domain: windows
984 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| BnuuySolutions/OculusKiller A Windows utility that kills the Oculus Dash process and auto-launches SteamVR when an Oculus headset is worn, effectively turning it into … | 10 | 1447 | maintenance |
| Oliviaophia/SmartTaskbar SmartTaskbar is a lightweight Windows utility written in C# that automatically switches the Windows Taskbar between show and auto-hide stat… | 23 | 1445 | maintenance |
| Invoke-IR/PowerForensics PowerForensics is a PowerShell module built on a C# class library that provides an all-in-one framework for live disk forensic analysis. It… | 23 | 1442 | maintenance |
| sysprogs/WinCDEmu WinCDEmu is an open-source Windows utility that mounts optical disc images (ISO, BIN/CCD, MDS/MDF, NRG) as virtual CD/DVD/Blu-ray drives vi… | 23 | 1431 | maintenance |
| 0xnobody/vmpdump VMPDump is a dynamic dumper and import fixer for binaries protected with VMProtect 3.x (x64), built on the VTIL intermediate language. It s… | 23 | 1412 | maintenance |
| Windows-XAML/Template10 Template10 is a C# library of templates and helpers for building Windows 10 UWP XAML applications, providing application startup, navigatio… | 23 | 1397 | maintenance |
| NytroRST/NetRipper NetRipper is a Windows post-exploitation tool that uses API hooking to intercept network traffic, capturing both plain-text and encrypted d… | 32 | 1390 | maintenance |
| rprichard/winpty winpty is a Windows software package providing a Unix pty-master-like interface for communicating with Windows console programs. It include… | 23 | 1383 | maintenance |
| Freaky/Compactor Compactor is a free, open-source GUI utility that exposes Windows 10's built-in filesystem compression (normally only accessible via compac… | 23 | 1381 | maintenance |
| bitsadmin/fakelogonscreen FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active … | 23 | 1378 | maintenance |
| LuckyHookin/edge-TTS-record A Windows desktop tool that records Microsoft Edge's online neural text-to-speech voices (e.g., Xiaoxiao, Yunyang) and saves the output as … | 23 | 1370 | maintenance |
| uberhalit/EldenRingFpsUnlockAndMore A small C# utility that patches Elden Ring's memory at runtime to remove the frame rate cap, adjust FOV, add widescreen support, and apply … | 23 | 1368 | maintenance |
| akavel/rsrc rsrc is a Go CLI tool that generates .syso (COFF) files embedding .ico icons and Windows manifest resources, which the Go linker automatica… | 23 | 1367 | maintenance |
| microsoft/FFmpegInterop A Microsoft open-source library and code sample that integrates FFmpeg into Windows 10/8.1/Phone 8.1 applications via a MediaStreamSource f… | 75 | 1366 | maintenance |
| Terminals-Origin/Terminals Terminals is a secure, multi-tab remote desktop and terminal services client for Windows that supports RDP, VNC, VMRC, SSH, Telnet, ICA Cit… | 56 | 1365 | maintenance |
| ysc3839/FontMod FontMod is a Windows DLL hooking tool that changes the fonts used by Win32 programs, including GDI, GDI+, and Qt-based applications. It wor… | 23 | 1355 | maintenance |
| ReversecLabs/SharpGPOAbuse SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by … | 32 | 1353 | maintenance |
| blackberry/pe_tree PE Tree is a Python module and standalone GUI application for viewing Portable Executable (PE) files in a tree-view, built on pefile and Py… | 10 | 1343 | maintenance |
| csutorasa/XOutput XOutput is a Windows application that converts DirectInput game controller input into XInput, emulating an Xbox 360 controller so older or … | 10 | 1340 | maintenance |
| OmerYa/Invisi-Shell Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS… | 32 | 1339 | maintenance |
| Arvanaghi/SessionGopher SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu… | 32 | 1334 | maintenance |
| GhostPack/SafetyKatz SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps … | 32 | 1332 | maintenance |
| tyranid/DotNetToJScript A C# command-line tool that generates JScript (or VBScript/VBA/scriptlet) files which bootstrap and load a .NET assembly entirely from memo… | 23 | 1332 | maintenance |
| myzxcg/RealBlindingEDR A Windows offensive security tool that uses arbitrary kernel read/write via a signed driver to remove AV/EDR kernel callbacks (ObRegisterCa… | 18 | 1324 | maintenance |
| OpenCover/opencover OpenCover is a code coverage tool for .NET 2 and above on Windows, supporting 32 and 64-bit processes with both branch and sequence point c… | 10 | 1324 | maintenance |
| malxau/yori Yori is a CMD replacement shell for Windows that adds backquotes, job control, and improved tab completion, file matching, aliases, and com… | 66 | 1316 | maintenance |
