Sitelet https://github.com/NairoDorian/tiny11builder_2026
Skip to content

About

Scripts to build a trimmed-down Windows 11 image.

Resources

Contributing

Stars

3 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

Tiny11 Builder — Ultimate Edition (2026)

CI Windows 11 26H2 / 25H2 / 24H2 PowerShell 5.1 | 7 x64 + ARM64 License: MIT

Turn Microsoft's official Windows 11 ISO into a small, clean, private one, with a graphical builder for the common options, or detailed command-line control.

The builder window after a finished build

With the built-in Default preset, it requests these changes to the resulting installation:

  • remove planned bloat apps, Edge and OneDrive, and disable targeted AI/Widgets/advertising policies;
  • send minimal telemetry;
  • install without a Microsoft account or a network connection;
  • skip the TPM / Secure Boot / CPU / RAM checks.

Default retains the Update, Defender and Store components; effective policy/runtime behavior depends on Windows edition/version and target testing.

This project is a fork of ntdevlabs/tiny11builder. Its full history is kept on main, and the 2026 edition follows as regular commits on top. It selectively adapts fixes from 20 community projects (see Credits and the branch comparison).

Important

The image patches target an offline Windows copy. Real builds temporarily attach media/hives and write project/work/output files:

  • It mounts the image in a work folder and edits the image's offline registry (temporarily loaded as HKLM\z*), then writes a new ISO.
  • The registry helpers refuse any path outside those offline hives, and refuse to write at all unless an image hive is loaded.
  • The only optional host-side change is Faster build (Defender exclusion). It is off by default and cleanup is attempted when the build ends. It is not authorized on this session's read-only host; see working notes.

Current state and documentation

Implementation reviewed at 2ae045d, 2026-10-05; version label remains 2026.09. Start with the documentation map, agent handoff, architecture/pipeline and verification matrix. Together they explain current behavior, constraints, history and unfinished validation from Markdown alone.

The latest app checks passed in PowerShell 5.1 and 7 (CI). Two earlier fresh Standard x64 Pro builds measured 9m18s / 14.75 GB uncompressed with cleanup skipped and 21m06s / 6.23 GB maximum with normal cleanup. These were at 7aa45d5, before later PR/reference safeguards. No latest-revision full ISO or VM installation is claimed. The historical final output is absent at its recorded path; source ISO and compact evidence remain. See PERFORMANCE.md.

Contents


Highlights

Build options in one window A 7-tab GUI with a live log, step/overall progress and ETA. The build runs in a hidden child; Cancel attempts cleanup.
Current Windows Readers/planners cover newer Windows release labels, x64/ARM64, WIM/ESD and language metadata. Full-build evidence is 26300.9457 Pro x64/en-US; other combinations need validation.
AI and ads off Policies for Copilot, Recall, Click to Do, the Settings agent, generative AI in Paint, Notepad and Edge, Widgets, Bing search, Start recommendations and "finish setting up" nags.
No surprise reinstalls Removed apps are deprovisioned, and the Outlook, Dev Home, Teams and Edge re-installers are blocked.
Your first boot, your way A local admin account (or create one in OOBE), locale, time zone, computer name, a zero-touch install for VMs, a browser installed at first sign-in, and your own scripts.
Transparent Every registry value is listed in docs/TWEAKS.md, every app in docs/APPS.md. Each ISO gets a .json manifest and a .sha256 file.
Safe by construction Options are validated early. Offline registry guards protect live paths; failures stop and attempt cleanup, retaining files when dismount/state is unsafe. The downloaded oscdimg.exe is checksum-pinned.
Tested About 1,900 core checks plus real media/export fixtures; PowerShell 5.1 and 7 CI. See the dated verification matrix for exact counts and limits.

