# nccgroup/Winpayloads

Undetectable Windows Payload Generation

Repository: https://github.com/nccgroup/Winpayloads
Canonical: https://ross.abutalabs.com/products/winpayloads
Language: Python
License: Apache-2.0
License Family: permissive
Topics: python, persistence, kali, payloads, bypass, antivirus, uac, windows, meter, msfconsole, metasploit, powershell, netsec, undetectable
Last push: 2022-11-08T08:14:23+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3981, "days_push": 1394, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1616, forks 327 (observed 2026-08-28T04:05:11.572267+00:00)

## What it is
Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stagers. It integrates with Metasploit and popular PowerShell post-exploitation scripts and is now primarily distributed via Docker.

## Use cases
- generate undetectable windows payloads for penetration testing
- bypass antivirus detection on windows targets
- bypass uac on compromised windows machines
- add persistence to a payload that survives reboot
- invoke powershell payloads in memory with a stager
- spray psexec with stolen hashes across a network
- create custom shellcode payloads for red team engagements

## When to choose
- you are doing authorized penetration testing or red teaming against Windows targets
- you need payload generation with AV evasion, UAC bypass, and persistence in one tool
- you work from Kali Linux and already use Metasploit

## When to avoid
- you need a maintained tool - it runs on deprecated Python 2.7 and development is stale
- you are not authorized to test the target systems - this is offensive tooling
- you need modern evasion against current EDR/AV, as detection rates have grown

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, penetration-testing
- domain: security, penetration-testing, windows
- platform: cli
- tags: payload-generation, antivirus-bypass, metasploit, powershell, uac-bypass, persistence, red-team, linux, docker

## Member repositories
- nccgroup/Winpayloads (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:11.572267+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:50:04.320173+00:00, confidence not recorded.
  - readme: https://github.com/nccgroup/Winpayloads (fetched 2026-08-28T04:05:11.572267+00:00, sha c346893d3b4b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