| 0xrawsec/whids WHIDS is an open-source Endpoint Detection and Response (EDR) tool for Windows, built on the Gene detection engine to match Sysmon/ETW even… | 23 | 1311 | maintenance |
| xmichelo/Beeftext Beeftext is a free, open-source text snippet expansion tool for Windows, written in C++ with Qt. It lets users define keyword-to-snippet co… | 23 | 1309 | maintenance |
| mandiant/ThreatPursuit-VM ThreatPursuit-VM is an open-source Windows-based virtual machine distribution from Mandiant preloaded with tools for threat intelligence an… | 10 | 1306 | maintenance |
| wbenny/injdrv A proof-of-concept Windows kernel driver that injects DLLs into user-mode processes using Asynchronous Procedure Calls (APC). It hooks into… | 32 | 1296 | maintenance |
| med0x2e/SigFlip SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb… | 32 | 1290 | maintenance |
| 99natmar99/Windows-11-Fixer Windows 11 Fixer is a C# desktop application that provides a single GUI for customizing Windows 11, adjusting system and privacy settings, … | 23 | 1272 | maintenance |
| witalihirsch/qBitTorrent-fluent-theme A Fluent Design theme (dark and light variants) for the qBitTorrent torrent client, styled after Windows 11's WinUI look with optional Mica… | 23 | 1271 | maintenance |
| lintstar/LSTAR LSTAR is a comprehensive Cobalt Strike post-exploitation Aggressor plugin written in PowerShell and CNA. It consolidates host information g… | 23 | 1266 | maintenance |
| CobaltFusion/DebugViewPP DebugView++ is a Windows application that collects, views, and filters application logs, including OutputDebugString messages, with highlig… | 72 | 1264 | maintenance |
| Cybellum/DoubleAgent DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin… | 32 | 1262 | maintenance |
| adoxa/ansicon ANSICON is a Windows utility that enables ANSI escape sequence processing in console programs, similar to ANSI.SYS for MS-DOS. It works by … | 23 | 1256 | maintenance |
| Kaldaien/FAR FAR (Fix Automata Resolution) is a plugin/mod for the 2017 Steam version of NieR:Automata that fixes fullscreen resolution issues and adds … | 23 | 1244 | maintenance |
| mgeeky/ThreadStackSpoofer A proof-of-concept C++ implementation of thread call stack spoofing, an in-memory evasion technique that hides shellcode references from a … | 23 | 1242 | maintenance |
| cascadium/wsl-windows-toolbar-launcher A Python CLI tool that generates a Windows toolbar menu of Linux GUI applications installed inside WSL, by converting freedesktop .desktop … | 23 | 1235 | maintenance |
| VerySleepy/verysleepy Very Sleepy is a free open-source sampling CPU profiler for Windows with a wxWidgets-based GUI. It can attach to any running native Windows… | 23 | 1233 | maintenance |
| am0nsec/HellsGate The original C implementation of the Hell's Gate technique, which resolves Windows system call numbers at runtime to invoke NT APIs directl… | 32 | 1220 | maintenance |
| nccgroup/redsnarf RedSnarf is a pen-testing/red-teaming tool for retrieving hashes and credentials from Windows workstations, servers, and domain controllers… | 32 | 1216 | maintenance |
| AlexAkulov/putty-color-themes A collection of color themes for the PuTTY terminal emulator, applied via registry files and a JavaScript helper script. It lets users appl… | 32 | 1214 | maintenance |
| Viralmaniar/Powershell-RAT A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre… | 23 | 1207 | maintenance |
| Opticos/GWSL-Source GWSL is an open-source Windows XServer application that automates running graphical Linux apps on Windows 10 via WSL and over SSH. It wraps… | 23 | 1199 | maintenance |
| basildane/WakeOnLAN A Windows GUI and command-line application for sending Wake-on-LAN magic packets to power on remote machines, plus remote shutdown, sleep, … | 23 | 1198 | maintenance |
| hillwoodroc/winetricks-zh A fork of winetricks that adds setup wizards (verb files) for popular Chinese Windows applications like QQ, WeChat, TIM, and NetEase Cloud … | 23 | 1195 | maintenance |
| bats3c/DarkLoadLibrary DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It lo… | 32 | 1188 | maintenance |
| oneclick/rubyinstaller RubyInstaller for Windows build recipes: a collection of Rake recipes that download the MinGW toolchain and compile the Ruby interpreter, i… | 23 | 1184 | maintenance |
| blackrosezy/gui-inspect-tool A collection of Windows GUI inspection utilities such as Inspect.exe, Spy++, UISpy, and AccExplorer bundled in one repository. These tools … | 32 | 1182 | maintenance |
