FLARE VM
Windows-based virtual machine distribution for malware analysis maintained by Mandiant.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with FLARE VM?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is FLARE VM?
FLARE VM is an open-source project designed to streamline the setup and maintenance of reverse engineering environments on virtual machines (VMs). It addresses the challenge of managing complex toolchains for cybersecurity professionals, malware analysts, and software developers by automating software installations and configurations. The tool leverages Chocolatey, a Windows package manager, and Boxstarter, a framework for scripting Windows environments, to create repeatable, reproducible setups. By centralizing the installation of tools like IDA Pro, GDB, and Volatility, FLARE VM reduces manual effort and ensures consistency across development and analysis workflows. Its primary users include reverse engineers, incident responders, and security researchers who require controlled, isolated environments for analyzing malicious code or debugging software. The project solves the problem of tool curation by providing a curated list of applications essential for reverse engineering tasks, eliminating the need to manually search for and configure each tool.
How it works
FLARE VM is a collection of PowerShell scripts and Chocolatey packages that automate the installation of reverse engineering tools on Windows-based VMs. It simplifies the creation of a standardized environment by integrating tools like Ghidra, Radare2, and WSL2, which are critical for analyzing binaries and network protocols. The project’s purpose is to eliminate the complexity of setting up a reverse engineering lab. By using Boxstarter to orchestrate installations, users can deploy a fully functional environment with minimal manual intervention, ensuring all dependencies are resolved automatically. FLARE VM supports the installation of core reverse engineering tools, including IDA Pro, GDB, and Volatility, alongside utilities for memory analysis, disassembly, and network monitoring. It also integrates Windows Subsystem for Linux (WSL2) to provide a Unix-like environment for scripting and analysis. The tool’s scripts handle dependency resolution, ensuring compatibility between applications and system components.
How to use it
- 1Download and install VirtualBox or VMware to host the VM. 2. Create a new VM with a Windows host system (e.g., Windows 10/11). 3. Mount the FLARE VM ISO file or run the installation scripts via PowerShell. 4. Execute the Boxstarter script to automate tool installation and configuration. 5. Reboot the VM to apply changes and verify tool availability. Practical tips: Ensure the VM has sufficient RAM (at least 4GB) and storage (20GB+). Use the latest Windows updates to avoid compatibility issues. Customize Chocolatey package sources if required for offline installations.
What it can do
- malware analysis VM
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/mandiant/flare-vm
- license: Apache-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Requires a Windows-based VM, limiting cross-platform compatibility
- Initial setup may take time due to the volume of tools and dependencies
- Manual intervention is needed for advanced customization beyond default configurations
- Lacks a graphical user interface (GUI) for non-technical users
Understanding the result
Windows-based virtual machine distribution for malware analysis maintained by Mandiant.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (Apache-2.0).
- Built with
- (mandiant/flare-vm)
- License
- Apache-2.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with mandiant/flare-vm. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- Apache-2.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Apache-2.0 License
Upstream project
Frequently asked
What is FLARE VM and who is it intended for?
FLARE VM is an open-source tool for automating reverse engineering environments on Windows VMs. It is intended for cybersecurity professionals, malware analysts, and developers who need consistent toolchains for analyzing binaries, debugging software, and researching vulnerabilities. The tool simplifies setup by integrating essential tools like IDA Pro, GDB, and Volatility into a single deployment process.
How does FLARE VM use Chocolatey and Boxstarter?
FLARE VM leverages Chocolatey, a Windows package manager, to download and install reverse engineering tools as preconfigured PowerShell scripts. Boxstarter then orchestrates these installations, ensuring dependencies are resolved and configurations are applied consistently across VMs. This combination allows users to deploy a standardized environment with minimal manual effort, even on systems without prior tool installations.
How do I install FLARE VM on a virtual machine?
First, install VirtualBox or VMware and create a new VM with a Windows host system. Download the FLARE VM ISO or run the installation scripts via PowerShell. Execute the Boxstarter script to automate tool installation, then reboot the VM. Ensure the VM has sufficient resources (4GB RAM, 20GB storage) and Windows updates installed for optimal performance.
How does FLARE VM compare to alternatives like Vagrant or Docker?
FLARE VM is specifically tailored for Windows-based reverse engineering tools, whereas Vagrant and Docker focus on broader VM and container management. Unlike Docker, which relies on Linux containers, FLARE VM provides native Windows tool support. Vagrant offers more flexibility for multi-platform setups but lacks the curated toolchain of FLARE VM. Both alternatives may require manual configuration for reverse engineering tasks.
What should I do if FLARE VM installation fails?
Common issues include permission errors during script execution or missing dependencies. Run PowerShell as an administrator to resolve permission problems. Verify internet connectivity for Chocolatey package downloads, and ensure Windows updates are installed. If specific tools fail, check the Chocolatey package logs for error details and manually install problematic components if needed.