Get the Virtual Appliance

The easiest way to get the REMnux distro is to download the REMnux virtual appliance in the OVA format, import it into your hypervisor, then run the upgrade command to make sure it's up-to-date. The virtual appliance is based on Ununtu 18.04.

Step 1: Download the Virtual Appliance File

The REMnux virtual appliance approximately 5 GB. It comes as the industry-standard OVA file, which you can import into your virtualization software.

Pick one OVA file to download: Unless you're using Oracle VM VirtualBox, get the general OVA file. If you're using VirtualBox, get the VirtualBox version.

General OVA Link
VirtualBox OVA Link
General OVA Link

Download the REMnux general OVA file from one of these locations:

VirtualBox OVA Link

Download the REMnux VirtualBox OVA from one of these locations:

Some browsers (e.g., Brave) change the extension of the OVA file after downloading it, possibly giving it the incorrect .ovf extension. If that happens, rename the file so it has the .ova extension.

Step 2: Confirm the Hash the OVA File

Validate the SHA-256 hash of the downloaded file using a tool such as sha256sum or shasum to make sure it matches this expected value:

General OVA Hash
VirtualBox VM Hash
General OVA Hash
bf08a6d2b0b4813131b704c1cfcb921320e81ae917c825fa5c01e2131e0409c0
VirtualBox VM Hash
43f7e4fe7a58bd2012df5624423846307b4a028f655ad02cf40f929b6dc8231d

Step 3: Import the OVA File

If possible, upgrade your virtualization software to the latest version. Then, use it to import the downloaded OVA file. If you're not sure how to do that, follow the instructions below:

Direct Import
Conversion
Conversion

When importing the REMnux virtual appliance, allocate resources such as RAM and disk space based on what you have available. REMnux is a relatively lightweight distro, but the more you allocate to it, the faster it will run. As a point of reference, most people find 4 GB RAM and 50 GB disk sufficient.

Step 4: Start the REMnux Virtual Machine

Once you start your REMnux virtual machine, it will automatically log you into the REMnux environment.

There is no logon screen for accessing the REMnux environment, because analysts generally use REMnux on a system to which physical access is already restricted. When you need to elevate your privileges or access the REMnux virtual appliance remotely, note the follow default credentials:

Username: remnux Password: malware

If necessary, change the keyboard layout of your system to match your locale and setup.

Step 5: Consider Special Hypervisor Requirements

Depending on which hypervisor or environment you're using, you might need to take the following steps:

VirtualBox

If running VirtualBox on Windows 10, be sure to disable Hyper-V using the command bcdedit /set hypervisorlaunchtype off. Do this even if Hyper-V appears disabled in the Windows Features listing. If you don't, you are likely to run into problems downloading files and updating REMnux.

If your REMnux window is too small when you boot it up the system in VirtualBox, activate the Scaling Mode for the VM via the VirtualBox menu View > Scaling Mode.

Remote Cloud, Such as AWS

The REMnux virtual appliance ships in "dedicated" installation mode, which automatically turns off the SSH daemon. This configuration is generally desirable when running REMnux in a local lab. If you're deploying the virtual appliance in a cloud environment, you might need to keep SSH enabled to remotely access your REMnux system. In that case:

  1. Edit the /etc/remnux-config and change the mode from dedicated to cloud.

  2. Enable the SSH daemon by running: sudo systemctl enable ssh.

  3. Change the default user's password and otherwise strengthen the SSH authentication method according to your requirements and risk tolerance.

  4. Reboot your REMnux system.

KVM/QEMU

If you converted the REMnux virtual appliance to KVM/QEMU, install install the "spice-vdagent" package in the virtual machine to be able to resize the windows of your VM and copy/paste between it and your host.

Proxmox

If you're planning to use the REMnux virtual appliance in Proxmox, follow the steps in this article to import the OVA. Once done, consider taking the following steps using the Proxmox interface:

  1. VM > Hardware > Display > Set to -> SPICE(qxl)

  2. VM > Hardware > Option > Spice Enhancements > Video Streaming: all

Step 6: Upgrade the REMnux Virtual Machine

After installing the REMnux virtual machine, run the following command inside the VM to upgrade it to the latest version of the distro:

remnux upgrade

For more details about keeping your REMnux environment current, so you benefit from the latest enhancements, see the Keeping REMnux Up to Date section.

Step 7: Take a Snapshot of the Virtual Machine

Consider taking a snapshot of your REMnux virtual machine, so you can return it to a known good state if the need arises.