF desktop application for Windows that forges the SNI extension in Chromium-based browsers. It is aimed at users who want to study or resist network interception, and it is still described by its author as being in development.
Who is it for?
Adopt Sheas Cealer if you are on Windows 10 or later, you already understand what SNI is, and your goal is legal resistance to network eavesdropping or network security research; the author states the project is still in development, so treat it as a research tool rather than infrastructure.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 127 days ago.
What is it written in?
Mainly C#, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Sheas Cealer actually does, and who it is written for

Sheas Cealer is a desktop SNI forgery tool built on WPF and .NET 8. The problem it addresses is specific: when a client opens a TLS connection, the SNI extension in the handshake carries the hostname in cleartext, and anything sitting on the path can read it. Sheas Cealer changes what that field contains for Chromium-based browsers, which is the layer where a network observer would otherwise see the real destination.

The audience is narrow and the README is explicit about it. The project and, in the author's words, all related resources are intended only for resisting illegal network monitoring and for conducting network security research. The README also states that the project does not intend to circumvent any country's censorship apparatus. That framing matters: this is not marketed as a general-purpose circumvention client, and the user agreement and privacy policy are linked near the top of the README rather than buried at the bottom.

Platform support is Windows only. The README says Windows 10 or later, and directs users on earlier Windows versions to release 1.1.0. For other platforms it points to related projects rather than claiming portability. The primary language of the repository is C#, and the layout is a conventional WPF solution: App.xaml and App.xaml.cs at the root, with Pages, Models, Utils, Convs, Exts, Valids and Wins folders alongside a single Sheas-Cealer.sln.

The mechanism: Chromium launch parameters, not a proxy

The README describes the principle in one line: it uses a launch parameter feature of the Chromium core to forge the SNI extension marker, and it links to an external article for the detailed explanation, crediting kit for the underlying principle and NiceBowl for the write-up. What is visible from the repository itself is that the tool is a launcher and configuration layer, not a packet filter. It does not sit in the network stack, it does not terminate TLS, and it does not run a local proxy on a port that other applications can point at. It starts a Chromium-based browser with arguments that alter the handshake.

That design has consequences worth naming. Because the mechanism lives in the browser's startup parameters, the scope of protection is the browser instance Sheas Cealer launches. Other applications on the same machine that open their own TLS connections are not covered by this path. The README does mention companion projects that extend the idea in other directions, including Sheas Dop for anti-pollution DNS resolution, described as a subproject of global purification, and Sheas Nginx, a Pixiv Nginx launcher described as a collaboration between global forgery and Pixiv Nginx. Those are separate repositories, not features of this one.

The forgery rules themselves are not hardcoded in the application. The README states that the built-in forgery rules are continuously updated in the Cealing Host repository, and that Sheas Cealer does not overwrite existing rules when it updates. Synchronising with upstream requires the user to press an update-upstream-rules button or to modify and overwrite the rules manually. That is a deliberate trade-off: user edits survive upgrades, but the tool will not silently pull in new rules for you.

Installing Sheas Cealer on Windows and launching a first session

The README gives two installation routes and recommends the first. Download Sheas Cealer Setup.exe from the GitHub releases page and run it, then follow the prompts. The alternative is the portable Zip: download Sheas Cealer Zip.zip, extract it, and use it directly without an installer.

There is a third build variant the README warns about. The Scd version bundles the .NET runtime, so it runs on machines that lack a .NET runtime, at the cost of a larger file size and worse cross-platform capability. The README says not to use it without a specific reason. There is no package manager command in the README, so installation is a download from GitHub releases:

bash
# No package manager step is documented.
# Download Sheas Cealer Setup.exe from the GitHub releases page and run it,
# or download Sheas Cealer Zip.zip and extract it.

After installation, the first useful action is to check which forgery rules you have and update them if needed. The README notes that updates do not overwrite existing rules, so the sync step is a button labelled for updating upstream rules, or a manual edit. The README does not document the exact command-line arguments Sheas Cealer passes to the browser, so the launch parameters themselves are not reproducible from the README alone; the linked article is where the author directs readers for the principle.

For documentation beyond the README, the project points to Sheas Cealer Docs at docs.spacetimee.xyz, covering terminology, usage and project build instructions. The README also notes that the GitHub Wiki is open for collaborative documentation editing. If you want to build from source, the repository root contains Sheas-Cealer.sln and Sheas-Cealer.csproj, which is the standard entry point for a .NET solution, though the README does not spell out the build commands.

Where the design breaks down

The most concrete limitation is stated by the author rather than discovered by users: Sheas Cealer is still in development, though the README says each formal release will try to ensure it is stable and usable. That sentence is a promise about release hygiene, not a claim of maturity, and it should be read as one.

The second limitation is scope. Because the forgery is applied through Chromium launch parameters, anything outside that browser process is unaffected. If your threat model includes native applications, command-line tools, package managers or another browser engine, this tool does not address them. The related-projects list suggests the author is aware of the gap and has spun off separate efforts rather than widening this one.

