Operating Systems
Pentesting-focused Linux distributions, with what they're built on and how to get started.
Team is a hand-judged classification by primary use (offense vs. defense) — not every entry fits a team (privacy tools like Tails or Whonix aren't shown under any team filter). See the Category Key for how this is defined.
AndroL4b
Ubuntu MATE-based VM for Android app assessment, reverse engineering, and malware analysis
specialized Red Team ⚠ manual tools
ArchStrike
Arch Linux-based distribution for penetration testing and security research
general-purpose Red TeamAthena OS
Arch/NixOS-based distribution built on BlackArch's package repositories
general-purpose Red Team ⚠ manual tools
BackBox
Ubuntu-based distribution for penetration testing and security assessment
general-purpose Red Team ⚠ manual toolsBerserk Arch
Rolling-release Arch-based distro for security researchers and developers
general-purpose Red Team ⚠ manual tools
BlackArch
Arch Linux-based distribution with one of the largest pentest tool repositories
specialized Red TeamCAINE
Ubuntu-based digital forensics live distribution
forensics Blue Team ⚠ manual toolsCAPEv2
Automated malware sandbox for dynamic analysis and config/payload extraction
specialized Blue Team ⚠ manual tools
CommandoVM
PowerShell-provisioned Windows red-team toolkit
general-purpose Red Team ⚠ manual toolsCSI Linux
Ubuntu-based platform for OSINT, digital forensics, and incident response
forensics Blue Team ⚠ manual tools
Cuckoo3
CERT-EE's Python 3 rewrite of Cuckoo Sandbox for automated malware analysis
specialized Blue Team ⚠ manual toolsDemon Linux
Debian-based distribution focused on web and cloud penetration testing
specialized Red Team ⚠ manual tools
DragonOS
Debian/Ubuntu-based platform for software-defined radio (SDR) and RF work
wireless Red Team ⚠ manual toolsDShield Sensor
SANS Internet Storm Center's honeypot sensor for contributing threat data, with an ELK dashboard
specialized Blue Team ⚠ manual toolsExegol
Community-driven Docker hacking environment with 100+ pre-installed offensive tools
general-purpose Red Team ⚠ manual tools
FACT
Fraunhofer FKIE's firmware analysis and comparison platform for routers, IoT, and UEFI images
specialized Blue Team ⚠ manual toolsFedora Security Lab
Fedora spin for security auditing, forensics, and teaching security testing
general-purpose Red Team ⚠ manual tools
FLARE VM
Windows-based reverse-engineering and malware-analysis distribution
specialized Blue Team
Frieren
Open-source WiFi Pineapple-style framework for routers and single-board computers
wireless Red Team ⚠ manual tools
HackerOS (Cybersecurity Edition)
Polish Debian-based distro with a dedicated red-team-focused Cybersecurity Edition
specialized Red Team ⚠ manual toolsKali Linux
Debian-based distribution built for penetration testing and security auditing
general-purpose Red Team
Kali NetHunter
Kali Linux's penetration testing platform for Android devices
general-purpose Red Team ⚠ manual tools
Kali Purple
Kali Linux's defensive/purple-team security operations platform
specialized Blue Team ⚠ manual tools
Linux Kodachi
Debian-based privacy and anonymity platform
specialized ⚠ manual tools
Malcolm
CISA/Idaho National Laboratory network traffic analysis tool suite
specialized Blue Team ⚠ manual tools
MISP
Open-source threat intelligence and sharing platform, with an official test VM
specialized Blue Team ⚠ manual tools
Mobexler
Linux Lite-based VM for combined Android and iOS application penetration testing
specialized Red Team ⚠ manual tools
NetHydra
Debian-based pentest distro running a real-time (PREEMPT_RT) kernel by default
general-purpose Red Team ⚠ manual toolsNST
Fedora-based network security monitoring and analysis toolkit
specialized Blue Team ⚠ manual toolsOpen Secure-K OS
Debian-based encrypted live-USB OS for secure communication and anonymous browsing
specialized ⚠ manual tools
PALADIN
SUMURI's forensic disk-imaging and write-blocking live distribution
forensics Blue Team ⚠ manual tools
Parrot Security OS
Debian-based distribution for pentesting, digital forensics, and privacy
general-purpose Red Team ⚠ manual tools
Pentoo
Gentoo-based live distribution for penetration testing
general-purpose Red Team ⚠ manual tools
Predator-OS
Debian-based distro bundling around 1,200 tools across offense, defense, and privacy
general-purpose Red Team ⚠ manual tools
Pwnagotchi
Raspberry Pi companion that automates WPA/WPA2 handshake capture via bettercap
wireless Red Team ⚠ manual tools
Qubes OS
Security-by-compartmentalization OS built on the Xen hypervisor
specialized ⚠ manual tools
REMnux
Ubuntu-based toolkit for reverse-engineering and analyzing malicious software
specialized Blue TeamSamuraiWTF
OWASP-maintained web-app pentest training environment
specialized Red Team ⚠ manual tools
SecBSD
OpenBSD-based distribution for penetration testing and ethical hacking
general-purpose Red Team ⚠ manual tools
Security Onion
Ubuntu-based network security monitoring and threat hunting platform
specialized Blue TeamSIFT
SANS forensic workstation for digital forensics and incident response
forensics Blue Team ⚠ manual tools
SigintOS
Ubuntu-based distro for SDR-driven signals intelligence operations
specialized Red Team ⚠ manual tools
SystemRescue
Arch-based live system for disk repair, imaging, and data recovery
forensics ⚠ manual tools
T-Pot
All-in-one multi-honeypot platform with 20+ honeypots and Elastic Stack visualization
specialized Blue Team
Tails
Amnesic live OS focused on privacy and anonymity, routing all traffic through Tor
specializedTheHive
Incident-response case management platform with an official demo VM
specialized Blue Team ⚠ manual tools
Trace Labs OSINT VM
Debian-based virtual machine purpose-built for OSINT investigations
specialized Red Team ⚠ manual toolsTsurugi Linux
Ubuntu-based distribution for digital forensics, OSINT, and malware analysis
forensics Blue Team ⚠ manual tools
Wazuh
Open-source SIEM/XDR platform distributed as an official VM appliance
specialized Blue Team ⚠ manual toolsWhonix
Debian-based anonymity platform routing traffic through Tor
specialized ⚠ manual tools
Wifislax
Slackware-based distribution focused on wireless network auditing
wireless Red Team ⚠ manual tools
WinFE
Windows Forensic Environment — a forensically sound Windows PE boot environment
forensics Blue Team ⚠ manual tools