# S3cur3Th1sSh1t/WinPwn

Automation for internal Windows Penetrationtest / AD-Security

Repository: https://github.com/S3cur3Th1sSh1t/WinPwn
Canonical: https://ross.abutalabs.com/products/winpwn
Language: PowerShell
License: BSD-3-Clause
License Family: permissive
Topics: pentesting, automation, adsecurity, privilege-escalation, powersploit, pentest-tool, exploitation, recon, redteam, powershell
Last push: 2025-08-28T13:07:26+00:00

## Health v2 (maintenance only)
Score: 40/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 39, release rhythm 8, longevity 100
- inputs: {"age_days": 3101, "days_push": 370, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3693, forks 536 (observed 2026-08-28T04:08:14.813637+00:00)

## What it is
WinPwn is a PowerShell-based automation framework for internal Windows penetration testing and Active Directory security assessment. It bundles well-known offensive security scripts for reconnaissance, privilege escalation, and credential dumping behind a menu-driven interface with automatic proxy support.

## Use cases
- automate internal windows penetration tests
- enumerate active directory domain vulnerabilities
- dump credentials and lsass memory on a compromised host
- run local privilege escalation checks on windows
- perform smb relay and mitm attacks during red team engagements
- find passwords and sensitive files on a windows system

## When to choose
- you are doing authorized internal pentesting or red teaming on Windows/AD environments
- you want a single menu-driven script chaining many recon and exploitation tools
- you need proxy-aware execution on a target network
- you need an offline-capable toolkit on a machine without internet access

## When to avoid
- you need defensive or blue-team tooling rather than offensive testing
- you are on Linux or macOS - it targets Windows PowerShell
- you want stealthy, low-noise tooling - it bundles widely signatured scripts
- you are not authorized to test the target system

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, workflow-automation, developer-tools
- domain: penetration-testing, security, windows
- platform: windows, cli
- tags: red-team, active-directory, privilege-escalation, reconnaissance, powershell, offensive-security, credential-dumping

## Member repositories
- S3cur3Th1sSh1t/WinPwn (main) score 40

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:14.813637+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:31:05.965232+00:00, confidence not recorded.
  - readme: https://github.com/S3cur3Th1sSh1t/WinPwn (fetched 2026-08-28T04:08:14.813637+00:00, sha d337139f1161)
- Data as of 2026-08-30T08:39:29.467469+00:00.
