For the complete documentation index, see llms.txt. This page is also available as Markdown.

Virtual Environments

Virtual Environments (VEs) are secure, isolated, monitored workspaces for browsing, research, analysis, and other online tasks. This guide covers how to create, launch, manage, and extend them.

Viewing Virtual Environments

After you sign in, the landing page shows the Virtual Environments you can access. If nothing appears on your first login, no environments have been assigned to you yet.

Grid and List Views

The Virtual Environments page supports two display modes:

  • Grid View (default): Shows each environment as a card with status, egress, and actions.

  • List View: Shows environments in a table with more detail.

Virtual Environment Card Details

In Grid View, each card shows:

  • Status: The current state, such as Running or Unavailable

  • Egress: The egress router name, health percentage, and location

  • Zone: The deployment zone the environment is hosted in, if applicable.

  • Last Accessed By: The user who most recently launched or used the environment. If unused, this shows Never Accessed.

  • Last Accessed Date/Time: The most recent access time. If unused, this shows Never Used.

Exporting to CSV

In List View, click Download CSV in the toolbar to export the current environment data for auditing or bulk review.

Creating a Virtual Environment

From the Virtual Environments page, click Create Environment. The creation form opens in a panel from the right side of the screen.

Types of Virtual Environments

Choose the environment type that matches your task, then click Next.

  • Research: Best for most users. Supports common workflows such as browsing, research, development, testing, and training.

  • Virtual Jobs: Runs recurring automated workloads that do not need user interaction after creation. Common use cases include web scraping and scheduled data processing.

  • Malware: Designed for malware analysis, reverse engineering, and execution of potentially harmful software in an environment built for that workflow.

Environment Details

Complete the required fields, then click Next.

  • Name: Choose a name that describes the work you plan to do. This name stays internal to your organization and is not exposed publicly.

  • Assignment: Assign the environment to a user, group, or profile. By default, the creator is the assignee. Any users in an assigned group can access the environment. Administrators always have access. If you assign a profile, Replica inherits the profile's assignee and egress, and the Egress Location option disappears.

  • Base Image: See Base Images. The base image determines the operating system, tools, and built-in features available in the environment.

Environment Connectivity

Choose how the environment connects to the network, then click Next.

  • Egress: Select a VPN hosted by Replica or a third-party provider. Each egress maps to a location on the Egress Map and determines where traffic exits to the internet. You can choose from the list or click a point directly on the map.

  • Private Route (optional): Connection to an additional network location for access to specialized services. See Private Routes

  • Enclave (optional): Attach an enclave created through the Butler User Guide.

  • Proxy (optional): Select a SOCKS proxy hosted by a third-party provider. This field only appears if your administrator has configured proxy servers.

  • Open Port (optional): Allows inbound or outbound network ports between Virtual Environments. To connect two environments, enable this option on both. This is only available for supported environment types and only when enabled by an administrator.

Malware environments use a Deployment Zone step instead of standard egress selection. The deployment zone controls where the environment is hosted and where its traffic exits. Enclave attachment still appears in the Connectivity step.

Open Port

Open Port is an advanced feature that enables you to make network connections between virtual environments.

To enable Open Port, complete one extra step:

  • Port Name: A descriptive name such as HTTP

  • Port Number: The port to open, such as 8080

  • Protocol: The traffic protocol. If you are unsure, start with TCP.

For more information on using this feature, see Connections Between Environments. Open Port is an advanced feature that must be enabled by Replica support before use.

Advanced Options

Select any optional features, then click Next. None of these are required.

  • Packet Capture (optional): Captures network traffic to and from the environment and stores it as PCAP for later analysis.

  • File Export (configurable): If File Export is enabled by your administrator, this option exports files from the environment to external block storage such as MinIO or S3.

Click Submit to start provisioning. The new environment appears on the Virtual Environments page. Creation may take a few minutes, depending on the options selected.

Quick Creating a Virtual Environment (Beta)

If My View is enabled, you can create a new Virtual Environment in two clicks. Click Quick Create in My View (accessible from the header toolbar).

Replica opens a shortened creation flow with preconfigured defaults based on your organization's settings. You can usually change the default egress and select an enclave if needed. Click Submit to create the environment.

Cloning a Virtual Environment

To clone an existing environment, drag its card into the clone area on the Virtual Environments page. You can also click Create Environment in the clone area to open the standard wizard.

Cloning creates a new Virtual Environment with the same configuration as the source environment.

Using a Virtual Environment

To open an environment, click Launch on its card. The Virtual Environment interface opens in your browser.

