Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
evil-winrm-py — Execute commands interactively on remote Windows machines using the WinRM protocol (just faster) | Kitploit
Tools/GitHubGitHub/adityatelange/evil-winrm-py
Password AttacksLateral MovementScripting & AutomationPost-ExploitationPenetration TestingCommand and ControlAuthenticationRed TeamingRemote Access ToolPayload Development
GitHub
40038913 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
adityatelange/evil-winrm-py

evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

View RepositoryWebsite
ewp-logo

evil-winrm-py

PyPI version Python License PyPI Downloads Github Wiki

evil-winrm-py is a python-based tool for executing commands on remote Windows machines using the WinRM (Windows Remote Management) protocol. It provides an interactive shell with enhanced features like file upload/download with progress and checksum verification, tab-completion of local/remote paths and PowerShell cmdlets, loading and running PowerShell scripts, in-memory execution of DLLs and EXEs, command history, and colorized output. It can also run as an MCP server, exposing WinRM sessions as tools for MCP-compatible clients. It supports various authentication methods including NTLM, Pass-the-Hash, Certificate, and Kerberos. skip to installation

[!NOTE] This tool is designed strictly for educational, ethical use, and authorized penetration testing. Always ensure you have explicit authorization before accessing any system. Unauthorized access or misuse of this tool is both illegal and unethical.

Motivation

The original evil-winrm is written in Ruby, which can be a hurdle for some users. Rewriting it in Python makes it more accessible and easier to use, while also allowing us to leverage Python’s rich ecosystem for added features and flexibility.

I also wanted to learn more about winrm and its internals, so this project will also serve as a learning experience for me.

Features

  • Execute commands on remote Windows machines via an interactive shell.
  • Download files from the remote host to the local machine.
  • Upload files from the local machine to the remote host.
  • Progress bar for file transfers with speed and time estimation.
  • Stable and reliable file transfer including support for large files with MD5 checksum verification.
  • Auto-complete local and remote file paths (even those with spaces) with Tab completion.
  • Auto-complete PowerShell cmdlets/helpers with Tab completion.
  • Load PowerShell functions from local scripts into the interactive shell.
  • Run local PowerShell scripts on the remote host.
  • Load local DLLs (in-memory) as PowerShell modules on the remote host.
  • Upload and execute local EXEs (in-memory) on the remote host.
  • List the running services (except system services) on the remote host.
  • Optional MCP server mode to expose WinRM login/execute/logout as tools for MCP clients, with support for multiple concurrent sessions. 🆕
  • Enable logging and debugging for better traceability.
  • Navigate command history using up/down arrow keys.
  • Display colorized output for improved readability.
  • Lightweight and Python-based for ease of use.
  • Keyboard Interrupt (Ctrl+C / Ctrl+D) support to terminate long-running commands gracefully.

Includes support for:

  • NTLM authentication.
  • Pass-the-Hash authentication.
  • Certificate authentication.
  • Kerberos authentication with custom SPN prefix and hostname options.
  • SSL to secure communication with the remote host.
  • custom WSMan URIs.
  • custom user agent for the WinRM client.
  • connecting to Just Enough Administration (JEA) session configurations. 🆕

Detailed documentation can be found in the docs directory.

Installation

Installation of Kerberos prerequisites on Linux

sudo apt install gcc python3-dev libkrb5-dev krb5-pkinit
# Optional: krb5-user

Install evil-winrm-py

You may use uv/pipx instead of pip to install evil-winrm-py. uv/pipx is a tool to install and run Python applications in isolated environments, which helps prevent dependency conflicts by keeping the tool's dependencies separate from your system's Python packages.

Check Installation Guide for more details.

pip install evil-winrm-py
# for optional dependencies use any one of the following commands:
pip install evil-winrm-py[kerberos] # for kerberos support on Linux
pip install evil-winrm-py[mcp] # for mcp support
pip install evil-winrm-py[kerberos,mcp] # to install both optional dependencies

# Note: building gssapi and krb5 packages may take some time, so be patient.

or if you want to install with latest commit from the main branch you can do so by cloning the repository and installing it with pip/uv/pipx:

git clone https://github.com/adityatelange/evil-winrm-py
cd evil-winrm-py
pip install .
# or use: pip install .[kerberos,mcp] to install both optional dependencies

Update

pip install --upgrade evil-winrm-py

Uninstall

pip uninstall evil-winrm-py

Availability on Unix distributions

Packaging status

For above mentioned distributions, you can install evil-winrm-py directly from their package managers. Thanks to the package maintainers for packaging and maintaining evil-winrm-py in their respective distributions.

Usage

Details on how to use evil-winrm-py can be found in the Usage Guide.

usage: evil-winrm-py [-h] [-i IP] [-u USER] [-p PASSWORD] [-H HASH] [-c CONFIGURATION_NAME]
                     [--priv-key-pem PRIV_KEY_PEM] [--cert-pem CERT_PEM] [--uri URI] [--ua UA]
                     [--port PORT] [--spn-prefix SPN_PREFIX] [--spn-hostname SPN_HOSTNAME] [-k]
                     [--no-pass] [--ssl] [--log] [--debug] [--no-colors] [--version] [--mcp]
                     [--mcp-port MCP_PORT] [--mcp-host MCP_HOST]
Download Tool