Quick start

  1. Download a Windows 11 ISO from microsoft.com/software-download/windows11.
  2. Double-click LAUNCH_TINY11.bat and press 1 (graphical builder). It asks for administrator rights.
  3. In Source, browse to the ISO and choose an edition, for example Windows 11 Pro. Its editions load automatically without mounting. For a typed path or existing drive, click Load editions.
  4. Optionally adjust the other tabs, then click Build ISO. Time depends on source/options/storage/CPU; the measured maximum run took 21 minutes. See the performance report.
  5. Write the ISO to a USB stick with Rufus (keep its default options) or attach it to a VM.

From an elevated PowerShell prompt, the same in one line:

.\tiny11maker.ps1 -ISO C:\iso\Win11_25H2_English_x64.iso -Edition Pro -Yes

The ISO is written next to the scripts as tiny11.iso (tiny11core.iso for Core), with tiny11.iso.json (what was built and how) and tiny11.iso.sha256. Logs go to logs\.

Requirements

  • Windows 10 or 11 (x64 or ARM64) and an administrator account.
  • Windows PowerShell 5.1 (powershell.exe, built into Windows) or PowerShell 7 (pwsh.exe, including the Microsoft Store build). Under PowerShell 7 the in-box DISM module fails on mounted images ("Class not registered"), so the builder loads it through the Windows PowerShell compatibility session automatically; nothing to configure.
  • About 25 GB free on an NTFS drive: 1.5 × the image size, at least 20 GB. The GUI shows the free space and warns before you start.
  • oscdimg.exe is taken from the Windows ADK if installed. Otherwise it is downloaded before image work and retained in tools\oscdimg\2.56, from Microsoft's symbol server and verified against a pinned SHA-256.

The GUI

tiny11gui.ps1 (option 1 of LAUNCH_TINY11.bat) exposes the common build choices. -WorkDirectory is currently CLI-only. Compression engine/effort/thread settings can be stored in profiles and forwarded, but do not have dedicated visible controls.

  • It remembers your last settings in gui-settings.json (never the password).
  • Save profile / Load profile stores a whole configuration, so you can rebuild it for every new Windows release in two clicks.
  • Everything maps 1:1 to the command line; the Build tab shows the exact command.
Tab What you set
1 Source ISO file or drive; edition list with build, architecture, language and size; Standard or Core builder; output ISO; work drive (with free space); compression; quick test build; boot without "Press any key"; dry run
2 Preset & features Preset, plus each of its 22 flags as a checkbox (hover for details). Changed flags become a custom preset automatically. Load and save preset files.
3 Apps The full removal list by category (uncheck to keep an app), your own package prefixes, import/export of lists, the optional apps to keep, and "keep everything".
4 Tweaks All 28 registry tweak groups and what enables each. Uncheck to skip a group; check a greyed one to turn on its flag. Every value of the selected group is shown.
5 Setup & account Local admin and password, or create the account in OOBE. Language/keyboard, time zone, computer name, zero-touch install, custom answer file. Preview or save the generated autounattend.xml.
6 Extras .NET 3.5, a driver folder (the .inf files are counted), a browser, payload scripts, the low-RAM profile, no driver updates, and the Defender exclusion on the build PC.
7 Build Plan, checks and the equivalent command line. During the build: overall and current-step progress, elapsed time, rough total ETA and measured step ETA when enough progress is available, a colour-coded log, Cancel, logs and output buttons. Steps without a measurable percentage show an animated bar.
Source Preset & features
Apps Tweaks
Setup & account Extras

The build runs as a hidden, non-interactive PowerShell process of the same edition as the GUI (powershell.exe or pwsh.exe). Its arguments go through a temporary file that is deleted immediately, so a password never appears on a command line.


Standard or Core

Standard — tiny11maker.ps1 Core — tiny11Coremaker.ps1
For PCs, laptops, long-lived VMs disposable VMs, test rigs, CI
Windows Update, language packs, features keep working impossible after the build
Defender retained by Default; configurable offline policies removed/disabled by Core choices
WinRE / "Reset this PC" kept removed
WinSxS cleaned (/StartComponentCleanup /ResetBase) rebuilt with only the servicing stack
Edge WebView2 kept (removed only with Minimal-VM) removed
Default preset Default Minimal-VM

Presets

A preset is a set of on/off flags (presets/*.json). The tweak matrix shows which registry groups each preset applies, and docs/APPS.md shows which apps depend on the preset.