Some environments support multiple simultaneous users. When more than one user is connected, an indicator appears in the top-right corner. The first user to connect sets the environment resolution for everyone.

Additional Launch Options

You can change how the environment opens by holding keyboard modifiers while clicking Launch.

  • On Mac:

    • Hold shift to open in a new window

    • Hold command to open in a new tab

    • Hold shift + command to open in the DCV Desktop Viewer

  • On PC:

    • Hold shift to open in a new window

    • Hold ctrl to open in a new tab

    • Hold shift + ctrl to open in the DCV Desktop Viewer

Launching the Web Browser

The browser may open automatically. If it does not, click Applications in the bottom-left corner, open Internet, and select Chromium Web Browser or the browser supported by that image.

Launching Other Applications

Virtual Environments provide a full desktop experience. Many images include tools beyond a web browser. The installed applications depend on the selected base image, and advanced users can install additional software when permitted.

To view installed applications, open the Applications menu in the lower-left corner of the environment.

Overlay Toolbox

Every Virtual Environment includes a toolbox overlay. It provides quick access to common tools while you work.

To open the toolbox, click the toolbox icon on the right side of the Virtual Environment.

1

Toolbox - Close

Use the close icon to hide the toolbox.

2

Toolbox - Files

The Files icon shows files shared with the environment and lets you move files in or out. Drag a file from your computer into the dotted upload area to copy it into the Virtual Environment. See File Transfer for details.

3

Toolbox - Clipboard

The Clipboard icon opens the shared clipboard between your computer and the environment. See Clipboard for more details.

4

Toolbox - Egress

The Egress icon lets you switch the environment to a different egress location.

5

Toolbox - SMS

The SMS icon opens text messaging for phone numbers assigned to the user or environment. See SMS Messaging and Phones for more detail.

6

Toolbox - Credentials

The Credentials icon displays the environment credentials used for privileged actions such as software installation or command-line administration.

File Transfer

Use Files to send files into a Virtual Environment or download files from it to your computer.

These files are stored through Butler User Guide. From there, they can also be downloaded, transferred to other environments, or shared when permitted.

Replica also supports file sharing between users, Secure Enclaves, and cross-environment file transfer. See Butler User Guide for the full workflow.

Upload

1

Start Upload

Open the toolbox and click Files.

2

Select Files

Click Upload Files from Library to choose a file from your computer, or drag a file into the dotted upload area.

3

Post-Upload

After upload, the file appears in the list. It may take a minute or two to complete antivirus scanning before download or editing is allowed. Refresh the file list to check status. If automated file transfer is enabled, the file may also appear on the environment desktop.

Download

To download a file to your computer, click the download icon next to the file and choose a destination on your local system.

Full Screen Mode & Keyboard Lock

Use the full screen button to switch the browser to full screen and lock special keys so they are passed directly to the Virtual Environment.

Change Egress

Use Egress to change the network location used by the environment while it is running.

Phones

If telephony is enabled and your administrator has assigned phone numbers to you, your group, or a profile, phone features are available from the main navigation and from the Virtual Environment overlay.

See Phones for details on assignments, configuration, and call forwarding.

SMS Messaging

SMS supports both sending and receiving text messages. Click the SMS icon on the right side of the overlay to open the chat window. The dropdown at the top shows the numbers assigned to you. Use the To field to start a new conversation or reopen a previous one.

Messages remain available for review, including those received while you were not active in the system. If a new message arrives while you are using the environment, Replica shows a notification. Click the notification or the SMS icon to open the conversation.

You can view SMS and MMS messages, reply as needed, and open received images or video attachments at full size for download. You can also click individual messages to copy them to the clipboard.

Click to Call

From the Phones page, you can configure a call forwarding number for supported numbers. Inbound calls to the Replica number are then forwarded automatically. Support varies by provider.

To place an outbound call through a Replica number, use click to call where available.

1

Select the number you want to call in the To field.

2

Click the phone icon.

3

Enter your callback number in the popup.

4

Enter the target phone number and click Call.

5

Replica calls your phone first.

6

Answer the call and Replica connects you to the target number.

7

The recipient sees the Replica phone number as the caller.

Credentials

Use the environment credentials for actions that require elevated privileges.

Language Support

Chinese

Replica supports Chinese input with pinyin. Two input methods are available:

  • iBus: For Chinese input across the desktop, except inside the browser

  • Google Input Tools (Chromium extension): For Chinese input inside Chromium only

iBus Configuration

To adjust iBus settings, right-click the language icon in the bottom-right corner.

