Skip to content

Evil-Win RM

Ultimate WinRM shell for hacking and pentesting Windows hosts using the native WinRM protocol.

Self-hostedNot yet verified
Report issue
GPL-3.0★ 4500Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Evil-Win RM?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Evil-Win RM?

Evil-WinRM is an open-source tool designed to provide a secure, interactive shell for interacting with Windows systems via the Windows Remote Management (WinRM) protocol. It serves as a critical utility for ethical hackers and penetration testers who need to execute commands remotely on target machines. The tool simplifies the process of leveraging WinRM, which is a Microsoft implementation of the WS-Management protocol, to perform tasks such as file transfers, command execution, and system reconnaissance. It is particularly useful in scenarios where direct access to a Windows machine is required but traditional methods like PowerShell remoting are not feasible. The project's popularity, evidenced by its 5.4k GitHub stars, underscores its value in the cybersecurity community for its efficiency and flexibility in handling complex remote operations. The tool addresses the challenge of managing and exploiting Windows environments through a, scriptable interface. By abstracting the complexities of WinRM communication, Evil-WinRM enables users to bypass limitations of other tools, such as the need for interactive sessions or specific authentication methods. Its open-source nature allows for customization and integration into broader penetration testing frameworks. Users include red teams, security researchers, and system administrators testing their networks' defenses. The tool's ability to handle both basic and advanced operations makes it a go-to solution for tasks ranging from simple command execution to sophisticated post-exploitation activities.

How it works

Evil-WinRM is a command-line interface (CLI) tool that facilitates remote interaction with Windows systems using the WinRM protocol. It is primarily used in penetration testing and ethical hacking to execute commands, transfer files, and manage remote sessions on Windows targets. The tool's purpose is to streamline the exploitation of WinRM-enabled systems by providing a user-friendly interface for executing payloads and managing sessions. It is particularly effective when traditional methods like PowerShell remoting are restricted or unavailable. Evil-WinRM supports command execution, file uploads/downloads, and session management. It can bypass limitations of other tools by allowing direct interaction with WinRM endpoints, even when authentication mechanisms like Kerberos are in place. For example, users can execute arbitrary commands on a target machine and view real-time outputs, making it ideal for post-exploitation tasks.

How to use it

  1. 1Ensure the target Windows machine has WinRM enabled and configured for remote management. 2. Use Ruby to install Evil-WinRM via the Gem package manager or clone the repository from GitHub. 3. Run the tool with the target's IP address, port, and credentials (e.g., `evil-winrm -i 192.168.1.1 -u Administrator -p password`). 4. Execute commands using the shell interface or script payloads for automated tasks. Practical tips include using HTTPS for encrypted communication, handling authentication challenges via the `-H` flag, and leveraging the tool's scriptability for complex operations like privilege escalation.

What it can do

  • WinRM shell

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/Hackplayers/evil-winrm
  • license: GPL-3.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
  • Requires WinRM to be explicitly enabled and configured on the target system
  • Dependent on Ruby runtime, which may introduce compatibility issues
  • Limited support for advanced authentication methods beyond basic credentials
  • May be blocked by firewalls or network policies restricting WinRM traffic

Understanding the result

Ultimate WinRM shell for hacking and pentesting Windows hosts using the native WinRM protocol.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (GPL-3.0).
Built with
(Hackplayers/evil-winrm)
License
GPL-3.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with Hackplayers/evil-winrm. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
GPL-3.0
View source on GitHub

Open-source project

License: GPL-3.0Source: this project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is the primary use case for Evil-WinRM?

Evil-WinRM is primarily used for penetration testing and ethical hacking, enabling users to execute commands, transfer files, and manage remote sessions on Windows systems via the WinRM protocol. It is especially valuable when traditional methods like PowerShell remoting are restricted, allowing attackers to bypass limitations and maintain access for post-exploitation activities.

How does Evil-WinRM interact with the WinRM protocol?

Evil-WinRM leverages the WinRM protocol's SOAP-based communication to establish a remote session with a Windows target. It sends commands as XML requests, which the target processes and returns outputs. This interaction allows for real-time command execution and file manipulation, making it a powerful tool for remote system management. The tool abstracts the complexity of WinRM's XML-based messaging, providing a simpler CLI interface for users.

How do I execute a command using Evil-WinRM?

To execute a command, first establish a connection using `evil-winrm -i <target_ip> -u <username> -p <password>`. Once connected, type the command in the shell prompt (e.g., `whoami` or `ipconfig`). For scripted execution, use Ruby syntax within the tool's interface or integrate it with external scripts for automation.

How does Evil-WinRM compare to tools like PowerShell or Empire?

Evil-WinRM differs from PowerShell by relying on WinRM instead of native cmdlets, which can bypass restrictions on certain systems. Compared to Empire, it lacks built-in payload generation but offers a more direct interface for WinRM-based operations. PowerShell is often preferred for its native integration with Windows, while Empire provides broader payload options, making Evil-WinRM a specialized tool for WinRM-specific tasks.

How do I troubleshoot connection issues with Evil-WinRM?

Common issues include WinRM being disabled on the target, incorrect credentials, or firewall blocks. Verify WinRM is enabled via `winrm quickconfig` on the target. Use the `-H` flag to handle authentication challenges. Ensure the target's firewall allows traffic on port 5985 (HTTP) or 5986 (HTTPS). If connectivity fails, test with `Test-NetConnection` in PowerShell to diagnose network issues.

Spotted something wrong with Evil-Win RM, or want to maintain it? See how to help.