domain: windows
984 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| DarthTon/Xenos Xenos is a Windows DLL injector built on the Blackbone library, supporting x86/x64 processes, manual image mapping, managed image injection… | 23 | 2645 | maintenance |
| steveloughran/winutils Windows native binaries (winutils.exe and Hadoop DLLs) for various Hadoop versions, built from the same git commits as official ASF release… | 23 | 2639 | maintenance |
| ParrotSec/mimikatz mimikatz is a well-known Windows security tool that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memory, and suppo… | 32 | 2630 | maintenance |
| lework/RedisDesktopManager-Windows Windows x64 builds of the open-source RedisDesktopManager (RDM) Redis GUI, compiled from the upstream uglide/RedisDesktopManager project. I… | 23 | 2625 | maintenance |
| google/omaha Omaha is the open-source version of Google Update, a Windows program that installs requested software and keeps it up to date via backgroun… | 10 | 2620 | maintenance |
| CEF Detector A Windows desktop application (built with Electron) that scans your computer using Everything IPC to detect how many copies of CEF (Chromiu… | 22 | 2593 | maintenance |
| microsoft/DirectML DirectML is a high-performance, hardware-accelerated DirectX 12 library for machine learning that provides GPU acceleration across DirectX … | 58 | 2580 | maintenance |
| ArcadeRenegade/SidebarDiagnostics A Windows desktop sidebar application that displays real-time hardware diagnostic information such as CPU, RAM, GPU, network, and drive met… | 23 | 2564 | maintenance |
| LazoVelko/Windows-Hacks A Windows application showcasing creative and unusual manipulations of other windows via the Windows API, written in C#. It includes tricks… | 32 | 2540 | maintenance |
| felixrieseberg/npm-windows-upgrade A small command-line tool that automates upgrading npm on Windows, handling the manual PowerShell/CMD path steps normally required. It list… | 10 | 2504 | maintenance |
| timsutton/brigadier A Python CLI tool that fetches Apple's Boot Camp ESD driver packages for a specific Mac model and unpacks the nested archives, optionally r… | 23 | 2429 | maintenance |
| OneGet/oneget PackageManagement (OneGet) is Microsoft's package manager for Windows, shipped as a PowerShell module that unifies software installation th… | 23 | 2380 | maintenance |
| koush/UniversalAdbDriver A single Windows driver package that supports the Android Debug Bridge (ADB) and fastboot interfaces for most Android phones. It is distrib… | 32 | 2318 | maintenance |
| eliboa/TegraRcmGUI A Windows-only C++ GUI for TegraRcmSmash that injects payloads into Nintendo Switch consoles via the Fusée Gelée RCM exploit. It also suppo… | 23 | 2293 | maintenance |
| cdarlint/winutils A repository of precompiled Windows binaries (winutils.exe, hadoop.dll, hdfs.dll) needed to run Hadoop natively on Windows. It continues th… | 32 | 2287 | maintenance |
| itm4n/PrintSpoofer PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from… | 10 | 2268 | maintenance |
| topotam/PetitPotam PetitPotam is a proof-of-concept tool that coerces Windows hosts to authenticate to attacker-controlled machines via the MS-EFSRPC protocol… | 32 | 2267 | maintenance |
| worawit/MS17-010 A collection of Python exploit scripts and proof-of-concepts for the MS17-010 Windows SMB vulnerabilities, including Eternalblue, Eternalch… | 32 | 2260 | maintenance |
| imDema/FreeMove A Windows GUI utility that moves directories to another drive and creates an NTFS junction/symbolic link at the old location so programs an… | 23 | 2244 | maintenance |
| M2TeamArchived/NSudo NSudo is a Windows system administration toolkit whose launcher lets users run programs with TrustedInstaller, SYSTEM, or elevated user tok… | 10 | 2206 | maintenance |
| axstin/rbxfpsunlocker A Windows utility that removes Roblox's 60 FPS cap by modifying running Roblox processes, allowing higher framerates on capable hardware. I… | 10 | 2195 | maintenance |
| SystemRage/py-kms py-kms is a Python-based KMS (Key Management Service) server emulator that responds to v4, v5, and v6 KMS requests to activate volume-licen… | 32 | 2190 | maintenance |
| dafthack/DomainPasswordSpray DomainPasswordSpray is a PowerShell tool that performs password spray attacks against domain user accounts, automatically generating a user… | 32 | 2082 | maintenance |
