Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Operating Systems

Pentesting-focused Linux distributions, with what they're built on and how to get started.

Team

Team is a hand-judged classification by primary use (offense vs. defense) — not every entry fits a team (privacy tools like Tails or Whonix aren't shown under any team filter). See the Category Key for how this is defined.

AndroL4b

Ubuntu MATE-based VM for Android app assessment, reverse engineering, and malware analysis

specialized Red Team ⚠ manual tools

ArchStrike

Arch Linux-based distribution for penetration testing and security research

general-purpose Red Team

Athena OS

Arch/NixOS-based distribution built on BlackArch's package repositories

general-purpose Red Team ⚠ manual tools

BackBox

Ubuntu-based distribution for penetration testing and security assessment

general-purpose Red Team ⚠ manual tools

Berserk Arch

Rolling-release Arch-based distro for security researchers and developers

general-purpose Red Team ⚠ manual tools

BlackArch

Arch Linux-based distribution with one of the largest pentest tool repositories

specialized Red Team

CAINE

Ubuntu-based digital forensics live distribution

forensics Blue Team ⚠ manual tools

CAPEv2

Automated malware sandbox for dynamic analysis and config/payload extraction

specialized Blue Team ⚠ manual tools

CommandoVM

PowerShell-provisioned Windows red-team toolkit

general-purpose Red Team ⚠ manual tools

CSI Linux

Ubuntu-based platform for OSINT, digital forensics, and incident response

forensics Blue Team ⚠ manual tools

Cuckoo3

CERT-EE's Python 3 rewrite of Cuckoo Sandbox for automated malware analysis

specialized Blue Team ⚠ manual tools

Demon Linux

Debian-based distribution focused on web and cloud penetration testing

specialized Red Team ⚠ manual tools

DragonOS

Debian/Ubuntu-based platform for software-defined radio (SDR) and RF work

wireless Red Team ⚠ manual tools

DShield Sensor

SANS Internet Storm Center's honeypot sensor for contributing threat data, with an ELK dashboard

specialized Blue Team ⚠ manual tools

Exegol

Community-driven Docker hacking environment with 100+ pre-installed offensive tools

general-purpose Red Team ⚠ manual tools

FACT

Fraunhofer FKIE's firmware analysis and comparison platform for routers, IoT, and UEFI images

specialized Blue Team ⚠ manual tools

Fedora Security Lab

Fedora spin for security auditing, forensics, and teaching security testing

general-purpose Red Team ⚠ manual tools

FLARE VM

Windows-based reverse-engineering and malware-analysis distribution

specialized Blue Team

Frieren

Open-source WiFi Pineapple-style framework for routers and single-board computers

wireless Red Team ⚠ manual tools

HackerOS (Cybersecurity Edition)

Polish Debian-based distro with a dedicated red-team-focused Cybersecurity Edition

specialized Red Team ⚠ manual tools

Kali Linux

Debian-based distribution built for penetration testing and security auditing

general-purpose Red Team

Kali NetHunter

Kali Linux's penetration testing platform for Android devices

general-purpose Red Team ⚠ manual tools

Kali Purple

Kali Linux's defensive/purple-team security operations platform

specialized Blue Team ⚠ manual tools

Linux Kodachi

Debian-based privacy and anonymity platform

specialized ⚠ manual tools

Malcolm

CISA/Idaho National Laboratory network traffic analysis tool suite

specialized Blue Team ⚠ manual tools

MISP

Open-source threat intelligence and sharing platform, with an official test VM

specialized Blue Team ⚠ manual tools

Mobexler

Linux Lite-based VM for combined Android and iOS application penetration testing

specialized Red Team ⚠ manual tools

NetHydra

Debian-based pentest distro running a real-time (PREEMPT_RT) kernel by default

general-purpose Red Team ⚠ manual tools

NST

Fedora-based network security monitoring and analysis toolkit

specialized Blue Team ⚠ manual tools

Open Secure-K OS

Debian-based encrypted live-USB OS for secure communication and anonymous browsing

specialized ⚠ manual tools

PALADIN

SUMURI's forensic disk-imaging and write-blocking live distribution

forensics Blue Team ⚠ manual tools

Parrot Security OS

Debian-based distribution for pentesting, digital forensics, and privacy

general-purpose Red Team ⚠ manual tools

Pentoo

Gentoo-based live distribution for penetration testing

general-purpose Red Team ⚠ manual tools

Predator-OS

Debian-based distro bundling around 1,200 tools across offense, defense, and privacy

general-purpose Red Team ⚠ manual tools

Pwnagotchi

Raspberry Pi companion that automates WPA/WPA2 handshake capture via bettercap

wireless Red Team ⚠ manual tools

Qubes OS

Security-by-compartmentalization OS built on the Xen hypervisor

specialized ⚠ manual tools

REMnux

Ubuntu-based toolkit for reverse-engineering and analyzing malicious software

specialized Blue Team

SamuraiWTF

OWASP-maintained web-app pentest training environment

specialized Red Team ⚠ manual tools

SecBSD

OpenBSD-based distribution for penetration testing and ethical hacking

general-purpose Red Team ⚠ manual tools

Security Onion

Ubuntu-based network security monitoring and threat hunting platform

specialized Blue Team

SIFT

SANS forensic workstation for digital forensics and incident response

forensics Blue Team ⚠ manual tools

SigintOS

Ubuntu-based distro for SDR-driven signals intelligence operations

specialized Red Team ⚠ manual tools

SystemRescue

Arch-based live system for disk repair, imaging, and data recovery

forensics ⚠ manual tools

T-Pot

All-in-one multi-honeypot platform with 20+ honeypots and Elastic Stack visualization

specialized Blue Team

Tails

Amnesic live OS focused on privacy and anonymity, routing all traffic through Tor

specialized

TheHive

Incident-response case management platform with an official demo VM

specialized Blue Team ⚠ manual tools

Trace Labs OSINT VM

Debian-based virtual machine purpose-built for OSINT investigations

specialized Red Team ⚠ manual tools

Tsurugi Linux

Ubuntu-based distribution for digital forensics, OSINT, and malware analysis

forensics Blue Team ⚠ manual tools

Wazuh

Open-source SIEM/XDR platform distributed as an official VM appliance

specialized Blue Team ⚠ manual tools

Whonix

Debian-based anonymity platform routing traffic through Tor

specialized ⚠ manual tools

Wifislax

Slackware-based distribution focused on wireless network auditing

wireless Red Team ⚠ manual tools

WinFE

Windows Forensic Environment — a forensically sound Windows PE boot environment

forensics Blue Team ⚠ manual tools