Open-source project
mandiant/flare-vm avatar
mandiant/flare-vm

FLARE-VM: a scripted Windows reverse engineering environment

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

9,078 stars1,119 forksPowerShellApache-2.0

At a glance

What is it?
FLARE-VM installs and maintains a curated set of malware analysis and reverse engineering tools on a Windows VM using Chocolatey and Boxstarter. It is a machine image builder, not a portable toolkit, and it expects a disposable VM with Defender and Windows Update turned off.
Who is it for?
Adopt FLARE-VM if you want a repeatable Windows analysis VM and you are willing to run it on a throwaway guest with Defender, Tamper Protection and Windows Update disabled, at least during installation. Do not install it on a daily-driver Windows machine, and do not expect it to work with antivirus left on: the installer's own validation checks exist because those settings break package installs.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 100 days ago.
What is it written in?
Mainly PowerShell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What FLARE-VM solves for malware analysts

Assembling a Windows reverse engineering workstation by hand is a curation problem before it is a technical one. You need a disassembler, a debugger, a PE parser, unpackers, a hex editor, Python tooling, and a set of analysis utilities that do not fight each other. Installing them one at a time means tracking download pages, versions, install paths and environment variables, and repeating the whole exercise whenever the VM is rebuilt. FLARE-VM addresses that by describing the environment as a list of packages plus a set of environment variable paths, and letting an installer reproduce it.

The intended audience is narrow and the README is explicit about it: FLARE-VM should only be installed on a virtual machine. That is not a stylistic preference. The project asks you to disable Tamper Protection and any anti-malware solution, preferably through Group Policy, and to disable Windows Updates at least until installation finishes. Those are reasonable settings inside a disposable analysis guest and unacceptable on a machine you use for anything else. If you are looking for a toolkit you can drop onto a working laptop and use alongside your normal software, this is the wrong shape of project.

Chocolatey packages, Boxstarter reboots and a config.xml

The mechanism rests on two existing Windows tools. Chocolatey is a NuGet-based package manager where a package is essentially a ZIP file containing PowerShell installation scripts that download and configure a specific tool. Boxstarter sits on top of Chocolatey packages to automate software installation and to create repeatable, scripted Windows environments, which is where reboot resiliency comes from: many analysis tools install drivers or shell extensions and want a restart mid-run.

What the user actually edits is config.xml, downloaded from the repository by default. It holds the list of packages to install and the environment variable paths. A second file, CustomStartLayout.xml, defines the taskbar layout. Both can be replaced with your own file path or URL through -customConfig and -customLayout, so the environment definition is a text artifact you can diff and store rather than a sequence of manual clicks. The installer also ships a GUI, shown after validation checks and after Boxstarter and Chocolatey are installed if they are not already present, where package selection from FLARE-VM and the Chocolatey community can be adjusted. The CLI-only path skips that GUI.

One detail worth knowing before you start: the README notes that items listed in the layout XML which are not installed simply do not appear in the taskbar, so a trimmed package list does not produce broken shortcuts.

Installing FLARE-VM on a Windows 10 or 11 VM

The requirements come first, because the installer checks them. A Windows 10 or later guest, PowerShell 5 or later, at least 60 GB of disk, at least 2 GB of memory, a username without spaces or special characters, an internet connection, and Defender, Tamper Protection and Windows Update disabled. Take a VM snapshot before you begin so you can revert to a clean state.

Open an administrator PowerShell prompt and pull the installer to the Desktop. The README gives this exact command:

bash
(New-Object net.webclient).DownloadFile('https://raw.githubusercontent.com/mandiant/flare-vm/main/install.ps1',"$([Environment]::GetFolderPath("Desktop"))\install.ps1")

Then unblock the downloaded file and allow script execution. The second command is required because the file arrives with the mark-of-the-web:

bash
Unblock-File .\install.ps1
Set-ExecutionPolicy Unrestricted -Force

If the execution policy is overridden at a more specific scope, the README suggests passing a scope, for example Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force, and Get-ExecutionPolicy -List to inspect all scopes. Finally, run the installer. Passing the password lets Boxstarter survive reboots; -noWait and -noGui keep it non-interactive:

bash
.\install.ps1 -password <password> -noWait -noGui

For a custom package list, add -customConfig with a local path or a URL:

bash
.\install.ps1 -customConfig "https://raw.githubusercontent.com/mandiant/flare-vm/main/config.xml"

After installation the README recommends switching the VM to host-only networking and taking another snapshot. If you plan to install IDA Pro through the idapro.vm package, place the installer and optionally the license file on the Desktop before running install.ps1; the installer does not fetch them for you.

Where FLARE-VM gets in the way

The heaviest constraint is the security software requirement. Disabling Defender and Tamper Protection is a prerequisite, not a troubleshooting step, and the installer's -noChecks flag exists to skip validation checks that would otherwise stop it. That flag is documented as not recommended, and the reason is plain: skipping the checks moves the failure from a clear message to a half-installed package list.