| gurnec/HashCheck HashCheck is a Windows Explorer shell extension that lets users verify and generate file checksums (MD5, SHA-1, SHA-2, SHA-3, and more) dir… | 23 | 2079 | maintenance |
| JKornev/hidden A Windows kernel driver with a usermode library and CLI that can hide processes, files, directories, and registry keys, and protect process… | 23 | 2051 | maintenance |
| es3n1n/no-defender A Windows CLI tool that disables Windows Defender and the firewall by registering a fake antivirus through the undocumented Windows Securit… | 10 | 2038 | maintenance |
| zetaloop/ExplorerPatcher A Simplified Chinese localized fork of ExplorerPatcher, a Windows utility that restores efficient working environments on Windows 11. It le… | 10 | 2031 | maintenance |
| Pulover/PuloversMacroCreator Pulover's Macro Creator is a free Windows automation tool and script generator built on AutoHotkey, featuring a built-in recorder for keyst… | 23 | 2017 | maintenance |
| cube0x0/CVE-2021-1675 A proof-of-concept exploit tool implementing the PrintNightmare vulnerabilities (CVE-2021-1675/CVE-2021-34527) in both C# and Python (Impac… | 32 | 1999 | maintenance |
| Codeusa/SteamCleaner Steam Cleaner is a Windows PC utility that removes leftover cache and data from game clients like Steam, Origin, Uplay, Battle.net, GoG, an… | 10 | 1999 | maintenance |
| 411Hall/JAWS JAWS is a PowerShell enumeration script that helps penetration testers and CTF players quickly identify potential Windows privilege escalat… | 32 | 1993 | maintenance |
| oblitum/Interception A Windows kernel driver and C library providing an API to intercept and control keyboard, mouse, and other input devices programmatically. … | 23 | 1967 | maintenance |
| docker/for-win Docker Desktop for Windows is an application that provides an integrated Docker container experience on Microsoft Windows, including the Do… | 63 | 1947 | maintenance |
| zsh2401/AutumnBox AutumnBox is a free, graphical Windows application that wraps the Android Debug Bridge (ADB) command-line tool in a WPF-based GUI. It lets … | 10 | 1933 | maintenance |
| sense-of-security/ADRecon ADRecon is a PowerShell-based tool that extracts a wide range of artefacts from an Active Directory environment, including users, groups, t… | 32 | 1929 | maintenance |
| builtbybel/bloatbox Bloatbox is a small standalone Windows Forms application for uninstalling pre-installed Windows 10 UWP apps (bloatware). It also supports a… | 23 | 1888 | maintenance |
| Alia5/GlosSI GlosSI (formerly GloSC) is a Windows tool that applies Steam-Input controller rebinding system-wide and provides a global borderless-window… | 10 | 1887 | maintenance |
| LAB02-Research/HASS.Agent HASS.Agent is a Windows-based companion client application for Home Assistant, built in .NET 6. It integrates a Windows PC with a Home Assi… | 23 | 1885 | maintenance |
| microsoft/windows-dev-box-setup-scripts A collection of PowerShell recipe scripts from Microsoft that automate setting up a Windows developer machine using Boxstarter and Chocolat… | 32 | 1872 | maintenance |
| Abdelrhman-AK/WinPaletter WinPaletter is a portable Windows application for deeply customizing the appearance of Windows 7 through 11, including colors, visual style… | 93 | 1865 | maintenance |
| glmcdona/Process-Dump Process Dump is a Windows command-line reverse-engineering tool that dumps unpacked malware PE files and loose code chunks from process mem… | 23 | 1852 | maintenance |
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1844 | maintenance |
| CCob/SweetPotato SweetPotato is a C# command-line tool that collects multiple native Windows privilege escalation techniques (RottenPotato, PrintSpoofer, Ef… | 32 | 1839 | maintenance |
| p3nt4/PowerShdll PowerShdll is a C# tool that runs PowerShell commands and scripts without invoking powershell.exe, by loading PowerShell automation DLLs vi… | 23 | 1831 | maintenance |
| SysWhispers SysWhispers is a Python CLI tool that generates header and assembly files for making direct system calls on Windows, bypassing user-mode AP… | 32 | 1828 | maintenance |
| klezVirus/inceptor Inceptor is a template-driven PE packer and AV/EDR evasion framework for Windows, aimed at penetration testers and red teamers. It automate… | 32 | 1817 | maintenance |
| ljc545w/ComWeChatRobot A PC WeChat robot implemented in C++ that reverse-engineers the Windows WeChat client to expose contacts, messaging, group management, and … | 10 | 1816 | maintenance |
