Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
qvm-create-windows-qube — Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS | Kitploit
Tools/GitHubGitHub/qubesos/qvm-create-windows-qube
OSINT (Open Source Intelligence)Security VirtualizationPrivacy
GitHubqubesos/qvm-create-windows-qube

qvm-create-windows-qube

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

View RepositoryWebsite
40349301 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Logo

Qvm-Create-Windows-Qube

Spin up new Windows qubes quickly, effortlessly and securely

Travis CI build License Made for Qubes OS

About

Qvm-Create-Windows-Qube is a tool for quickly and conveniently installing fresh new Windows qubes with Qubes Windows Tools (QWT) drivers automatically. It officially supports Windows 7, 8.1 and 10 as well as Windows Server 2008 R2, 2012 R2, 2016 and 2019.

The project emphasizes correctness, security and treating Windows as an untrusted guest operating system throughout the entire process. The installation takes place 100% air gapped and features optional Whonix integration on the finished Windows qube for added privacy. Accomplishing these goals in as few lines of code as possible to ensure simplicity and minimalism is key.

It also features other niceties such as automatic installation of packages including Firefox, Office 365, Notepad++, Visual Studio and more using Chocolatey to get you up and running quickly in your new environment.

As featured on: Hacker News Favicon Hacker News | Proudly ranked in the top 10 on the front page of Hacker News as well as first place for Show HN

Installation

  1. Download the installation script by opening the link, right-clicking and then selecting "Save [Page] as..."
  2. Copy install.sh into Dom0 by running the following command in Dom0:
    • qvm-run -p --filter-escape-chars --no-color-output <name_of_qube_script_is_located_on> "cat '/home/user/Downloads/install.sh'" > install.sh
    • Make sure to get all the single and double quotes
  3. Review the code of install.sh to ensure its integrity
    • Safer with escape character filtering enabled in the previous step; qvm-run disables it by default when the output is a file
  4. Run chmod +x install.sh && ./install.sh
    • Note that this will install packages in the global default TemplateVM, which is fedora-XX by default
  5. Review the code of the resulting /usr/bin/qvm-create-windows-qube

Updating

To update Qvm-Create-Windows-Qube, start by simply deleting the windows-mgmt VM and main program by running the following command in Dom0:

qvm-remove -f windows-mgmt && sudo rm /usr/bin/qvm-create-windows-qube

Lastly, follow the installation steps above to reinstall.

Note that this will also delete any Windows ISOs that have already been downloaded. This may be desirable in the case that Microsoft has updated the Windows ISOs (meaning you should redownload them anyway). However, if you would like to avoid downloading any of the Windows ISOs again, simply navigate to /home/user/qvm-create-windows-qube/windows/isos in the windows-mgmt VM and copy its contents to another (preferably disposable) qube. After the reinstall is complete, copy those ISOs back into windows-mgmt at the aforementioned directory.

Usage

Usage: qvm-create-windows-qube [options] -i <iso> -a <answer file> <name>
  -h, --help
  -c, --count <number> Number of Windows qubes with given basename desired
  -t, --template Make this qube a TemplateVM instead of a StandaloneVM
  -n, --netvm <qube> NetVM for Windows to use
  -s, --seamless Enable seamless mode persistently across reboots
  -o, --optimize Optimize Windows by disabling unnecessary functionality for a qube
  -y, --spyless Configure Windows telemetry settings to respect privacy
  -w, --whonix Apply Whonix recommended settings for a Windows-Whonix-Workstation
  -p, --packages <packages> Comma-separated list of packages to pre-install (see available packages at: https://chocolatey.org/packages)
  -P, --pool <name> LVM storage pool to install Windows on (https://www.qubes-os.org/doc/secondary-storage/)
  -i, --iso <file> Windows media to automatically install and setup
  -a, --answer-file <xml file> Settings for Windows installation

Downloading Windows ISO

Mido (mido.sh) is the secure Microsoft Windows Downloader (for Unix), inspired by Fido from Rufus. It's capable of automating the download process for a few Windows ISOs that Microsoft has behind a gated download web interface. Mido is robust and securely downloads Windows ISOs to be used by Qvm-Create-Windows-Qube from official Microsoft servers. You can find it located at /home/user/qvm-create-windows-qube/windows/isos/mido.sh in windows-mgmt.

windows-mgmt is air gapped from the network. This means that in order to securely perform the download, one must copy the mido.sh script to another (disposable) qube followed by transferring the newly downloaded ISO(s) into windows-mgmt and placing them into the /home/user/qvm-create-windows-qube/windows/isos directory. Alternatively, windows-mgmt can temporarily be given network access, however, this isn't recommended for security reasons.

Once generated, Windows ISOs are cached in /home/user/qvm-create-windows-qube/windows/out for later use. If you download an updated ISO with Mido, then make sure to remove the same ISO from the aforementioned cache directory. This will cause the cache to be regenerated from the updated ISO.

For advanced readers: Qvm-Create-Windows-Qube takes a generic approach to handling ISOs that can work with any given Windows ISO. If you have your own Windows ISO you would like to use then likely only a very slight adjustment to the closest matching answer file (namely the /IMAGE/NAME key) would be needed to make it work. You can get the valid /IMAGE/NAME values for your ISO by parsing the install.wim inside using the wiminfo command (packaged as wimlib-utils on Fedora or wimtools on Debian) or from within Windows using Windows ADK.

Creating Windows VM

Download Tool