Burnout

Writes a bootable USB drive from the command line.

Two commands. The same two on Windows, on macOS and on Linux. Burnout reads the image, works out what that image needs, and does it.

Install with Homebrew

brew install stiven-gjekaj/tap/burnout

Open source, under the MIT licence.

$ burnout list
#  DRIVE              SIZE                              BUS     REMOVABLE
1  APPLE SSD AP0512Z  500.3 GB (500,277,792,768 bytes)  Fabric  no   (system disk)
2  SanDisk Ultra      62.5 GB (62,521,344,000 bytes)    USB     yes

$ burnout write ubuntu-24.04.iso 2
This erases the drive. Nothing undoes it.

    image   ubuntu-24.04.iso
            2.1 GB (2,109,796,352 bytes)
    drive   SanDisk Ultra
            62.5 GB (62,521,344,000 bytes)
            /dev/rdisk4 USB removable

The image carries a boot table in its first sector.

Type yes to go on:
> yes
Wrote 2.1 GB (2,109,796,352 bytes) to SanDisk Ultra.
Checked 2.1 GB (2,109,796,352 bytes) of the drive against the image, byte for byte.
An example session. The list names each drive with its size, and marks the system disk. The write names the image and the drive, waits for yes, and then says which check it ran.

One tool for both kinds of image

Most tools of this kind solve one half of the problem. A byte copy writes a Linux ISO and fails on Windows. Rufus builds a real Windows installer and runs on Windows only. So the answer today depends on which image you hold and which computer you sit at, and each answer has its own flags to learn.

Burnout removes the choice. It reads the image, works out what that image needs, and does it. The commands you type on a Mac are the commands you type on Windows, and the image decides the rest.

What it does

  • Writes any bootable image. A Linux ISO, a BSD ISO, a raw .img.
  • Builds a real Windows installer, and not a copy of the files.
  • Holds a large install image, with no split and no lost install.esd.
  • Skips the checks of Windows 11 for TPM, Secure Boot, RAM, CPU and storage, when you ask.
  • Skips the Microsoft account step in Windows Setup, when you ask.
  • Verifies the write, and names the check that it ran.

How it behaves

  • The same commands on all three operating systems.
  • No flag for a thing that the tool can work out by itself.
  • It never mounts a drive, and it calls no tool of the host.
  • It refuses the disk that your system starts from.
  • Each error says what went wrong, and then what to do about it.
  • It asks for a password through sudo, and never reads one itself.
  • It names the target, and you confirm it, one time.

Two modes, and the image chooses

You do not tell Burnout which mode to use. It reads the first 512 bytes of the image.

  1. 1

    Burnout reads the first 512 bytes of the image.

  2. 2

    A boot signature and a partition table there mean a hybrid image. Raw mode copies the bytes.

  3. 3

    Without them, it looks for sources/install.wim or sources/install.esd. Windows mode builds the installer.

  4. 4

    If it finds neither, it stops and says what it found.

Raw mode

For Linux, BSD, any hybrid ISO and any .img

What it does
Copies the image byte for byte.
Partition table
Comes from inside the image.
Verifies by
One hash of the device against the source.
Proves
The drive holds the image.

Windows mode

For a Windows installer ISO

What it does
Partitions, formats, and writes the files.
Partition table
Burnout creates it.
Verifies by
One hash for each file.
Proves
Each file arrived whole.

A Linux ISO is already a bootable disk image. It carries its own boot code, its own partition table and its own EFI system partition, so writing it means a copy of the bytes. A Windows ISO is not a bootable disk image. It holds no boot code for a USB drive, so a byte copy gives a drive that most firmware refuses.

The drive that Windows mode writes

MBR partition table

Partition 1

FAT32, about 1 GB

  • every boot file
  • bootmgr, efi/, boot.wim
  • autounattend.xml

UEFI firmware reads this. It reads FAT only, so every boot file lives here.

Partition 2

exFAT, the rest of the drive

  • sources/install.wim
  • or sources/install.esd
  • whole, and never split

Windows PE reads this, after it has started from partition 1.

  • exFAT, and not NTFS. macOS mounts NTFS read only, so an NTFS partition would give a Windows path that works on two hosts out of three.
  • No file is ever split. exFAT has no 4 GiB limit, so the install image goes on whole. Burnout writes no WIM file.
  • MBR, and not GPT. Burnout writes the table itself, so the spare EFI partition that diskutil adds on macOS never appears.

Download

Each release has six binaries. None of them needs anything installed beside it.

The binaries of the latest release
SystemSizeSHA-256Download
The page reads the latest release from GitHub.

