# mandiant/ThreatPursuit-VM

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.

Repository: https://github.com/mandiant/ThreatPursuit-VM
Canonical: https://ross.abutalabs.com/products/threatpursuit-vm
Language: PowerShell
License: NOASSERTION
License Family: other
Topics: cyber, threat, threatintelligence, threathunting, intelligence, intelligence-analysis, data-science, analytics, malware, virtual-machine, mandiant, fireeye
Archived: true
Last push: 2023-06-01T13:37:21+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2177, "days_push": 1189, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1306, forks 262 (observed 2026-08-28T04:04:18.917542+00:00)

## What it is
ThreatPursuit-VM is an open-source Windows-based virtual machine distribution from Mandiant preloaded with tools for threat intelligence analysis, threat hunting, and malware triage. It is installed via a PowerShell/Boxstarter script that configures a Windows 10 VM with analytics, visualization, and hunting tooling.

## Use cases
- set up a threat intelligence analysis workstation quickly
- build a malware analysis VM for threat hunting
- get a preconfigured Windows VM with MISP, OpenCTI, and Maltego
- stand up a hunting environment with Jupyter, Elasticsearch, and Splunk
- customize a Windows security analyst VM with an install script

## When to choose
- you are an intel or malware analyst needing a ready-made Windows tooling environment
- you want a customizable, scriptable alternative to prebuilt security VM images
- you need threat hunting tools like MISP, OpenCTI, Maltego, and Splunk in one VM

## When to avoid
- you need a Linux-based malware analysis distribution like FLARE-VM alternatives or REMnux
- you require actively maintained tooling - the last release was mid-2023
- you cannot run Windows 10 VMs with 120+ GB disk and virtualization support

## Facets
- artifact type: application
- maturity: maintenance
- function: security, developer-tools, data-science, analytics, search-engine, machine-learning
- domain: security, osint, windows
- platform: windows, self-hosted
- tags: threat-intelligence, threat-hunting, malware-analysis, virtual-machine, boxstarter, powershell, security-distribution, mandiant, docker

## Member repositories
- mandiant/ThreatPursuit-VM (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:18.917542+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:50:58.496969+00:00, confidence not recorded.
  - readme: https://github.com/mandiant/ThreatPursuit-VM (fetched 2026-08-28T04:04:18.917542+00:00, sha 484a510c3de9)
- Data as of 2026-08-30T08:39:29.467469+00:00.
