MANDIANT's repositories
commando-vm
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
flare-floss
FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
flare-fakenet-ng
FakeNet-NG - Next Generation Dynamic Network Analysis Tool
stringsifter
A machine learning tool that ranks strings based on their relevance for malware analysis.
capa-rules
Standard collection of rules for capa: the tool for enumerating the capabilities of programs
macos-UnifiedLogs
A cross platform parser for Apple UnifiedLogs!
VM-Packages
Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.
GeoLogonalyzer
GeoLogonalyzer is a utility to analyze remote access logs for anomalies such as travel feasibility and data center sources.
gostringungarbler
Python tool to resolve all strings in Go binaries obfuscated by garble
gocrack-ui
The User Interface for GoCrack
gootloader
Collection of scripts used to deobfuscate GOOTLOADER malware samples.
poisonplug-scatterbrain
Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator
capa-testfiles
Data to test capa's code and rules.
flare-gsoc
Supporting resources and documentation for FLARE @ Google Summer of Code 2025
flare-floss-testfiles
Resources for testing FLOSS by the FLARE team.