| antonioCoco/RoguePotato RoguePotato is a Windows local privilege escalation tool written in C that elevates from a service account to SYSTEM by abusing the DCOM/NT… | 23 | 1177 | maintenance |
| CCob/SharpBlock SharpBlock is a C# command-line tool that blocks EDR (Endpoint Detection and Response) protection DLLs from executing their entry points in… | 32 | 1171 | maintenance |
| DarkCoderSc/win-brute-logon A Windows command-line proof-of-concept tool that brute-forces local user account passwords without requiring any privileges, exploiting th… | 32 | 1170 | maintenance |
| kirillkovalenko/nssm NSSM (Non-Sucking Service Manager) is a Windows service helper that wraps any application as an NT service and automatically restarts it if… | 32 | 1169 | maintenance |
| susam/uncap Uncap is a tiny Windows utility written in C that maps the Caps Lock key to Escape, or any key to any other key, via command-line arguments… | 23 | 1169 | maintenance |
| master131/ExtremeInjector A Windows GUI tool for injecting DLLs into running processes, supporting multiple injection methods such as manual mapping, thread hijackin… | 23 | 1165 | maintenance |
| Ch0pin/AVIator AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload u… | 10 | 1161 | maintenance |
| cuiliang/ClickShow A Windows utility that displays visual ripple effects on mouse clicks and a position indicator around the cursor, with per-button colors an… | 10 | 1160 | maintenance |
| dotnet/try-convert try-convert is a .NET CLI global tool that converts legacy .NET Framework projects (including WinForms and WPF) to the modern SDK-style pro… | 10 | 1159 | maintenance |
| kkkgo/vlmcsd vlmcsd is a portable open-source KMS emulator written in C that replaces Microsoft's KMS server, bundled with a vlmcs test client. It runs … | 23 | 1156 | maintenance |
| prsyahmi/GpuRamDrive A Windows application that creates a virtual RAM disk backed by GPU memory, built on top of ImDisk's proxy feature. It is a proof-of-concep… | 23 | 1151 | maintenance |
| threatexpress/red-team-scripts A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera… | 32 | 1146 | maintenance |
| FuzzySecurity/Sharp-Suite Sharp-Suite is a collection of C# security tooling samples for Windows threat emulation, including techniques like process command-line spo… | 32 | 1144 | maintenance |
| leechristensen/SpoolSample SpoolSample is a C# proof-of-concept tool that coerces Windows hosts to authenticate to arbitrary machines via the MS-RPRN Print System Rem… | 32 | 1141 | maintenance |
| Keypirinha/Keypirinha Keypirinha is a fast, keyboard-driven launcher for Windows that lets users quickly find and launch applications, files, bookmarks, URLs, se… | 23 | 1136 | maintenance |
| med0x2e/GadgetToJScript GadgetToJScript is a C# tool that generates .NET BinaryFormatter serialized gadget payloads embedded in JS/VBS/VBA/HTA scripts, triggering … | 23 | 1133 | maintenance |
| ClementGre/ThreeFingerDragOnWindows A WinUI 3 Windows application that emulates macOS-style three-finger dragging on Windows Precision touchpads by holding down the left mouse… | 60 | 1130 | maintenance |
| WiX Toolset WiX Toolset v3 builds Windows Installer (MSI) packages and executable bundles from XML source code via a command-line environment. It integ… | 87 | 1128 | maintenance |
| hausec/ADAPE-Script A PowerShell script that automates Active Directory assessment and privilege escalation checks by bundling multiple well-known pentest modu… | 32 | 1125 | maintenance |
| microsoft/Windows-Machine-Learning Microsoft's Windows Machine Learning samples and tools repository, providing a high-performance ONNX inference API powered by ONNX Runtime … | 39 | 1123 | maintenance |
| FailedShack/USBHelperInstaller USBHelperInstaller is a Windows setup utility that installs Wii U USB Helper and USBHelperLauncher, retrieving builds from an archive.org c… | 23 | 1123 | maintenance |
| JoelGMSec/AutoRDPwn AutoRDPwn is a PowerShell post-exploitation framework that automates the RDP Shadow attack on Windows, letting an attacker view or control … | 32 | 1118 | maintenance |
| fossephate/JoyCon-Driver A Windows application that feeds input from Nintendo Switch JoyCons and the Pro Controller into vJoy virtual gamepads, with analog stick su… | 32 | 1117 | maintenance |
| neilpa/cmd-colors-solarized A Solarized color scheme port for the Windows command prompt, covering cmd.exe, PowerShell, and Bash on Ubuntu on Windows. It provides regi… | 32 | 1111 | maintenance |
| calebstewart/CVE-2021-1675 A pure PowerShell proof-of-concept exploit for CVE-2021-1675 (PrintNightmare), a Windows Print Spooler local privilege escalation vulnerabi… | 32 | 1109 | maintenance |
| mohuihui/antispy AntiSpy is a free Windows anti-rootkit and antivirus toolkit that detects, analyzes, and restores kernel modifications and hooks with the h… | 23 | 1109 | maintenance |
| tevora-threat/SharpView SharpView is a C#/.NET port of the PowerView PowerShell script for Active Directory domain enumeration and reconnaissance. It exposes Power… | 32 | 1108 | maintenance |
| Eun/MoveToDesktop A small Windows utility that adds a 'Move to Desktop' option to the window system menu and provides hotkeys (WIN+ALT+Left/Right) for moving… | 10 | 1093 | maintenance |
| vufa/deepin-wine-wechat-arch A packaging project that ports Deepin's WeChat Wine container (com.qq.weixin.deepin) to Arch Linux and derivatives, with custom run scripts… | 23 | 1092 | maintenance |
| gmamaladze/globalmousekeyhook A C# .NET library (NuGet package MouseKeyHook) that taps global keyboard and mouse activity on Windows via Win32 hooks, raising standard .N… | 23 | 1092 | maintenance |
| aguinet/wannakey A C++ tool that recovers the RSA private key prime numbers generated by the WannaCry ransomware from the wcry.exe process memory. It exploi… | 32 | 1091 | maintenance |
| Accenture/Spartacus Spartacus is a Windows toolkit that automates discovery and exploitation of DLL and COM hijacking vulnerabilities by parsing Process Monito… | 10 | 1085 | maintenance |
| dirkjanm/PrivExchange PrivExchange is a set of Python proof-of-concept tools that abuse Exchange Web Services push notifications to relay authentication and esca… | 32 | 1077 | maintenance |
| hui-Zz/RunAny RunAny is a Windows quick-launch tool written in AutoHotkey that lets users start any application with three keystrokes, regardless of wher… | 23 | 1077 | maintenance |
| silverf0x/RpcView RpcView is a free, open-source Windows GUI tool for exploring and decompiling Microsoft RPC (Remote Procedure Call) interfaces present on a… | 23 | 1070 | maintenance |
| ohyicong/decrypt-chrome-passwords A Python script that decrypts Chrome passwords saved locally on a Windows machine, exporting them to a CSV file. It is intended to raise aw… | 58 | 1068 | maintenance |
| 0xbadjuju/Tokenvator Tokenvator is a C# command-line tool for manipulating Windows tokens to elevate privileges, such as stealing a SYSTEM token from a running … | 23 | 1067 | maintenance |
| AHXR/ghost Ghost is a lightweight Remote Access Trojan (RAT) written in C++ that gives an attacker silent remote command-line access to Windows machin… | 23 | 1058 | maintenance |
| Tylemagne/Gopher360 Gopher360 is a free, zero-config Windows application that turns Xbox 360, Xbox One, or DualShock (via XInput emulation) controllers into mo… | 23 | 1058 | maintenance |
| AdamWagner/stackline Stackline is a Hammerspoon-based Lua plugin that adds visual indicators to yabai's window stacking feature on macOS. It shows the position … | 67 | 1055 | maintenance |
| Koalageddon Koalageddon is a Windows utility that unlocks DLC for games on Steam, Epic, Origin, EA Desktop, and Uplay by hooking platform DRM DLLs. It … | 10 | 1055 | maintenance |
| wwh1004/ExtremeDumper A Windows GUI tool for dumping .NET assemblies from running processes, including bypassing anti-dump protections. It can also inject .NET a… | 23 | 1054 | maintenance |
| btbd/access A Windows kernel driver plus DLL wrapper that lets a usermode process perform privileged operations on protected processes without creating… | 32 | 1053 | maintenance |
| valinet/Win11DisableRoundedCorners A small C utility that cold-patches the Windows 11 Desktop Window Manager (uDWM.dll) to disable window rounded corners, and can restore the… | 23 | 1050 | maintenance |
| samratashok/ADModule A backup of the Microsoft-signed ActiveDirectory PowerShell module (DLL and module files) from Server 2016 with RSAT. It allows enumerating… | 32 | 1047 | maintenance |
| MCMrARM/mc-w10-version-launcher A Windows 10 launcher that lets users install and run multiple versions of Minecraft: Windows 10 Edition (Bedrock) side-by-side. It require… | 80 | 1046 | maintenance |
| xenolightning/AudioSwitcher_v1 Audio Switcher is a Windows application for quickly switching between audio playback and recording devices, built on WASAPI/MMDevAPI. This … | 23 | 1046 | maintenance |
| 9176324/Shark Shark is a Windows kernel driver project written in C that disables Kernel Patch Protection (PatchGuard) in real time on Windows 7 (7600) a… | 23 | 1042 | maintenance |
| LionelJouin/PiP-Tool A Windows desktop application that enables Picture-in-Picture mode by capturing a selected region of any window and displaying it in an alw… | 23 | 1038 | maintenance |