Preset For Compared with Default
Default everyone Removes bloat apps, Edge, OneDrive and AI features; telemetry off. Keeps the Store, Defender, WebView2 and Mark-of-the-Web.
Gaming gaming PCs Keeps the Xbox app, Game Bar and Xbox sign-in. Adds the Ultimate Performance power plan, raw mouse input, fast shutdown and firewall rules that block telemetry.
PrivacyPlus privacy first Adds firewall rules that block telemetry and fast shutdown. Defender stays on but sends no cloud reports or samples.
Minimal-VM lab VMs Also removes the Store, WebView2 and Defender (no antivirus), and turns off Mark-of-the-Web.

To make your own preset, change the checkboxes in the GUI and click Save as preset, or copy a JSON file. Then use it with -Preset .\my-preset.json. Missing flags inherit from Default.


Command line

Both builders share the main options. -LowRam, -DisableDriverUpdates and -Custom are Standard-only CLI parameters; Core does not accept them. Core asks about .NET 3.5 when run interactively. Run Get-Help .\tiny11maker.ps1 -Full for the built-in help.

# Check everything first, build nothing
.\tiny11maker.ps1 -ISO C:\iso\Win11.iso -Edition Pro -DryRun

# Gaming preset, keep Paint and Snipping Tool, install Firefox at first sign-in
.\tiny11maker.ps1 -ISO E -Edition Pro -Preset Gaming -Keep Paint,SnippingTool -Browser Firefox -Yes

# Unattended VM install that WIPES DISK 0, with a UK locale and a named account
.\tiny11maker.ps1 -ISO E -Edition Pro -ZeroTouch -User Alice -Password "S3cret!" `
    -Locale en-GB -TimeZone "GMT Standard Time" -ComputerName TINY11-VM -Yes

# Smallest possible image for throw-away VMs
.\tiny11Coremaker.ps1 -ISO E -Edition Pro -Yes

Source and output

Option Meaning
-ISO <path|letter> A Windows 11 .iso file, or the drive letter of a mounted ISO or USB stick
-Edition <name> / -Index <n> The edition to build, e.g. Pro, Home, "Windows 11 Pro N" (the exact name or its last word), or its index
-SCRATCH <letter> NTFS drive for the legacy root work folders (default: the scripts' drive)
-WorkDirectory <absolute folder> CLI-only isolated work root; new or empty local NTFS folder. Overrides work-root placement, but shared hive aliases still require one build at a time.
-OutputIso <path> Where to write the ISO
-Compress maximum|balanced|fast|none maximum (default) writes install.esd, the smallest ISO; the others write install.wim
-CompressionEngine Auto|Wimlib|Dism Auto prefers the portable pinned wimlib compressor; DISM is available as a fallback
-CompressionLevel <1-200> wimlib compression effort; 100 (high) by default
-CompressionThreads <n> Zero (default) chooses threads based on CPU and memory; no host priority settings are changed
-Fast Fast compression and no component cleanup (quick test builds)
-NoPrompt The ISO boots straight into Setup without "Press any key" (implied by -ZeroTouch)

maximum means solid LZMS compression; balanced means LZX. The old recovery and max spellings remain accepted for existing commands and saved profiles. DISM's API still requires those historical names internally. Maximum compression is applied once, at the end. The initial edition export reuses ordinary WIM compressed resources where possible; solid ESD sources are converted to a standard WIM for servicing. See performance measurements and dependency audit. The build bug investigation records reproduced failures, upstream size/Setup regressions, safeguards and the limits of current verification.