The iBus icon changes based on the currently selected input language.

To enable Chinese input, click the icon and select Chinese - Intelligent Pinyin. To switch back, select English - English (US).

Google Input Tools Configuration

The Chromium extension is not preconfigured and must be set up before use.

The Google Input Tools extension icon appears in the top-right area of Chromium.

To configure it, click the extensions icon and select Extension Options.

On the language list page, find Chinese (Simplified, China) in the left column. Select it, then click the black arrow in the center to move it to the enabled list on the right.

Close the tab, then click the extension icon again and select Chinese as the active input language.

You can now use pinyin input in Chromium text fields.

Snapshots

Linux Virtual Environments

If your administrator has enabled Snapshots for Linux Virtual Environments, you can save browser state and later reuse it in another environment. Depending on configuration, the browser may begin storing cookies, bookmarks, extensions, browsing history, and related state after first use. That state contributes to the environment fingerprint. A snapshot preserves it for later reuse.

These steps assume you are comfortable using the Linux command line.

This feature only appears on supported Virtual Environments.

Capture

1

Open Terminal from ApplicationsSystem Tools.

2

Copy the command for the browser you are using from the table below.

3

Run the command and wait for the snapshot process to finish.

4

When the process completes, an archive named for the browser type and environment ID is created on the desktop.

5

Upload that archive to external storage such as Files.

Browser
Command

Chromium

. /opt/greymarketlabs/configs/chromium/chromium.sh && snapshot_save

Firefox

. /opt/greymarketlabs/configs/firefox/firefox.sh && snapshot_save

Brave

. /opt/greymarketlabs/configs/brave/brave.sh && snapshot_save

Tor

. /opt/greymarketlabs/configs/tor/tor.sh && snapshot_save

Restore

1

Download the snapshot archive from external storage.

2

Move the archive to the desktop.

3

Open Terminal from ApplicationsSystem Tools.

4

Copy the correct restore command from the table below.

5

Run the command and wait for the restore process to finish.

Browser
Command

Chromium

. /opt/greymarketlabs/configs/chromium/chromium.sh && snapshot_load /home/$USER/Desktop/chromium-*.tar.gz

Firefox

. /opt/greymarketlabs/configs/firefox/firefox.sh && snapshot_load /home/$USER/Desktop/firefox-*.tar.gz

Brave

. /opt/greymarketlabs/configs/brave/brave.sh && snapshot_load /home/$USER/Desktop/brave-*.tar.gz

Tor

. /opt/greymarketlabs/configs/tor/tor.sh && snapshot_load /home/$USER/Desktop/tor-*.tar.gz

Windows Virtual Environments

If Snapshots are enabled for Windows Virtual Environments, some environments, such as malware testing images, may support them. A snapshot captures the current environment state so you can restore it later.

Open the Actions menu on the Virtual Environment and click Manage Snapshots. From that dialog, you can create, restore, edit, and delete snapshots.

Creating a snapshot starts a background job. The time required depends on how much data is stored in the environment.

Restoring a snapshot also starts a background job. The current state is replaced by the snapshot, and the environment restarts while the restore is applied.

Credentials

Each Virtual Environment has its own credentials. Use them for advanced actions that require a password.

Viewing Environment Credentials

From the Virtual Environments page, open the environment's Actions menu and click View Credentials. You can also open the same credentials from the toolbox through Admin Credentials while inside the environment.

Deleting a Virtual Environment

Deleting an environment permanently removes it.

To delete an environment, open its Actions menu and click Delete, then confirm the action.

Stop/Start a Virtual Environment

Malware environments can be stopped and started.

To stop or start one, open its Actions menu and click Stop Environment or Start Environment, then confirm the action.

Restarting a Virtual Environment

To restart an environment, open its Actions menu, click Restart, and confirm.

Renaming a Virtual Environment

To rename an environment, open its Actions menu, click Rename, and enter the new name.

Additional Details

To view more information about an environment, open its Actions menu and click View Details.

Assigning a Virtual Environment

A Virtual Environment can be assigned to a user, group, or profile. Administrators can assign any environment. Standard users can assign only to themselves, to groups they belong to, or to users in those groups. By default, the creator is the assignee.

Assignment on creation

During creation, you can assign the environment to a user, group, or profile. Assigning to a group grants access to all users in that group. If the environment is assigned to a profile, the user or group that owns the profile can access it.

Reassignment

To change the assignee after creation, open the environment's Actions menu and click Assign.

