What’s RFF? →

Free Windows troubleshooting tools

Windows hides its most useful diagnostics behind tools nobody enjoys using. These wrap a few of the worst offenders. No account, no install, no upload.

Every tool here runs entirely in your browser. Nothing is uploaded.

wraps Installer switches

SwitchHunt

What's the silent install switch?

Drop any Windows installer and get its silent install, repair, and uninstall commands. Also builds a real .intunewin package for Intune.

wraps VBScript

VBS to PowerShell

What does this old logon script actually do?

Drop a .vbs file and get PowerShell back, plus a count of what still needs a human. It keeps the semantics that break a find-and-replace: & always concatenates, string compares are case-sensitive, Mid and InStr count from 1. Lines it can't convert cleanly come back as # TODO with your original underneath.

wraps NVD + MSRC

VulnScan

What here is actually vulnerable, and how do you know?

Run one script and get the published CVEs affecting your installed software and your build of Windows, with the registry key each finding was read from. Covers the top 500 Windows applications plus the OS, and reads Store apps too, which most tools miss. Nothing is uploaded.

wraps NVD + CISA KEV + MSRC

CVE catalog

What is this CVE, and what actually fixes it?

Search every published CVE by id or product, with its CVSS score and whether CISA lists it as actively exploited. For Windows CVEs you also get the part other catalogs leave blank: the update that fixes it and the build revision that carries the fix.

wraps Intune Win32 detection

Intune detection rule

Why does Intune keep reinstalling this app?

Drop an MSI, EXE or install script and get the Win32 detection rule for it, with the version operator set so a new build still applies. Most broken deployments trace back to a rule that was fine on day one and quietly stopped matching after the first update.

wraps PerfMon

Culprit

Why is this machine slow?

Drop a PerfMon CSV and get a plain-English verdict: what is eating the CPU, whether it is out of RAM, and whether the disk is the real bottleneck.

wraps Procmon

Denied

Why does this app crash?

Drop a Procmon CSV and get the culprit: the access denied that mattered, the DLL that never loaded, the file a scanner had locked, and what is safe to ignore.

wraps Group Policy / RSoP

WorksOnMine

It works on my machine. Why not that one?

Run one script on two machines and see exactly which policies and registry values disagree, with the Group Policy that set each one.

wraps secedit / auditpol

Hardened

Is this machine locked down?

Score one machine against a Windows security baseline covering account policy, user rights, audit policy, and the registry settings that matter.

wraps Intune / ConfigMgr / RMM export

Sprawl

How many versions of everything are you running?

Drop the software inventory you already export from Intune, Configuration Manager or your RMM and see every application running at more than one version, plus what is past end-of-support.

wraps Disk cleanup

SafeToDelete

What is actually safe to delete?

Run one script and get every reclaimable location graded by how safe it is to remove and what it costs you, including which part of the Windows Installer cache is orphaned and which part is still needed for repair and uninstall. It reports by default and removes only the rows you approve, logging every file it touches.

wraps Windows CVE checking

Patched?

Is this build actually patched?

Paste a Windows build with its revision and get the answer with the evidence: the revision Microsoft says fixes each CVE, the one you are on, and which installed update covered you, including when it only did so by superseding the update that carried the fix. Other checkers compare a version string, and Windows version strings drop the revision, so a fully patched machine reads as vulnerable.

wraps Intune Win32 packaging

Create a .intunewin file

No IntuneWinAppUtil.exe, nothing uploaded.

Convert an EXE or MSI into a real, Intune-ready .intunewin package in your browser, with no IntuneWinAppUtil.exe and nothing uploaded.

Why these run in your browser

Every tool here reads your file locally and never sends it anywhere. That is not a privacy slogan, it is an architectural choice with a real cost: it rules out anything needing server-side compute, which is why you will not find an EXE-to-MSI repackager here. The upside is that you can verify the claim rather than trust it. Open your browser's developer tools, watch the network tab, and drop a file - there is no upload request, because there is nowhere for it to go.

That matters more than usual for this audience. An installer can be a licensed vendor package, a registry export can carry internal server names, and a performance capture lists every process a person was running. Those are things an admin should think twice about handing to a stranger's server, and with these tools that question never comes up.

Where the paid product starts

These are deliberately single-machine, point-in-time, and read-only. None of them changes anything or scales past a machine or two, because that is the honest boundary: at fleet scale you want continuous monitoring and the ability to fix what you find, which is what RFF does. Free for your first 100 endpoints.

Built by the RFF team.