What is removed

Option Meaning
-Preset <name|file.json> Default, Gaming, PrivacyPlus, Minimal-VM, or your own JSON file
-Keep a,b / -Remove a,b Optional apps: Terminal, Calculator, Notepad, Photos, Paint, Camera, SoundRecorder, StickyNotes, Clock, MediaPlayer, MoviesTV, SnippingTool
-KeepApps Remove no provisioned app at all
-PackageList <file> Your own list instead of removePackage.txt
-Custom Pick the apps to remove interactively in the console (and decide on Edge and OneDrive)
-SkipTweak Id1,Id2 Leave out tweak groups; the ids are in docs/TWEAKS.md
-LowRam Extra trimming for 1–2 GB PCs (Windows Update and Defender untouched)
-DisableDriverUpdates Windows Update will not install drivers

What is added

Option Meaning
-EnableNetFx3 Enable .NET Framework 3.5 from the ISO
-DriverPath <folder> Inject .inf drivers into Windows and into Setup (e.g. Intel RST/VMD, so Setup can see the disk)
-Browser Firefox|Chrome Silent install at the first sign-in; waits for the network
-Payload Run your scripts from payload\packages at the end of Setup (details)

Installation and first start (built into the ISO's answer file)

Option Default Meaning
-User / -Password User / empty Local administrator created by Setup, signed in automatically once. The password is stored Base64-obfuscated, and the answer files are deleted after the first sign-in.
-InteractiveOobe off Create no account; Windows asks for a local user name instead
-Locale xx-YY ask in OOBE Language, region and keyboard (e.g. de-DE); skips those setup pages
-TimeZone <id> UTC Any id from tzutil /l, e.g. "W. Europe Standard Time"
-ComputerName <name> random 1–15 letters, digits or -
-ZeroTouch off Wipes disk 0 and installs with no questions (UEFI/GPT). For VMs and test PCs.
-UnattendFile <xml> — Your own answer file; its image index is pointed at the exported edition

Build behaviour

Option Meaning
-DryRun Validate and print the plan without image patch/export/mastering. Writes logs and may attach/release the source; legacy stale-state cleanup can occur without WorkDirectory.
-Yes Never prompt. Needs -ISO, and -Edition/-Index for multi-edition ISOs
-DefenderExclusion Temporarily exclude the work folders from this PC's Defender scan; removed at the end

In PowerShell, lists work as -Keep Paint,Camera; from cmd, write -Keep "Paint,Camera".


What a build does

  1. Normalizes/validates options and loads the servicing prerequisites. A real build prepares the ISO writer early, before long image work; a dry run skips its download.
  2. Resolves the source, selects the actual edition and records source metadata. Source/work-tree overlap is rejected. Prefer a fresh isolated -WorkDirectory for manual runs; legacy root layout includes stale-state recovery and is not safe alongside another writer.
  3. Tests a disposable offline hive before copying/mounting, copies setup media excluding the original install image, and exports only the chosen source edition. Ordinary WIM resources can be reused without re-encoding; solid ESD becomes a mountable WIM.
  4. Mounts the image and performs planned app/capability/Edge/OneDrive changes and optional .NET/driver injection. Core also reduces component packages, WinRE and WinSxS.
  5. Loads owned offline hives, applies the tweak catalog and removes offline telemetry tasks. SYSTEM template paths follow the image's Select\Default; denied DWORDs receive verified file-only repair after unload.
  6. Stages generated/custom answer files and SetupComplete/FirstLogon hooks, applies normal component cleanup unless skipped, then commits/unmounts.
  7. Exports the final selected compression format once and validates actual source edition/language/product metadata. Only missing source-derived fields may be restored via supported wimlib operations; conflicts fail.
  8. Patches small Setup hive files without a boot mount where supported; driver/fallback servicing uses a separate boot mount. Writes the final answer file.
  9. Refuses duplicate/intermediate installation images, masters the ISO with the prepared Oscdimg path, hashes it and writes JSON/SHA sidecars. Releases owned attachments and cleans safe work folders.

Failure and GUI Cancel attempt cleanup. If dismount fails or mount state is unknown, image files are retained. Check the actual state before any replacement; cleanup is not guaranteed, separate folders are not a global concurrency lock, and counted warnings need inspection. See PROJECT_GUIDE.md for the complete mechanism and BUILD_BUG_REPORT.md for unresolved failures.


