CommandoVM
PowerShell-provisioned Windows red-team toolkit
CommandoVM has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Last verified September 5, 2026
CommandoVM is a Windows-based red-team toolkit maintained by Mandiant (formerly FireEye), for tools that don’t have good equivalents on Kali/Linux — filling a gap for testers who need a Windows-native attack platform.
Use it only against systems you own or are explicitly authorized to test — see the disclaimer.
Notable bundled toolsmanually maintained
bloodhound
Six Degrees of Domain Admin, BloodHound CE
CyberChef
Decode and otherwise analyze data using this browser app.
ghidra
Software Reverse Engineering Framework
ida-free
Freeware version of the world's smartest and most feature-full disassembler.
mimikatz
Uses admin rights on Windows to display passwords in plaintext
wireshark
Network traffic analyzer - graphical interface
Getting started
CommandoVM is installed by running a PowerShell script against a fresh Windows VM (after disabling Defender/Tamper Protection), rather than booting a dedicated ISO. It pulls 300+ packages from Mandiant's companion VM-Packages repository, but that install list mixes genuine offensive-security tools with general productivity software (browsers, editors, PDF readers) and shared runtime dependencies with no clean automatic way to separate the two — the same reason this site doesn't auto-sync from Pentoo's package overlay.