Engine Surface

This page summarizes the current engine catalog. Availability depends on platform, runtime assets, saved configuration, and local permissions.

Windows engine catalog

EngineTypeNotes
sniDPI bypass stackWindows-only native DLL-backed SNI path with local XRay listeners.
xrayProxy coreSupports current Windows XRay runtime behavior, including client-side REALITY handling.
gdpiTCP handlinglegacy is the stable default; native is experimental.
psiphonVPN/proxy clientCurrent runtime is backed by blackout_warp.dll.
warpVPN/proxy clientCurrent runtime is backed by blackout_warp.dll.
tunSystem tunnelRequires admin rights on Windows.
torProxy clientUses a supplied Tor runtime.
mhrvHTTP relayEmbedded HTTP relay; HTTPS CONNECT is intentionally unsupported.
ikev2, wireguard, openvpn, softetherVPN pathsDepend on their respective runtime/setup requirements.
appsscriptHTTP relayHTTP relay path only.
hysteria2, tuicQUIC proxyRun through the native sing-box-backed proxy engine path.
legendComposite targetConnect/start target that is separate from the legend security mode name.

Linux engine catalog

EngineSupported?Notes
xrayYesUses the managed blackout-engine runtime.
tunYesRequires root and Linux networking prerequisites.
hysteria2YesManaged runtime path through blackout-engine.
tuicYesManaged runtime path through blackout-engine.
Everything elseNoWindows-only or otherwise unsupported on Linux.

Read the capability matrix

Run blackout demo for a safe simulation or blackout capabilities for the full catalog with local state.

Ready means local prerequisites passed. Blocked means a local runtime, setting, permission, port, or compatible saved configuration is missing. Unsupported means this platform has no shipped runtime path. A cataloged target remains visible even when it is unsupported here.

Automatic GitHub release downloads are staged and require matching SHA-256 metadata before promotion. Manual or user-supplied runtimes are labeled unverified and are the user's responsibility.

Golden path

blackout demoblackout doctor --local-onlyblackout capabilitiesblackout routeblackout setupblackout ready <engine>blackout connect

The guided setup is read-only in JSON and non-interactive modes. When Blackout Kit changes a local system proxy, it records ownership and restores or clears it only while the current proxy still matches the recorded target.

Boundary reminder

Engine availability does not prove that the selected upstream server or filtered network will work. Blackout Kit distinguishes local readiness from remote success.