The reassignment dialog lets you choose a new user, group, or profile.

Base Images

Base images define the operating system, applications, and built-in features for a Virtual Environment.

Viewing Image Details

Click any image card in the image catalog to open its details. The panel shows the image version, operating system, image type, and installed applications. Click close to dismiss it.

Your image catalog may include:

  • Linux Firefox

  • Linux Brave

  • Linux Tor

  • Linux Jupyter Notebooks

  • Linux Selenium

  • Windows Edge

Available images depend on your organization's subscription and configuration. You may see fewer images than the examples listed here, and custom images may also be available.

Linux Neo4j

To access Neo4j in a Linux Neo4j environment:

1

Open the applications menu and select Open Neo4j from the Programming category.

2

Connect to the Neo4j database.

Linux Jupyter Notebooks

To access Jupyter Notebooks in a Linux Jupyter Notebooks environment:

1

Open Jupyter Notebooks.

2

Jupyter launches in Firefox at http://127.0.0.1:8888/lab.

3

The environment displays the shared notebooks.

File Export

If you are not using File Export for out-of-band transfer, use Files in Butler to move data into or out of Virtual Environments.

If your administrator has configured File Export, you will see an additional option under Advanced during environment creation. You must enable it at creation time. After that, files saved in the Sync folder on the environment desktop can be exported to external storage such as MinIO or S3.

All exported data is encrypted in transit with SSL/TLS 1.2 or higher and encrypted at rest with AES-256. If S3 is used, AWS Server-Side Encryption S3 (SSE-S3) provides AES-256 encryption at rest.

Exporting Data Walkthrough

1

Create a new Virtual Environment from the Environments page and enable File Export under Advanced Options. If this option does not appear, the image does not support File Export or it has not been configured.

2

Return to the Environments page. In the environment's Actions menu, look for Export to S3. The label says "S3" even if a different storage backend is configured.

3

Launch the Virtual Environment and download a file with the in-environment browser.

4

When saving the file, change the destination from Downloads to the Sync folder on the desktop.

5

Return to the Environments page, open the Actions menu for that environment, and click Export to S3.

6

Confirm the export. A success notification appears in the top-right corner.

Viewing Exported Data

1

If your deployment uses AWS S3 and you have direct bucket access, locate the export bucket using the prefix configured by your administrator followed by -exports- and your user ID. If you do not have direct access, contact your administrator.

2

Open the bucket and locate the folder named for the Virtual Environment ID and export timestamp. Timestamps use the format mm-dd-yyyy-hh:mm:ss.

3

Open the most recent export folder and confirm that the file from the environment is present.

Advanced Virtual Environment Networking

Private Routes

Private Routes are a Replica feature that enables your environment to connect to network locations which are not on the public Internet. If you have private routes available to you, you can select them when you create your environment.

For private routes to be available, it must be configured and enabled by your administrator.

Private Routes are available on container-type Virtual Environments

Connections Between Environments

Replica provides several features to enable network connections to be made between Virtual Environments. For instance, you can run a web server on one of your virtual environments, and enable it to be accessed locally from other virtual environments. These features vary depending on the type of environment you are using.

Container-Type Virtual Environments

Use the Open Port feature when you create each environment. This feature affects enables both inbound and outbound traffic on the selected port. Use this option for each environment you wish to allow traffic for. You can connect to any other Virtual Environments of this type using the local IP address.

Standard Virtual Environments with any Open Ports are isolated from all other environments.

The Open Port feature is not available by default. To enable this feature, reach out to Replica support.

To connect between Virtual Environments with an open port, you can use the IP address of the environment you want to connect to. To get the IP address, run ifconfig eth0 | awk '/inet / {print $2}' on the target environment.

Malware Environments

Malware environments within a zone share a local network by default. You can connect to any other Malware environment in the same zone using the local IP address.

You may also need to permit traffic through the operating system's default firewall within your environment, if applicable.

Other Environments (Cloud Zone)

Connections directly between environments which are hosted in third-party cloud zones are not currently available.

Hardware Virtual Environments

Hardware Virtual Environments connect physical devices to the Replica platform. They launch and operate like other Virtual Environments, but available features may differ because of hardware-specific limitations.

These environments require special configuration and can only be created or deleted by an administrator. Some standard features, such as Butler file transfer, may not be available.

To check whether an environment is hardware-backed, open View Details and review the Environment ID. Hardware Virtual Environments use IDs that begin with hw.

Administrators can find additional details in the administrator documentation.

Last updated

Was this helpful?