Back to rankings

mandiant/ThreatPursuit-VM

PowerShell

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.

cyberthreatthreatintelligencethreathuntingintelligenceintelligence-analysisdata-scienceanalyticsmalwarevirtual-machinemandiantfireeye
Star Growth
Stars
1.3k
Forks
260
Weekly Growth
โ€”
Issues
13
5001k
Oct 2020Sep 2022Aug 2024Jul 2026
README

      __   __                         __      
    _/  |_|  |_________  ____ _____ _/  |_    
    \   __|  |  \_  __ _/ __ \\__  \\   __\   
     |  | |   Y  |  | \\  ___/ / __ \|  |     
     |__| |___|  |__|   \___  (____  |__|     
     ______  __ _________ ________ __|___/  |
     \____ \|  |  \_  __ /  ___|  |  |  \   __\
     |  |_> |  |  /|  | \\___ \|  |  |  ||  |
     |   __/|____/ |__| /____  |____/|__||__|
     |__|                    \/

            MANDIANT THREAT INTELLIGENCE VM
                   Version 2020.1
              threatpursuit@fireeye.com

                     Created by:
                     Dan Kennedy
              Jake Barteaux @day1player
          Blaine Stancill @MalwareMechanic
                     Nhan Huynh
      Front Line Advanced Research and Expertise

Pre-Requisites

Google Chrome Browser

Oracle Java SE 11 or Greater

Installation (Install Script)

Requirements

  • Windows 10 1903
  • 120+ GB Hard Drive
  • 8+ GB RAM
  • 1 network adapters
  • 1024mb Graphics Card Memory
  • Enable Virtualization support for VM (Required for Docker)

Known Issues

Using Oracle Virtualbox as the virtualisation software running from a Windows 10 physical host, will cause issues with the Docker install. There is currently no workaround other than using VMware Player or VMware Workstation.

Instructions

Standard install

  1. Create and configure a new Windows Virtual Machine
  2. Ensure VM is updated completely. You may have to check for updates, reboot, and check again until no more remain
  3. Take a snapshot of your machine!
  4. Download and copy install.ps1 on your newly configured machine.
  5. Open PowerShell as an Administrator
  6. Unblock the install file by running Unblock-File .\install.ps1
  7. Enable script execution by running Set-ExecutionPolicy Unrestricted -f
  8. Finally, execute the installer script as follows: .\install.ps1 You can also pass your password as an argument: .\install.ps1 -password The script will set up the Boxstarter environment and proceed to download and install the ThreatPursuit VM environment. You will be prompted for the administrator password in order to automate host restarts during installation. If you do not have a password set, hitting enter when prompted will also work.

Installed Tools

Development, Analytics and Machine Learning

  • Shogun
  • Tensorflow
  • Pytorch
  • Rstudio
  • RTools
  • Darwin
  • Keras
  • Apache Spark
  • Elasticsearch
  • Kibana
  • Apache Zeppelin
  • Jupyter Notebook
  • MITRE Caret
  • Python (x64)

Visualisation

  • Constellation
  • Neo4J
  • CMAP

Triage, Modelling & Hunting

  • MISP
  • OpenCTI
  • Maltego
  • Splunk
  • Microsoft MSTIC Jupyter and Python Security Tools
  • MITRE ATT&CK Navigator
  • Cortex Analyzer
  • Greynoise API and GNQL
  • threatcrowd API
  • threatcmd
  • ViperMonkey
  • Threat Hunters Playbook
  • MITRE TRAM
  • SIGMA
  • YETI
  • Azure Zentinel
  • AMITT Framework

Adversarial Emulation

  • MITRE Calderra
  • Red Canary ATOMIC Red Team
  • Mordor Re-play Adversarial Techniques
  • MITRE Caltack Plugin
  • APTSimulator
  • FlightSim

Information Gathering

  • Maltego
  • nmap
  • intelmq
  • dnsrecon
  • orbit
  • FOCA
  • CyberChef
  • KeepPass
  • FLOSS
  • peview
  • VLC
  • AutoIt3
  • Chrome
  • OpenVPN
  • Sublime
  • Notepad++
  • Docker Desktop
  • HxD
  • Sysinternals
  • Putty
Related repositories
OpenCTI-Platform/opencti

Open Cyber Threat Intelligence Platform

TypeScriptnpmOthercybercti
opencti.io
9.7k1.4k
bee-san/pyWhat

๐Ÿธ Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! ๐Ÿง™โ€โ™€๏ธ

PythonPyPIMIT Licensecybersecurity
7.3k388
CarterPerez-dev/Cybersecurity-Projects

Building 70 Projects ranging from beginner to advanced so anyone can โ€” learn from, build upon, use as a reference, or even copy directly. Gamified Cybersecurity learning ๐Ÿ‘‡

GoGo ModulesGNU Affero General Public License v3.0aicertification
certgames.com
4.2k600
odedshimon/BruteShark

Network Analysis Tool

C#GNU General Public License v3.0hackingpcap-files
3.4k357
frankwxu/digital-forensics-lab

Free hands-on digital forensics labs for students and faculty

Jupyter NotebookOthercybersecuritydigital
github.com/frankwxu/digital-forensics-lab
2.9k607
eth0izzle/bucket-stream

Find interesting Amazon S3 Buckets by watching certificate transparency logs.

PythonPyPIMIT Licensecybercyint
darkport.co.uk
1.8k207
bee-san/Name-That-Hash

๐Ÿ”— Don't know what type of hash it is? Name That Hash will name that hash type! ๐Ÿค– Identify MD5, SHA256 and 300+ other hashes โ˜„ Comes with a neat web app ๐Ÿ”ฅ

PythonPyPIGNU General Public License v3.0hashinfosec
nth.skerritt.blog
1.7k110
mytechnotalent/Hacking-Windows

A FREE Windows C development course where we will learn the Win32API and reverse engineer each step utilizing IDA Free in both an x86 and x64 environment.

CApache License 2.0hackingwindows
1.6k143
HashPals/Name-That-Hash

๐Ÿ”— Don't know what type of hash it is? Name That Hash will name that hash type! ๐Ÿค– Identify MD5, SHA256 and 300+ other hashes โ˜„ Comes with a neat web app ๐Ÿ”ฅ

PythonPyPIGNU General Public License v3.0hashinfosec
nth.skerritt.blog
1.5k102
simeononsecurity/Windows-Optimize-Harden-Debloat

Enhance the security and privacy of your Windows 10 and Windows 11 deployments with our fully optimized, hardened, and debloated script. Adhere to industry best practices and Department of Defense STIG/SRG requirements for optimal performance and security.

PowerShellMIT Licensewindowsstig-compliant
simeononsecurity.com/github/optimizing-and-hardening-windows10-deployments/
1.4k98
blst-security/cherrybomb

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

Rustcrates.ioApache License 2.0blstfirecracker
1.2k84
devxprite/infoooze

A OSINT tool which helps you to quickly find information effectively. All you need is to input and it will take take care of rest.

JavaScriptnpmMIT Licenseosintosint-tool
infoooze.js.org
1.1k159