After installing

  • Setup creates your account and signs in once automatically, unless you chose to create the account in OOBE.
  • Software: winget (App Installer) is always kept, e.g. winget install Mozilla.Firefox 7zip.7zip VideoLAN.VLC.
  • Logs on the installed system: C:\Windows\Setup\Tiny11\setupcomplete.log and firstlogon.log.
  • Undoing a tweak: every value is listed in docs/TWEAKS.md. Most are policies under HKLM\SOFTWARE\Policies; delete the value to restore the Windows default.
  • Getting Edge back: delete HKLM\SOFTWARE\Policies\Microsoft\EdgeUpdate, then run winget install Microsoft.Edge.

Customising

What Where
Apps removed by default removePackage.txt, one package-name prefix per line (or the Apps tab)
Optional apps and their defaults Get-OptionalUtilities in lib/tiny11utils.psm1
Registry tweaks data/tweaks.psd1: add a value to a group, or a new group with a When flag
Presets presets/*.json, or Save as preset in the GUI
Scripts run after Setup payload/packages/ with -Payload
Browser installers Browsers/

After editing the catalog, the presets or the answer-file generator, run .\scripts\update-generated.ps1. It refreshes docs/TWEAKS.md, docs/APPS.md, the reference answer files and the module manifests.


Troubleshooting

Symptom Fix
Hive unload / commit failure Stop the owned writer and close handles into the offline work folder. Verify owned mounts/hives before retrying; preserve image files if dismount/state is unsafe. See the bug report.
"Filename or extension is too long" during hive load A 33-character path still failed in controlled tests; CIM launching succeeded, but the Windows cause is unresolved. The early hive preflight detects it. See the launch-context investigation; do not change host security settings.
Slow build / apparently stalled percentage Consult stage logs and PERFORMANCE.md. Maximum LZMS dominated the measured run; overall percentage/ETA is approximate. Do not overlap DISM writers or change this session's host settings.
"Load editions" fails The ISO must contain sources\install.wim or install.esd. Editions are read through the bundled UDF/ISO9660 reader, without elevation, mounting, downloads or cached guesses. Malformed, encrypted or split images need suitable source media.
Setup rejects product-key/edition validation Verify the chosen edition, source-derived final XML and any custom answer file. A successful build alone cannot rule out the upstream metadata failure. Firmware keys/activation depend on the target and matching edition.
Setup cannot see the disk (Intel VMD/RST laptops) Point the drivers folder at the extracted Intel RST "F6" drivers.
The ISO does not boot on an old BIOS PC x64 ISOs boot on BIOS, but zero-touch partitions for UEFI/GPT. Install interactively instead.
Anything else Run a dry run, then read the log in logs\. It records every value written.

Project layout

LAUNCH_TINY11.bat         Menu launcher (GUI / Standard / Core), elevates itself
Run.bat                   Runs tiny11maker.ps1 with your arguments
tiny11gui.ps1             Graphical builder (every option, live build log)
tiny11maker.ps1           Standard (serviceable) builder
tiny11Coremaker.ps1       Core (minimal, non-serviceable) builder
tiny11LegacyProfile.ps1   Compatibility shim for the old low-RAM profile
removePackage.txt         Apps removed by default
autounattend*.xml         Reference answer files (generated)
data/tweaks.psd1          Registry tweak catalog, the single source of truth
presets/*.json            Build presets
lib/tiny11utils.psm1      Build library: DISM/registry helpers, catalog engine, answer-file
                          generator, removal planning, shared build stages, ISO creation
lib/tiny11gui.psm1        Windows Forms window, state -> builder arguments, build runner
lib/tiny11media.psm1      Read-only bundled optical/WIM metadata reader
lib/OfflineRegistry.cs   File-only protected image-hive DWORD repair
data/reference-repos.json Exact reference URLs and branches
payload/                  Your post-install scripts (-Payload)
Browsers/                 Browser installers run at the first sign-in (-Browser)
docs/                     Handoff/architecture/verification and detailed reports; generated catalogs
docs/verification/        Compact dated measurement/audit evidence
scripts/                  Tests, parse check, linter, generators, test fixtures
repos/                    Reference forks (git-ignored, for study only)

