Skip to content

Pinned Loading

  1. capa capa Public

    The FLARE team's open-source tool to identify capabilities in executable files.

    Python 5.8k 661

  2. flare-vm flare-vm Public

    A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

    PowerShell 8.4k 1.1k

  3. flare-floss flare-floss Public

    FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

    Python 3.9k 521

  4. commando-vm commando-vm Public

    Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

    PowerShell 7.5k 1.3k

  5. Vulnerability-Disclosures Vulnerability-Disclosures Public

    C++ 214 69

Repositories

Showing 10 of 101 repositories
  • GoReSym Public

    Go symbol recovery tool

    mandiant/GoReSym’s past year of commit activity
    Go 934 MIT 94 9 (1 issue needs help) 2 Updated Feb 26, 2026
  • capa Public

    The FLARE team's open-source tool to identify capabilities in executable files.

    mandiant/capa’s past year of commit activity
    Python 5,842 Apache-2.0 661 234 (7 issues need help) 30 Updated Feb 26, 2026
  • capa-rules Public

    Standard collection of rules for capa: the tool for enumerating the capabilities of programs

    mandiant/capa-rules’s past year of commit activity
    694 Apache-2.0 221 121 (6 issues need help) 11 Updated Feb 26, 2026
  • speakeasy Public

    Windows kernel and user mode emulation.

    mandiant/speakeasy’s past year of commit activity
    Python 1,859 MIT 275 43 (7 issues need help) 4 Updated Feb 26, 2026
  • VM-Packages Public

    Chocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.

    mandiant/VM-Packages’s past year of commit activity
    PowerShell 217 Apache-2.0 95 109 17 Updated Feb 26, 2026
  • mandiant/Vulnerability-Disclosures’s past year of commit activity
    C++ 214 69 0 0 Updated Feb 25, 2026
  • dncil Public

    The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.

    mandiant/dncil’s past year of commit activity
    Python 171 Apache-2.0 19 2 (1 issue needs help) 2 Updated Feb 23, 2026
  • flare-floss Public

    FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

    mandiant/flare-floss’s past year of commit activity
    Python 3,898 Apache-2.0 521 94 (2 issues need help) 20 Updated Feb 23, 2026
  • xrefer Public

    FLARE Team's Binary Navigator

    mandiant/xrefer’s past year of commit activity
    Python 308 Apache-2.0 41 9 5 Updated Feb 23, 2026
  • capa-testfiles Public

    Data to test capa's code and rules.

    mandiant/capa-testfiles’s past year of commit activity
    Max 47 Apache-2.0 82 0 4 Updated Feb 18, 2026