awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
SecureThisShit avatar

SecureThisShit/WinPwn

0
View on GitHub↗
3,673 stars·538 forks·PowerShell·BSD-3-Clause·18 views

WinPwn

WinPwn is a Windows penetration testing framework designed for conducting internal security assessments and privilege escalation. It functions as a suite for Active Directory security auditing, credential extraction, and the execution of privilege escalation scripts.

The toolset enables the automation of SMB relay attacks to intercept and reuse authentication hashes. It provides specialized capabilities for retrieving passwords and hashes from system memory, registries, and browsers using obfuscated techniques to avoid detection.

The framework covers broad capability areas including domain and local reconnaissance, the deployment of kernel-level exploits, and the identification of misconfigured permissions. It includes functionality to bypass security controls, such as disabling event tracing and malware scanning interfaces.

The project is available as a standalone offline package, allowing the execution of scripts and binaries on isolated network systems without requiring internet connectivity.

Features

  • Active Directory Assessment - Provides a comprehensive suite for auditing and analyzing security configurations within Windows Active Directory environments.
  • Penetration Testing Frameworks - Provides a comprehensive framework for conducting internal security assessments and privilege escalation on Windows environments.
  • Credential Theft and Cracking Suites - Extracts stored passwords and hashes from system memory and browsers to facilitate unauthorized access.
  • Internal Network Penetration Testers - Conducts scanning and lateral movement within internal networks using SMB relay attacks and resource enumeration.
  • SMB Relay Attacks - Automates the interception and relaying of SMB authentication traffic to gain unauthorized network access.
  • Credential Memory Extraction - Extracts authentication secrets and password hashes from system memory using obfuscated techniques.
  • Credential Extraction - Retrieves passwords and hashes from memory, registries, and browsers using obfuscated extraction techniques.
  • Windows Privilege Escalation Suites - Offers a specialized toolkit of scripts to identify misconfigurations and deploy kernel exploits for local administrative access.
  • Credential Extraction Utilities - Extracts passwords and hashes from system memory, registries, and browsers using obfuscated techniques.
  • Kernel Privilege Escalation Exploits - Deploys functional exploits targeting kernel-level vulnerabilities to achieve the highest level of system control.
  • Active Directory Enumerations - Provides specialized discovery and mapping of users and trusts within Windows Active Directory environments.
  • Windows Privilege Escalations - Elevates limited user processes to SYSTEM or Administrator using Windows service misconfigurations and kernel exploits.
  • Active Directory Security Tools - Ships utilities for enumerating domain infrastructure and identifying delegation vulnerabilities within Active Directory.
  • Kernel-Level Bypass Utilities - Includes utilities to modify kernel verification logic and execute low-level vulnerabilities for system control.
  • SMB Relay Attacks - Intercepts and reuses authentication hashes via SMB-Relay attacks to access network resources.
  • Standalone Binary Packaging - Bundles all required scripts and binaries into a single standalone package for portable execution.
  • DLL Hijacking - Identifies and replaces system DLLs to elevate privileges during application startup.
  • Offline Host Collection - Runs standalone binaries on isolated endpoints to perform security operations in air-gapped environments.
  • Access Control Bypasses - Circumvents authentication and monitoring mechanisms to avoid detection by system security tools.
  • Security Product Evasions - Neutralizes antimalware and event tracing interfaces to avoid detection during security audits.
  • Offline Security Auditing - Executes security assessments and audits on isolated systems without requiring internet or network access.
  • Host Reconnaissance - Collects software lists, network shares, and system privileges from compromised hosts for local reconnaissance.
  • Security Monitoring Evasions - Disables event tracing and malware scanning interfaces to prevent detection by host security tools.
  • Windows Security Utilities - Automates reconnaissance and privilege escalation on Windows domains.

Star history

Star history chart for securethisshit/winpwnStar history chart for securethisshit/winpwn

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does securethisshit/winpwn do?

WinPwn is a Windows penetration testing framework designed for conducting internal security assessments and privilege escalation. It functions as a suite for Active Directory security auditing, credential extraction, and the execution of privilege escalation scripts.

What are the main features of securethisshit/winpwn?

The main features of securethisshit/winpwn are: Active Directory Assessment, Penetration Testing Frameworks, Credential Theft and Cracking Suites, Internal Network Penetration Testers, SMB Relay Attacks, Credential Memory Extraction, Credential Extraction, Windows Privilege Escalation Suites.

What are some open-source alternatives to securethisshit/winpwn?

Open-source alternatives to securethisshit/winpwn include: s3cur3th1ssh1t/winpwn — WinPwn is a Windows penetration testing framework and security toolkit designed for auditing Active Directory and… k8gege/k8tools — K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port… k8gege/ladon — Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning… ridter/intranet_penetration_tips — This project is a technical guide and reference for internal network penetration testing. It serves as a collection of… specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity…

Open-source alternatives to WinPwn

Similar open-source projects, ranked by how many features they share with WinPwn.
  • s3cur3th1ssh1t/winpwnS3cur3Th1sSh1t avatar

    S3cur3Th1sSh1t/WinPwn

    3,674View on GitHub↗

    WinPwn is a Windows penetration testing framework and security toolkit designed for auditing Active Directory and exploiting Windows environments. It provides a collection of automated tools and scripts for domain enumeration, credential theft, and privilege escalation. The toolkit distinguishes itself through capabilities for neutralizing antimalware scanning interfaces to evade detection and providing offline binary packaging for execution on isolated systems without internet access. It also includes specialized utilities for intercepting and relaying SMB authentication traffic to gain unau

    PowerShelladsecurityautomationexploitation
    View on GitHub↗3,674
  • k8gege/k8toolsk8gege avatar

    k8gege/K8tools

    6,167View on GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    View on GitHub↗6,167
  • k8gege/ladonk8gege avatar

    k8gege/Ladon

    5,297View on GitHub↗

    Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk security flaws and assets across network segments. It operates as a fileless security scanner, executing its engine and modules directly in memory to avoid leaving a disk footprint on target systems. The project is distinguished by its integration as a plugin for command beacons, specifically within the Cobalt Strike framework. This allows for memory-resident network discovery and vulnerability detection. It further supports stealth operations through payload and script obfuscatio

    C#brute-forceexpexploit
    View on GitHub↗5,297
  • samsar4/ethical-hacking-labsSamsar4 avatar

    Samsar4/Ethical-Hacking-Labs

    3,397View on GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    View on GitHub↗3,397
  • See all 30 alternatives to WinPwn→