The third is version drift. The most recent release listed is 1.1.5-alpha from 2024-12-30, with 1.1.4 from 2024-12-22 and 1.1.3 from 2024-10-21 before that. The repository's last push was on 2026-05-26, so work has continued after the latest tagged release, but the release channel itself has not produced a newer tag in the project's published history. Anyone planning to depend on the project should look at what is on master rather than assuming the release page reflects current state.

The fourth is the rules pipeline. Since the application does not overwrite existing forgery rules on update, a stale local ruleset can persist indefinitely if the user never syncs. That is a failure mode with no error message attached to it.

How it differs from a local proxy or a DNS-based approach

The obvious alternative class is a local proxy such as a TLS-terminating or SNI-rewriting proxy that applications connect to explicitly. The difference in approach is architectural. A proxy sits between the client and the network, so any application configured to use it is covered, and the proxy can inspect and rewrite traffic in both directions. Sheas Cealer does not sit in the path at all. It changes what the browser puts on the wire at the moment of the handshake, which means there is no listening port, no certificate store to manage, and no per-application configuration. The cost is that coverage is limited to what it launches.

A second alternative is DNS-level handling, and the project's own ecosystem shows the split. Sheas Dop is described in the README as a DNS anti-pollution resolution tool and a subproject of global purification. DNS and SNI are different layers: DNS decides which address you reach, while SNI is what an observer reads from the handshake. A tool that fixes resolution does not change the handshake field, and a tool that forges the handshake field does not fix a poisoned resolver. Which one you need depends on which layer your problem is at, and the README's related-projects list treats them as complements rather than substitutes.

For users on platforms other than Windows, the README points to Sheas Cealer Droid for Android and to a nix branch of this repository for the cross-platform desktop build. Those are the alternatives the author himself names, not third-party replacements.

Maintenance, upgrades and what the repository says about licensing

Upgrade cost has two parts. The application itself is upgraded by downloading a new release and running the installer or replacing the extracted Zip, and the README does not document rollback. The rules are upgraded separately, and the README is clear that application updates preserve your existing rules. That means an upgrade does not silently change behaviour, which is good for reproducibility and bad for anyone who assumes they are on current rules.

The release cadence visible from the project's published releases is uneven. Three releases appear between 2024-10-21 and 2024-12-30, the newest being an alpha, and then no further tagged release in the list. Meanwhile the repository's last push was on 2026-05-26, which is more than four months before the date of writing. The project is not archived, but it should not be described as actively developed on the strength of a tag list that stops in December 2024. Check the commit history on master if currency matters to you.

On licensing, the README's licence section contains a FOSSA status badge rather than a named licence, and no SPDX identifier appears in the repository metadata. That is a real gap for anyone who wants to redistribute the binaries or reuse the code. The README also links a privacy policy and a user agreement hosted outside the repository, and asks users to read them before use. Read them; they are the author's stated terms, and nothing here is legal advice.

Editorial conclusion

Adopt Sheas Cealer if you are on Windows 10 or later, you already understand what SNI is, and your goal is legal resistance to network eavesdropping or network security research; the author states the project is still in development, so treat it as a research tool rather than infrastructure. Do not adopt it if you are on macOS or Linux (the README points to Sheas Cealer Nix for the cross-platform desktop build), if you expect a stable, finished product, or if your use case is bypassing state censorship, which the README explicitly says the project does not intend to do. Before relying on it, verify three things: that you have read the user agreement and privacy policy it links to, that your Windows version is 10 or later (older systems are told to use release 1.1.0), and that you understand the update behaviour, where Sheas Cealer will not overwrite your existing forgery rules unless you click the button to update upstream rules or edit them yourself. Note also that the repository does not state a licence in the README, which carries a FOSSA status badge instead, so confirm licensing terms before any redistribution.

Frequently asked questions

What is Sheas Cealer and what does it do?

It is a Windows desktop tool built on WPF and .NET 8 that forges the SNI extension using Chromium launch parameters. The README states it is intended only for resisting illegal network monitoring and for network security research.

How do I install Sheas Cealer on Windows?

Download Sheas Cealer Setup.exe from GitHub releases and run it, or download Sheas Cealer Zip.zip and extract it for a portable install. The README recommends the Setup installer and warns that the Scd version has a larger file size and worse cross-platform capability.

Does Sheas Cealer work on macOS or Linux?

No. The README lists Windows 10 or later as the supported platform and points users on older Windows versions to release 1.1.0. For other platforms it refers to related projects, including Sheas Cealer Droid for Android and a nix branch for the cross-platform desktop build.

Why do my forgery rules not update when Sheas Cealer updates?

This is intentional. The README states that Sheas Cealer does not overwrite existing forgery rules on update, and that syncing with the Cealing Host upstream requires clicking the update upstream rules button or manually modifying and overwriting the rules.

Official sources

  1. Issues
  2. README
  3. Releases
  4. SpaceTimee/Sheas-Cealer on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/spacetimee-sheas-cealer.svg)](https://hysenlabs.com/projects/spacetimee-sheas-cealer)