Check a download

The checksum says that the file arrived whole:

shasum -a 256 -c SHA256SUMS --ignore-missing

The attestation says that the file came out of the Burnout repository, from the commit that the tag names, through the release workflow:

gh attestation verify burnout-<version>-aarch64-apple-darwin --repo Stiven-Gjekaj/burnout

The warning that a browser download brings

A browser marks each file that it downloads, and macOS and Windows then warn before they start it. The warning is about how the file arrived, and not about what the file holds. Check the file first, and then take the mark off.

macOS does not start the binary, because no paid certificate signed it:

xattr -d com.apple.quarantine burnout-<version>-aarch64-apple-darwin

Windows SmartScreen can show "Windows protected your PC". Select More info, and then Run anyway. In PowerShell, Unblock-File takes the mark off:

Unblock-File .\burnout-<version>-x86_64-pc-windows-msvc.exe

Homebrew, Cargo, curl and gh release download set no mark, so they bring no warning.

Install

Homebrew

On macOS and on Linux.

brew install stiven-gjekaj/tap/burnout

Scoop

On Windows.

scoop bucket add stiven-gjekaj https://github.com/Stiven-Gjekaj/scoop-bucket
scoop install stiven-gjekaj/burnout

winget

On Windows, when Microsoft accepts the manifest.

winget install Stiven-Gjekaj.Burnout

Cargo

On any of the three systems, from the source on crates.io.

cargo install burnout

A write needs the right to write to the drive. On macOS and on Linux, Burnout asks for a password through sudo only when the drive refuses the write. On Windows, run it from a shell that runs as Administrator.

Use

1Find the drive

burnout list

list runs with no privilege, so you see your drives before you give a password. The size comes twice: the rounded figure that the box shows, and the exact count of bytes. The list marks the system disk, and a drive that takes no write.

2Write the image

burnout write ubuntu-24.04.iso 2

The command is the same on all three systems. Burnout names the drive, its size to the byte and its serial, and waits until you type yes.

3A Windows ISO takes the same command

burnout write Win11_25H2.iso 2 --skip-hardware-checks --no-microsoft-account

--skip-hardware-checks turns off the checks of Windows 11 for TPM, Secure Boot, RAM, CPU and storage. --no-microsoft-account takes away the step of the Microsoft account. Setup then asks for a local account and its password, so Burnout holds no password.

When the write ends

Burnout names the check that it ran. For a Windows ISO, it counts the files:

Wrote 963 files of 8.0 GB (7,988,543,418 bytes) to Samsung Flash Drive: 962 onto partition 1, FAT32, and 1 onto partition 2, exFAT.
Checked each file through a new mount of its volume against the SHA-256 that it went in with, and the partition table against the one that Burnout wrote.

A write that stops

Burnout resumes nothing, and it promises nothing about a write that stops. It says what the drive holds, after an error and after Ctrl-C alike:

burnout: stopped. The write did not end, so the drive holds part of the image, and it is not usable now. Write the image again

An image that is not complete

An ISO records the size of its own volume. Burnout refuses a file that is shorter before it reads anything else, because a download that stopped early leaves such a file.

For a script

--json prints JSON on the output stream, and the text for a person goes to the error stream. Each kind of error has a name that a script can test.

burnout list --json

Safety

Burnout erases the drive that you give it. The erased data goes nowhere, and no undo exists. A wrong target, a drive that fails during the write, and a cable that comes loose all give the same result, and none of them is recoverable. Keep a backup of anything you value.

What the code must never do

  • Write to a device that you did not select and confirm.
  • Write to the disk that the running system starts from.
  • Treat a fixed disk as a removable one.
  • Report a verification pass that it did not run.
  • Hide the target behind a default. You name the target every time.

You supply the operating system

Burnout downloads no operating system, hosts none, and gives you a licence for none. A Windows installation needs a licence from Microsoft.

Read the terms before you run Burnout.

Questions

Does Burnout cost money?

No. Burnout is open source under the MIT licence.

Which computers does it run on?

Windows, macOS and Linux, on x86_64 and on arm64. Each release has six binaries, one for each system and processor. The Linux binaries carry their own C library, and the Windows binaries carry the Microsoft C runtime.

Can it make a macOS installer?

No, and it will not. Apple ships no ISO, and the supported path is createinstallmedia, which runs on macOS only. Burnout finds a macOS installer and refuses it with a sentence that names the right tool.

Does a Windows drive start in Legacy BIOS mode?

Not in version 1. Windows mode writes a drive for UEFI firmware. The MBR layout leaves the door open for Legacy BIOS later. In raw mode, the drive holds the boot code of the image itself.

Does it split a large install.wim?

No. Partition 2 is exFAT, which has no 4 GiB limit, so the install image goes on whole.

Why does my system warn me before it starts the binary?

The binaries carry no paid code signing certificate. Each one carries build provenance instead, which says that it came out of the release workflow of the repository. Download says how to check a file and how to take the mark off.

What is not tested yet?

Windows mode is tested on Arm64. An x64 machine and the firmware of a physical PC are not tested yet. The roadmap records each measurement.

Where do I report a problem?

In the issues of the repository. Give the command, the full output, and the system.