There is no documented rollback. The README never describes an uninstall path, an undo command, or a way to return a guest to its pre-FLARE-VM state. The snapshot you are told to take before installation is the rollback mechanism. That makes the disk cost real: two snapshots plus 60 GB of tools means provisioning generously.

Disk and network are the other hard edges. A minimum of 60 GB and 2 GB of memory is a floor, and the installation downloads packages from Chocolatey and elsewhere, so an offline or heavily filtered network will fail partway. The README also does not document what happens when a single Chocolatey package fails mid-run, which is the failure mode most likely to cost you an afternoon.

Finally, FLARE-VM is not a sandbox. It builds an analysis environment inside a VM; it does not contain malware for you. Isolation depends on the hypervisor configuration and the host-only networking switch the README recommends after installation.

FLARE-VM against REMnux and a hand-built VM

The closest alternative for a scripted analysis environment is REMnux, which solves the same curation problem on Linux rather than Windows. The difference is not cosmetic: a large part of the Windows reverse engineering toolchain, including the debuggers and the commercial disassemblers people install through idapro.vm, only exists on Windows, so REMnux is a complement for network and document analysis rather than a drop-in replacement for FLARE-VM. If your work is primarily Linux ELF binaries or malicious documents, REMnux covers that ground without asking you to disable Defender.

The other alternative is building the VM yourself. That gives you full control over what is installed and no dependency on Chocolatey package definitions, at the cost of redoing the curation every time the VM is rebuilt and of tracking environment variable paths by hand. FLARE-VM's value is precisely that config.xml turns that into a reviewable file. If your environment changes rarely and you already have a documented image, the installer adds a dependency on Boxstarter's reboot handling that you may not need.

Maintenance, licence and upgrade cost

The repository is not archived, and the last push was on 2026-06-23. The most recent release listed is vbox-1.0.0 from 2025-08-13, which is a VirtualBox-related artifact rather than a version of the tool set itself; FLARE-VM does not appear to follow a numbered release cadence for the package list, so tracking the main branch and your config.xml is how you follow changes.

Upgrades are cheap in the sense that the environment is defined by files, and expensive in the sense that the supported path is to rebuild the VM from a snapshot or from scratch. Because no uninstall or in-place upgrade procedure is documented, treat the guest as disposable and keep config.xml and your taskbar layout outside it.

The project is licensed under Apache-2.0, which permits commercial use and modification with the usual notice and attribution conditions. That covers the installer scripts in this repository. It does not cover the third-party tools the packages download, and those carry their own licences, several of which are commercial. IDA Pro is the obvious example: the README assumes you supply your own installer and license file. Check the licence of each package you enable in config.xml before you build an image for a team. This is a description of the licence terms, not legal advice.

Editorial conclusion

Adopt FLARE-VM if you want a repeatable Windows analysis VM and you are willing to run it on a throwaway guest with Defender, Tamper Protection and Windows Update disabled, at least during installation. Do not install it on a daily-driver Windows machine, and do not expect it to work with antivirus left on: the installer's own validation checks exist because those settings break package installs. Before committing, verify three things on your own image: that the Windows edition and build satisfy the Windows 10 or later requirement, that the account name has no spaces or special characters, and that the disk is provisioned at 60 GB or more. If those hold, the install is a single PowerShell script and a configuration XML you can keep under version control.

Frequently asked questions

What is FLARE-VM used for?

It sets up and maintains a reverse engineering environment on a Windows virtual machine, installing a curated collection of analysis tools. The README frames it as solving the problem of reverse engineering tool curation.

Is FLARE-VM free?

The FLARE-VM repository is licensed under Apache-2.0. Individual tools installed through Chocolatey packages have their own licences, and some are commercial, such as IDA Pro, for which the README expects you to supply your own installer and license file.

How do I install FLARE-VM?

Prepare a Windows 10 or later VM meeting the requirements, download install.ps1 to the Desktop, unblock it, set the execution policy to Unrestricted, and run .\install.ps1 as administrator. The README also documents -password, -noWait and -noGui for unattended installs.

How long does FLARE-VM take to install?

The README does not state an installation duration. It does note that reboots are handled through Boxstarter, that -noReboots is documented as not recommended, and that Windows Updates should stay disabled at least until installation finishes.

Can I install FLARE-VM on Windows 11?

Yes, the stated requirement is Windows 10 or later, so Windows 11 qualifies. The other requirements still apply, including PowerShell 5 or later, 60 GB of disk, a username without spaces, and Defender and Tamper Protection disabled.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. mandiant/flare-vm on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mandiant-flare-vm.svg)](https://hysenlabs.com/projects/mandiant-flare-vm)