{"adoption": {"forks": 679, "observed_at": "2026-08-28T04:09:18.526982+00:00", "stars": 5448}, "canonical_url": "https://ross.abutalabs.com/products/evil-winrm", "card": {"archived": false, "artifact_type": "cli-tool", "description": "The ultimate WinRM shell for hacking/pentesting", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "penetration-testing", "http-client", "cli"], "health_score": 87, "homepage": null, "language": "Ruby", "license": "LGPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["Hackplayers/evil-winrm"], "name": "Hackplayers/evil-winrm", "platform": ["windows", "ruby", "cli"], "pushed_at": "2026-06-02T15:23:03+00:00", "repo": "Hackplayers/evil-winrm", "stars": 5448, "tags": ["winrm", "pass-the-hash", "kerberos", "psrp", "post-exploitation", "powershell-remoting", "red-team", "command-line", "linux", "macos", "docker"], "topics": ["winrm", "shell", "hacking", "pentest", "ruby", "pentesting", "pentesting-windows", "remote-management", "win-rm", "evil-winrm", "pass-the-hash", "kerberos", "docker", "psrp", "powershell"], "urls": [], "use_cases": ["get a remote shell on a Windows box via WinRM during a pentest", "pass-the-hash authentication to Windows hosts", "load PowerShell scripts and DLLs in memory to evade AV", "connect with Kerberos tickets from ccache or kirbi files", "upload and download files to a compromised Windows machine", "run post-exploitation commands over PSRP with SSL or certificates"], "what_it_is": "Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features like pass-the-hash, Kerberos authentication, in-memory script/assembly loading, AMSI and ETW bypasses, and file upload/download.", "when_to_avoid": ["you need a general-purpose administration tool rather than offensive features", "unauthorized access - using this against systems without permission is illegal", "you need a GUI or cross-platform remote management suite", "the target does not have WinRM/PSRP enabled"], "when_to_choose": ["you are doing authorized penetration testing or red teaming against Windows hosts with WinRM enabled", "you need pass-the-hash or Kerberos-based remote shell access", "you want in-memory loading of scripts, DLLs, or assemblies to bypass antivirus", "you want a lightweight CLI alternative to interactive PowerShell remoting from Linux"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/evil-winrm", "repo": "Hackplayers/evil-winrm", "role": "main", "score": 79}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:09:18.526982+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T17:56:50.236010+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "06d1291aa5695b7342c296f13fa30e19db5be44fcdc20b3503cb32106f81867a", "fetched_at": "2026-08-28T04:09:18.526982+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Hackplayers/evil-winrm"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 85, "longevity": 100, "rhythm": 60}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2654, "days_push": 92, "days_rel": 269, "gap_med": 8, "n_releases_24m": 4}, "score": 79, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}