# WES-NG: Windows Exploit Suggester for Modern Windows Versions

> WES-NG takes the output of Windows' systeminfo utility and cross-references it against a compiled vulnerability database to list every unpatched CVE on a system, including available exploits. It works across every Windows release from Windows XP to Windows 11 and their Server counterparts.

**bitsadmin/wesng** — Windows Exploit Suggester - Next Generation

- Repository: https://github.com/bitsadmin/wesng
- Stars: 4,942 · Forks: 608
- Language: Python
- License: BSD-3-Clause
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/bitsadmin-wesng

## Why WES-NG Exists: The Limits of Its Predecessor

The README explains the origin directly. GDSSecurity's Windows-Exploit-Suggester worked well for Windows XP and Vista era systems, but Microsoft stopped updating the Excel-based Security Bulletin Data file that tool depends on in Q1 2017. Any vulnerability published after that date, and any operating system more recent than Windows Vista, falls outside what the original tool can detect. WES-NG replaces the old data source with Microsoft's MSRC API, which covers current Windows releases. The result is a tool that spans Windows XP through Windows 11 and the corresponding Windows Server families, all from the same workflow. The version available through pip is 1.0.3, classified in setup.py as Development Status 5 - Production/Stable. The project is actively maintained: the last push was on 2026-09-25.

## The Vulnerability Database: Four Sources Combined

WES-NG does not rely on a single data feed. The collector script pulls from four sources: Microsoft Security Bulletin Data for older systems, the MSRC API for modern Windows updates, the NIST National Vulnerability Database to add Exploit-DB links, and OffSec's Exploit-DB directly. These are merged into a single CSV file, compressed into definitions.zip, and committed to the GitHub repository. Running wes.py --update downloads the latest version of that file. If the upstream GitHub repository is unavailable or a custom database is needed, the collector/ folder contains the scripts to regenerate definitions.zip from scratch; the README notes they should be executed in the order they are listed and that comments at the top of each script describe their requirements.

## Getting Started: Installing and Running WES-NG

WES-NG installs through pip or can be cloned directly:

```bash
pip install wesng
```

Alternatively:

```bash
git clone https://github.com/bitsadmin/wesng --depth 1
```

Once installed, update the vulnerability database:

```bash
wes.py --update
```

To collect system information from the target host, run systeminfo on that machine and save the output:

```bash
systeminfo > systeminfo.txt
```

Then pass that file to WES-NG:

```bash
wes.py systeminfo.txt
```

For environments where PowerShell is available, the included missingkbs.ps1 script determines which patches are missing directly and produces a missing.txt file. That file can then be passed as input with wes.py --missing missing.txt, which gives a more precise result by working from confirmed missing patches rather than inferring from the full installed-patches list.

## Reducing False Positives with MUC Lookup

The README acknowledges that the MSRC feed is frequently incomplete, which causes WES-NG to report vulnerabilities that are already patched. To address this, contributor @DominicBreuker added the --muc-lookup parameter, which validates identified missing patches against Microsoft's Update Catalog. The wiki provides a dedicated 'Eliminating false positives' page with guidance on interpreting results, and a separate 'Reporting false positives' page for cases where the wiki guidance does not resolve the issue. Running the tool without this validation step on a heavily patched system can produce a list long enough to be impractical. The README lists false-positive reduction as an ongoing area of improvement alongside adding support for NoPowerShell's Get-SystemInfo output and alternative systeminfo output formats.

## Operational Constraints and Deployment Limits

WES-NG runs on the analyst's machine, not the target. It needs only the text output from systeminfo.exe, which means it works equally well for local analysis and for remote assessments where systeminfo /S MyRemoteHost captures a remote system. The tool does not require administrator rights on the analyst machine for basic usage. The setup.py lists chardet as the only runtime dependency, and it supports Python 2.7 through Python 3.11. The version available through pip is 1.0.3. WES-NG cannot assess Linux, macOS, or network devices: it is strictly a Windows patch-level auditing tool and the database covers only Microsoft products.

## Comparison with Microsoft's Built-In Security Tools

Windows Security Center and Windows Update report what patches are missing and offer to apply them. WES-NG does something different: it maps the gap between what is installed and what is published in the vulnerability database, then attaches CVE identifiers and exploit links to each gap. Microsoft Baseline Security Analyzer, which Microsoft retired in 2017, served a similar purpose for older systems but is no longer updated and does not cover modern Windows. WES-NG fills that space with a maintained, Python-based tool that a penetration tester can run without requiring any special Windows tools or a direct connection to the target.

## Offline Use, Remote Assessments, and Scripting

A significant practical strength of WES-NG is that the analysis runs entirely on the analyst's machine from a plain text file. The systeminfo.exe utility ships with every Windows installation, so collecting system information from a target requires no third-party tools on the target system. On a remote host, the command systeminfo /S MyRemoteHost redirects output across the network, though the README does not document authentication requirements for this. For assessments where network access to the target is restricted after initial enumeration, the text file can be transported manually and analyzed on a separate machine with the WES-NG database. This offline capability is a meaningful advantage over browser-based vulnerability databases that require internet access to query. The setup.py shows that the tool supports both Python 2.7 and Python 3.4 through 3.11, making it deployable on older analyst workstations without requiring a Python upgrade. The pip entry point installs wes as a command-line tool, so after installation, wes can be run directly from any terminal on the analyst machine. The CMDLINE.md file in the repository documents all available parameters for wes.py, missingkbs.vbs, and missingkbs.ps1; it is the most complete reference for command-line options beyond what the README covers. The --muc-lookup parameter in particular is not described in the README's quick-start section and is only found in the full parameter reference. Running wes.py without any arguments prints a summary of the available options. WES-NG is licensed under the BSD-3-Clause license, as recorded in LICENSE.txt. The tool was authored by Arris Huijgen, whose GitHub handle is bitsadmin.

## Conclusion

WES-NG is the right tool for penetration testers and system administrators who need to audit unpatched Windows systems and want a clear list of applicable CVEs and exploit links. It is not a remediation tool: it identifies gaps but does not apply patches or prioritize fixes by exploitability. Before using it in a production audit, run wes.py --update to get the latest definitions, and then consult the wiki's false-positive guidance before acting on the output, since the MSRC feed it depends on frequently reports incomplete patch data.

## FAQ

### How do I update the WES-NG vulnerability database?

Run wes.py --update after installation. This downloads the latest definitions.zip from the GitHub repository, which is the compiled database drawn from the MSRC API, NIST NVD, and Exploit-DB.

### Does WES-NG work on Windows 11?

Yes. The README states that every Windows OS between Windows XP and Windows 11, including their Windows Server counterparts, is supported.

### Why does WES-NG report vulnerabilities that are already patched?

The MSRC feed that WES-NG depends on is frequently incomplete, according to the README. Using the --muc-lookup parameter validates results against Microsoft's Update Catalog and reduces these false positives. The wiki's 'Eliminating false positives' page provides further guidance.

## Sources

- [bitsadmin/wesng on GitHub](https://github.com/bitsadmin/wesng)
- [Issues](https://github.com/bitsadmin/wesng/issues)
- [License: BSD-3-Clause](https://github.com/bitsadmin/wesng/blob/master/LICENSE)
- [README](https://github.com/bitsadmin/wesng/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bitsadmin-wesng
