Ross ROSS = Recommend OSS · open-source software intelligence for agents

Hackplayers/evil-winrm

The ultimate WinRM shell for hacking/pentesting observed · 2026-08-28

github.com/Hackplayers/evil-winrm · Ruby · LGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

79/100

  • Activity 85
  • Release rhythm 60
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 8
  • age_days: 2654
  • days_rel: 269
  • days_push: 92
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

5448 stars · 679 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features like pass-the-hash, Kerberos authentication, in-memory script/assembly loading, AMSI and ETW bypasses, and file upload/download.

Use cases

  • get a remote shell on a Windows box via WinRM during a pentest
  • pass-the-hash authentication to Windows hosts
  • load PowerShell scripts and DLLs in memory to evade AV
  • connect with Kerberos tickets from ccache or kirbi files
  • upload and download files to a compromised Windows machine
  • run post-exploitation commands over PSRP with SSL or certificates

When to choose

  • you are doing authorized penetration testing or red teaming against Windows hosts with WinRM enabled
  • you need pass-the-hash or Kerberos-based remote shell access
  • you want in-memory loading of scripts, DLLs, or assemblies to bypass antivirus
  • you want a lightweight CLI alternative to interactive PowerShell remoting from Linux

When to avoid

  • you need a general-purpose administration tool rather than offensive features
  • unauthorized access - using this against systems without permission is illegal
  • you need a GUI or cross-platform remote management suite
  • the target does not have WinRM/PSRP enabled

Facets

cli-tool · maturity active

security penetration-testing http-client cli security penetration-testing windows windows ruby cli winrm pass-the-hash kerberos psrp post-exploitation powershell-remoting red-team command-line linux macos docker

1 source

Member repositories

RepositoryRoleHealth v2
Hackplayers/evil-winrmmain79

For agents

markdown · JSON · MCP: product_card(name="Hackplayers/evil-winrm")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem