awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
mandiant avatar

mandiant/flare-vm

0
View on GitHub↗
8,799 estrellas·1,094 forks·PowerShell·Apache-2.0·10 vistas

Flare Vm

Flare-VM es un entorno de análisis de malware para Windows que consiste en scripts de instalación que automatizan el aprovisionamiento de una máquina virtual. Proporciona un conjunto integral de herramientas de ingeniería inversa, incluyendo descompiladores y depuradores, junto con las configuraciones del sistema y variables de entorno necesarias para la investigación de seguridad.

El proyecto funciona como un orquestador de imágenes de máquinas virtuales, permitiendo la creación, gestión y exportación automatizadas de dispositivos de análisis especializados. Cuenta con selección de herramientas basada en configuración y la capacidad de extender la lógica de instalación mediante modificaciones personalizadas del registro y definiciones de diseño del sistema.

El sistema incluye capacidades para la configuración de red aislada para evitar la comunicación externa mediante el modo host-only. También gestiona el ciclo de vida completo de los estados de análisis mediante la gestión de estados basada en instantáneas, incluida la capacidad de limpiar o exportar instantáneas como archivos de dispositivo verificados.

Features

  • Malware Analysis Environments - Provides specialized Windows configurations tailored specifically for reverse engineering and malware threat research.
  • Reverse Engineering - Provides a curated environment tailored for disassembling and analyzing compiled binary code.
  • Internal Virtual Network Isolations - Isolates lab networks using host-only virtual switches to prevent malware from communicating with the internet.
  • Virtual Machine - Uses virtual machine snapshots to restore base states and export verified appliances for analysis.
  • Environment Setup Tools - Installs a curated suite of reverse engineering software, tools, and configurations to prepare the analysis VM.
  • Custom Container and VM Image Creation - Builds customized analysis environments by restoring snapshots, injecting files, and exporting the result as an appliance.
  • Image Orchestrators - Automates the creation, snapshot management, and export of specialized analysis appliances.
  • Automated Provisioning - Automates the installation and configuration of software and systems within a virtualized analysis environment.
  • Provisioning Scripts - Automates the installation of software and system configurations through a series of executable provisioning scripts.
  • Malware Analysis - Provides a secure environment and toolset for the reverse engineering and behavioral analysis of malicious software.
  • Network Isolation - Implements network isolation to prevent analyzed malware from communicating with external networks via host-only mode.
  • Reverse Engineering Toolsets - Installs a comprehensive curated collection of software configured for analyzing binaries and malicious code.
  • Virtual Machine Snapshots - Includes capabilities to capture and restore virtual machine states to maintain clean analysis environments.
  • VM Appliance Exports - Converts specific snapshots into appliance files with host-only network interfaces and verification hashes.
  • Tool Selection Configuration - Provides a configuration system to select specific software packages and environment variables during the VM setup process.
  • Post-Installation Extensions - Runs a sequence of custom scripts and service modifications after the primary software installation is complete.
  • Windows Registry Modifications - Modifies Windows registry keys to alter system behavior and file extension visibility during environment setup.
  • Connection Auditing - Checks internet adapter status across virtual machines to ensure they are restricted to host-only mode.
  • Installation Logic Overrides - Allows adding custom installation steps such as registry modifications and service changes via configuration files.
  • Security Lab Environments - Windows-based distribution for malware analysis and reverse engineering.
  • Digital Forensics - Windows-based security distribution for malware analysis.
  • System Hardening Guides - Automates the deployment of security analysis tools on workstations.

Historial de estrellas

Gráfico del historial de estrellas de mandiant/flare-vmGráfico del historial de estrellas de mandiant/flare-vm

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a Flare Vm

Proyectos open-source similares, clasificados según cuántas características comparten con Flare Vm.
  • fireeye/flare-vmAvatar de fireeye

    fireeye/flare-vm

    8,768Ver en GitHub↗

    Flare-VM is a collection of scripts and an orchestrator designed to automate the installation and configuration of a reverse engineering toolset on Windows virtual machines. It functions as a provisioning system that deploys a consistent environment for malware analysis and security research on guest operating systems. The project utilizes a configuration manager and a graphical interface to allow for the selection of specific software packages and environment variables. It employs a curated manifest to manage the installation of compatible security tools and modifies system registries and ta

    PowerShell
    Ver en GitHub↗8,768
  • cuckoosandbox/cuckooAvatar de cuckoosandbox

    cuckoosandbox/cuckoo

    5,959Ver en GitHub↗

    Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual machines and produces structured behavioral reports. The platform captures system calls, file operations, and network activity during execution, compiling them into comprehensive analysis documents for programmatic consumption. The system operates through a modular analysis pipeline that processes behavioral data, applying YARA signature patterns against captured artifacts to identify known malware families. Each analysis run starts from a clean virtual machine snapshot to ensure

    JavaScript
    Ver en GitHub↗5,959
  • orange-cyberdefense/goadAvatar de Orange-Cyberdefense

    Orange-Cyberdefense/GOAD

    7,464Ver en GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    PowerShellactive-directoryansibleinfrastructure-as-code
    Ver en GitHub↗7,464
  • mentebinaria/retoolkitAvatar de mentebinaria

    mentebinaria/retoolkit

    5,222Ver en GitHub↗

    Retoolkit is a reverse engineering tool orchestrator and malware analysis environment provisioner for Windows. It functions as a binary analysis workflow automator that installs and configures the specialized software toolchains required for security research. The project manages the execution and lifecycle of standalone analysis binaries through a registry-based Windows shell context menu. This integration allows users to launch external tools directly from the file system right-click menu by passing selected file paths as command line arguments to third-party executables. The system covers

    Inno Setupinno-setupmalware-analysisreverse-engineering
    Ver en GitHub↗5,222
Ver las 30 alternativas a Flare Vm→

Preguntas frecuentes

¿Qué hace mandiant/flare-vm?

Flare-VM es un entorno de análisis de malware para Windows que consiste en scripts de instalación que automatizan el aprovisionamiento de una máquina virtual. Proporciona un conjunto integral de herramientas de ingeniería inversa, incluyendo descompiladores y depuradores, junto con las configuraciones del sistema y variables de entorno necesarias para la investigación de seguridad.

¿Cuáles son las características principales de mandiant/flare-vm?

Las características principales de mandiant/flare-vm son: Malware Analysis Environments, Reverse Engineering, Internal Virtual Network Isolations, Virtual Machine, Environment Setup Tools, Custom Container and VM Image Creation, Image Orchestrators, Automated Provisioning.

¿Qué alternativas de código abierto existen para mandiant/flare-vm?

Las alternativas de código abierto para mandiant/flare-vm incluyen: fireeye/flare-vm — Flare-VM is a collection of scripts and an orchestrator designed to automate the installation and configuration of a… cuckoosandbox/cuckoo — Cuckoo is an open-source automated malware analysis system that executes suspicious files inside isolated virtual… orange-cyberdefense/goad — GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of… mentebinaria/retoolkit — Retoolkit is a reverse engineering tool orchestrator and malware analysis environment provisioner for Windows. It… vxunderground/malwaresourcecode — This project is a curated archive and cybersecurity research dataset of raw source code from various malware families.… hasherezade/pe-sieve — pe-sieve is a set of diagnostic tools for scanning Windows process memory to identify malicious implants, shellcode,…