WebTunnel uses a reverse proxy architecture. An nginx web server with a valid TLS certificate receives HTTPS connections from Tor clients. The request path includes a random-looking suffix that the nginx configuration recognizes as a WebTunnel path and passes to the WebTunnel server process. The WebTunnel server then hands the connection to the Tor process via ExtORPort.
From the outside, every connection looks like a client accessing a specific URL on a web server with a legitimate domain and certificate. The distinguishing feature - the random path suffix - is not visible in DPI analysis because it is inside the encrypted TLS payload. Active probing that simply connects to the server and follows the TLS handshake cannot distinguish a WebTunnel server from an ordinary HTTPS web application.
The requirement for a real TLS certificate and a registered domain name is the main additional overhead compared to obfs4. Operators need a domain name (any cheap domain works) and a Let's Encrypt certificate. The domain does not need to resolve to anything except the VPS IP, and it does not need to be associated with any real website content.