| hlldz/Phant0m Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so… | 10 | 1812 | maintenance |
| cyd01/KiTTY KiTTY is a free Windows-only telnet and SSH client forked from PuTTY 0.76, adding features like session filters, automatic logon scripts, p… | 23 | 1811 | maintenance |
| Kevin-Robertson/Invoke-TheHash A collection of PowerShell functions for performing pass-the-hash attacks over WMI and SMB using NTLM hash authentication. It implements ra… | 32 | 1803 | maintenance |
| lextm/windowsterminal-shell A set of PowerShell scripts that install and uninstall Windows Explorer context menu items for launching Windows Terminal. It supports mult… | 32 | 1778 | maintenance |
| emoose/DLSSTweaks A tweak DLL that lets users customize NVIDIA DLSS behavior in games, such as forcing DLAA, adjusting scaling ratios, changing DLSS presets,… | 60 | 1768 | maintenance |
| knownsec/shellcodeloader A Windows shellcode loader generator written in C++ that packages raw shellcode into encrypted executables with multiple loading techniques… | 23 | 1747 | maintenance |
| nodists/nodist Nodist is a Node.js and npm version manager for Windows, inspired by the 'n' version manager. It lets users install, switch, and manage mul… | 23 | 1728 | maintenance |
| dege-diosg/dgVoodoo2 dgVoodoo2 is a wrapper library that translates legacy Glide and DirectX graphics APIs (DirectDraw, D3D1-9) onto modern D3D11/12, letting ol… | 90 | 1712 | maintenance |
| YuHuanTin/IDM_Cracker An archived mirror of a crack/patch tool for Internet Download Manager (IDM), originally released by Ali.Dbg and re-hosted by YuHuanTin. It… | 76 | 1707 | maintenance |
| dylanbai8/kmspro A one-click bash script for deploying a self-hosted KMS (Key Management Service) activation server on Linux, Windows, or Android, based on … | 32 | 1690 | maintenance |
| eladshamir/Internal-Monologue A C# post-exploitation tool that retrieves NTLM hashes by inducing NetNTLM challenge-response computations in-process, without touching the… | 32 | 1681 | maintenance |
| shayne/go-wsl2-host A Go program that installs as a Windows service and automatically updates the Windows hosts file with the WSL2 VM's IP address. It maps dis… | 23 | 1680 | maintenance |
| rasta-mouse/Watson Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti… | 10 | 1680 | maintenance |
| kellwinr/galaxybook_mask A Windows batch script that modifies the registry to make a non-Samsung PC appear as a Galaxy Book laptop, bypassing Samsung's device restr… | 10 | 1670 | maintenance |
| taviso/ctftool An interactive command-line tool for exploring the CTF (Clipboard/Text Services Framework) protocol used by Windows Text Services. It suppo… | 23 | 1667 | maintenance |
| google/UIforETW UIforETW is a Windows GUI application for recording and managing ETW (Event Tracing for Windows) traces, making deep performance investigat… | 10 | 1663 | maintenance |
| davehull/Kansa Kansa is a modular incident response framework written in PowerShell that uses PowerShell Remoting to run data-collection modules across ma… | 23 | 1661 | maintenance |
| Dec0ne/KrbRelayUp KrbRelayUp is a C# command-line tool that wraps Rubeus and KrbRelay to automate a Kerberos relay-based local privilege escalation in Window… | 32 | 1657 | maintenance |
| Mr-Un1k0d3r/SCShell SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via Chang… | 32 | 1655 | maintenance |
| 25H/Maya Maye is a small, lightweight quick-launcher for Windows that lets users launch files and shortcuts via drag-and-drop, hotkeys, and a search… | 69 | 1651 | maintenance |
| Paliverse/DualSenseX DualSenseX (DSX) is a Windows application that lets users connect a PS5 DualSense controller to their PC with support for Adaptive Triggers… | 55 | 1630 | maintenance |
| stefansundin/altdrag AltDrag is a small Windows utility that lets you move and resize windows by holding the Alt key and dragging with the mouse, replicating be… | 23 | 1625 | maintenance |
| nccgroup/Winpayloads Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag… | 32 | 1616 | maintenance |
| yingDev/WGestures WGestures is a free, open-source global mouse gesture utility for Windows 7/8/10, written in C#. It lets users perform common actions (web … | 23 | 1614 | maintenance |
| glucyzz/IDM A repackaged distribution of Internet Download Manager (IDM) 6.41.2 with license activation bypassed, distributed as a pre-cracked installe… | 44 | 1613 | maintenance |
