Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. PowerShell
  3. Nishang

Nishang

NOASSERTIONPowerShellv0.7.6

A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.

GitHubGitHub
10.0k stars2.5k forks0 contributors

What is Nishang?

Nishang is a comprehensive framework and collection of PowerShell scripts and payloads designed for offensive security operations. It enables security professionals and red teams to leverage PowerShell for penetration testing, post-exploitation, and red teaming activities across all phases of an engagement, from initial access to lateral movement and persistence.

Target Audience

Security professionals, penetration testers, and red team operators who need to conduct authorized security assessments, exploit vulnerabilities, and simulate adversary attacks using PowerShell in Windows environments.

Value Proposition

Developers choose Nishang for its extensive, modular collection of real-world attack scripts that emphasize in-memory execution to evade detection, its coverage of all penetration testing phases, and its practical focus on combining tools for complex attack chains in red team operations.

Overview

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Use Cases

Best For

  • Conducting penetration testing and red team engagements across Windows environments using PowerShell.
  • Executing post-exploitation activities like credential dumping, lateral movement, and privilege escalation.
  • Creating client-side attack payloads for phishing campaigns, such as malicious Office documents, CHM, HTA, and shortcut files.
  • Establishing persistence and backdoors on compromised systems using methods like HTTP, DNS, WLAN SSIDs, or registry tricks.
  • Bypassing antivirus and AMSI (Antimalware Scan Interface) to execute scripts in memory and avoid detection.
  • Performing reconnaissance and information gathering, including extracting credentials, hashes, WLAN keys, and LSA secrets.

Not Ideal For

  • Automated vulnerability scanning platforms requiring out-of-the-box reporting and GUI interfaces
  • Defensive security operations focused solely on monitoring, incident response, or compliance audits without red team authorization
  • Cross-platform engagements targeting Linux or macOS systems, as Nishang is heavily Windows and PowerShell-dependent
  • Projects needing commercial support, formal certifications, or vendor-backed updates for enterprise security tools

Pros & Cons

Pros

Comprehensive Red Team Coverage

Includes scripts for all penetration testing phases, from Active Directory exploitation and client-side attacks to lateral movement and persistence, as detailed in the Key Features section.

In-Memory Execution Focus

Designed to run scripts in memory using methods like download strings and encoded commands, specifically to evade antivirus detection, as emphasized in the Anti Virus usage examples.

Modular and Practical Design

Scripts are modular and can be combined for complex attack chains, reflecting real-world red team operations based on the author's experience and linked blog posts.

Built-in Evasion Techniques

Provides tools like Invoke-AmsiBypass and Invoke-Encode to bypass AMSI and antivirus, ensuring scripts can operate in monitored environments, as mentioned in the Bypass and Utility sections.

Cons

High Antivirus Detection Rate

Most scripts are flagged as malicious by antivirus software, requiring obfuscation or exclusive in-memory execution, which adds operational complexity and risk of failure.

Windows and PowerShell Dependency

Primarily effective only in Windows environments with PowerShell enabled, limiting usability in cross-platform scenarios or where PowerShell is restricted or absent.

Steep Operational Learning Curve

Requires advanced knowledge of PowerShell, networking, and attack methodologies to deploy and chain scripts effectively, with the README offering minimal beginner-friendly guidance.

Maintenance and Update Reliance

Evasion techniques may become outdated as security patches are released, and the project relies on community contributions, potentially lagging behind the latest threat landscapes.

Frequently Asked Questions

Quick Stats

Stars10,010
Forks2,547
Contributors0
Open Issues16
Last commit2 years ago
CreatedSince 2014

Tags

#lateral-movement#redteam#red-teaming#infosec#penetration-testing#security#activedirectory#offensive-security#red-team#post-exploitation#powershell#active-directory#hacking#backdoor#privilege-escalation

Built With

P
PowerShell

Included in

PowerShell5.4k
Auto-fetched 2 hours ago

Related Projects

PowerSploitPowerSploit

PowerSploit - A PowerShell Post-Exploitation Framework

Stars13,089
Forks4,715
Last commit6 years ago
BloodHoundBloodHound

Six Degrees of Domain Admin

Stars10,577
Forks1,798
Last commit4 months ago
PowerShellEmpirePowerShellEmpire

Empire is a PowerShell and Python post-exploitation agent.

Stars7,866
Forks2,936
Last commit6 years ago
Invoke-ObfuscationInvoke-Obfuscation

PowerShell Obfuscator

Stars4,300
Forks816
Last commit2 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub