Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

CommandoVM

PowerShell-provisioned Windows red-team toolkit

general-purposebased on WindowsRed Team

CommandoVM has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗

Last verified September 5, 2026

CommandoVM is a Windows-based red-team toolkit maintained by Mandiant (formerly FireEye), for tools that don’t have good equivalents on Kali/Linux — filling a gap for testers who need a Windows-native attack platform.

Use it only against systems you own or are explicitly authorized to test — see the disclaimer.

Notable bundled toolsmanually maintained

bloodhound

Six Degrees of Domain Admin, BloodHound CE

CyberChef

Decode and otherwise analyze data using this browser app.

ghidra

Software Reverse Engineering Framework

ida-free

Freeware version of the world's smartest and most feature-full disassembler.

mimikatz

Uses admin rights on Windows to display passwords in plaintext

wireshark

Network traffic analyzer - graphical interface

Getting started

CommandoVM is installed by running a PowerShell script against a fresh Windows VM (after disabling Defender/Tamper Protection), rather than booting a dedicated ISO. It pulls 300+ packages from Mandiant's companion VM-Packages repository, but that install list mixes genuine offensive-security tools with general productivity software (browsers, editors, PDF readers) and shared runtime dependencies with no clean automatic way to separate the two — the same reason this site doesn't auto-sync from Pentoo's package overlay.