| DavidXanatos/wumgr WuMgr is an open-source .NET tool for managing Windows updates on Windows 10, using the Windows Update Agent API to identify, download, and… | 23 | 1610 | maintenance |
| outflanknl/Dumpert Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR… | 32 | 1595 | maintenance |
| ChrisAnd1998/TaskbarXI TaskbarXI is a C++ application that modifies the Windows 11 taskbar, primarily turning it into a macOS-style dock. It supports multiple mon… | 10 | 1595 | maintenance |
| DeEpinGh0st/Erebus Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering… | 23 | 1568 | maintenance |
| ysc3839/AudioPlaybackConnector An open-source Windows application that manages Bluetooth A2DP Sink connections, letting other devices play audio through a Windows 10 2004… | 23 | 1568 | maintenance |
| cinit/WSAPatch A C++ patch that enables Windows Subsystem for Android (WSA) to run on Windows 10 instead of requiring Windows 11. It works by patching icu… | 22 | 1563 | maintenance |
| Mr-Un1k0d3r/PowerLessShell PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s… | 66 | 1559 | maintenance |
| Cn33liz/p0wnedShell p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r… | 32 | 1550 | maintenance |
| cinience/RedisStudio RedisStudio is a native Windows GUI client for managing and browsing Redis databases, built on hiredis and the duilib UI library. It suppor… | 36 | 1545 | maintenance |
| EpicGames/raddebugger The RAD Debugger is a native, user-mode, multi-process graphical debugger for Windows x64, currently in alpha, developed by Epic Games. It … | 93 | 7437 | experimental |
| mandiant/SharPersist SharPersist is a Windows persistence toolkit written in C# that can add, remove, check, and list various persistence techniques such as reg… | 10 | 1542 | maintenance |
| GhostPack/SharpUp SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat… | 32 | 1531 | maintenance |
| HerMajestyDrMona/Windows11DragAndDropToTaskbarFix A small C++ Windows utility that restores drag-and-drop-to-taskbar functionality missing in early Windows 11 builds by simulating Win+T and… | 23 | 1528 | maintenance |
| Yaxser/Backstab Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process… | 23 | 1527 | maintenance |
| coofcookie/Windows11Upgrade A free open-source Windows application that upgrades eligible and ineligible PCs to Windows 11 by bypassing Microsoft's hardware requiremen… | 23 | 1523 | maintenance |
| gentilkiwi/kekeo kekeo is a C-based command-line toolbox for manipulating Microsoft Kerberos, from the author of mimikatz. It supports operations like ticke… | 23 | 1521 | maintenance |
| SuperStudio/SuperCom SuperCom is a polished Windows serial port debugging tool for capturing, storing, and visualizing serial port logs. It supports monitoring … | 81 | 1512 | maintenance |
| pentestmonkey/windows-privesc-check A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv… | 32 | 1500 | maintenance |
| Kevin-Robertson/Powermad Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS… | 32 | 1500 | maintenance |
| optiv/Freeze Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su… | 10 | 1476 | maintenance |
| benbuck/rbtray RBTray is a small Windows background utility that lets you minimize any window to the system tray by right-clicking its minimize button, sh… | 28 | 1475 | maintenance |
| matterpreter/OffensiveCSharp A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S… | 32 | 1473 | maintenance |
| 0x09AL/RdpThief RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text… | 32 | 1469 | maintenance |
| antonioCoco/RemotePotato0 RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile… | 23 | 1469 | maintenance |
| rootclay/WMIHACKER WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44… | 33 | 1465 | maintenance |
| henkman/virgo A tiny virtual desktop manager for Windows written in C, providing four virtual desktops switchable via hotkeys. It runs as a lightweight t… | 23 | 1463 | maintenance |
| Jonno12345/TileIconifier A Windows utility that creates Start Menu tiles for Windows 8.1 and 10 applications by modifying shortcuts and extracting icons from EXE/DL… | 23 | 1457 | maintenance |
| QAX-A-Team/BrowserGhost BrowserGhost is a C# command-line tool for red team operators that extracts saved browser credentials, cookies, history, and bookmarks from… | 23 | 1452 | maintenance |