CSI Linux
Ubuntu-based platform for OSINT, digital forensics, and incident response
CSI Linux has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Last verified September 5, 2026
CSI Linux is an Ubuntu-based platform built for OSINT investigation, digital forensics, and incident response, distributed as role-specific VM images rather than one general-purpose desktop image.
Use it only against systems/media you own or are explicitly authorized to examine — see the disclaimer.
Notable bundled toolsmanually maintained
autopsy
Graphical interface to SleuthKit
maltego
Open source intelligence and forensics application
Volatility Framework
Memory forensics tool and framework.
wireshark
Network traffic analyzer - graphical interface
Getting started
CSI Linux is distributed as a set of virtual machine images with distinct roles (Analyst, Gateway, SIEM) rather than a single bootable ISO — plan for 8GB+ of RAM and 50GB+ of free disk space per the official system requirements. It bundles standard forensics/OSINT tools alongside CSI's own custom evidence-capture and case-management utilities, and doesn't publish a single structured tool catalog beyond short category descriptions on its site.