Development

.\scripts\parse-check.ps1         # every file parses, every command resolves
.\scripts\test-core-helpers.ps1   # ~1,900 checks, no admin rights and no ISO needed
.\scripts\test-media-progress.ps1 # real ISO metadata/progress fixtures
.\scripts\test-export-pipeline.ps1 # real small WIM/ESD fixtures
.\scripts\update-generated.ps1    # docs, reference answer files, manifests (-Check fails if stale)
.\scripts\linter.ps1              # PSScriptAnalyzer, high-signal rules
.\scripts\update-screenshots.ps1  # re-render docs\gui-*.png (window-only rendering)

The tests cover:

  • every catalog entry and the presets;
  • the generated and reference answer files, checked against an allow-list of real unattend settings (one unknown element makes Windows Setup abort);
  • app, capability and package removal planning;
  • the build stages, run against mocked DISM and registry functions;
  • the GUI logic, the build launcher, and the whole window driven end to end with a fake builder that never touches the system.

CI checks both Windows PowerShell 5.1 and PowerShell 7. A real ISO build needs admin rights and a Windows ISO: test those changes in a VM (dry run first) and mention the build you used in the pull request. See CONTRIBUTING.md and CHANGELOG.md.


History and credits

main holds the complete history of ntdevlabs/tiny11builder (100 commits), followed by the 2026 edition as regular commits, so every change can be traced back to the original with git log / git blame.

Ideas and fixes were studied in these projects and selectively adapted (code is downloaded under repos/). The tracked reference list, refresh script and comparison report record all 21 checkouts, exact branches and revisions:

Project Ideas used
ntdevlabs/tiny11builder The original: offline debloat, hardware bypass, answer file
chrisGrando/tiny11maker-reforged GUI, launcher, ISO auto-mount, final install.esd export
vinisebold/tiny11builder-revamped Shared module, TaskCache ACL takeover, cleanup trap, app selector
zPoche/tiny11builder-v2 Pre-flight checks, dry run, quick builds, ARM64, the mount-folder fix
YmlyZA/tiny11builder Tests, linter, build summary, keep/remove utilities, zero-touch
namnguyen97x/tiny-auto-builder Presets, driver injection, retrying dismount/unload
bluecloud122/tiny11builder Low-RAM profile, ISO sanity checks
MOPELotus/tiny11builder Payload / SetupComplete design, OOBE page tweaks, stale-state recovery
SamHimmy/tiny11builder 24H2/25H2 AI, Recall and Widgets policies
keepitupkitty/tiny11builder Paint/Notepad AI policies, Edge and OneDrive leftovers
user129233/tiny11builder Specialize-pass commands, answer-file cleanup after sign-in
DFveloper/DFwindows11_builder Browser installers, language-independent ACL handling
prismatecas-ui/tiny11builder GUI option ideas, installed-apps inventory
bedlaj/tiny11builder ADK lookup through the registry
AhmedLolyProductions/Loly11 Package-list entries
u0reo/tiny11builder, feature/25h2-patch Cloud-search policy; broader removals/raw XML repair reviewed selectively
luyingwei80/tiny11builder, Tony-patch-multi Multiple-edition deployment reference; retain our single-edition default
pi0n00r/tiny11builder, deployment/2026-26h2 Offline default control-set selection and source/workspace separation
391546581/tiny11builder CI workflows studied; original builder code unchanged
icis-org/tiny11builder Build workflow studied; original builder code unchanged
lexp-hub/tiny11builder.sh Linux/macOS port studied; file-only boot-update idea already covered

License

MIT, see LICENSE. Windows is a trademark of Microsoft. This project ships no Microsoft files; you supply your own ISO.

About

Scripts to build a trimmed-down Windows 11 image.

Resources

Contributing

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages