Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Exegol

Community-driven Docker hacking environment with 100+ pre-installed offensive tools

general-purposebased on DebianRed Team

Exegol has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗Source repo ↗

Last verified September 5, 2026

Exegol is a Docker-based pentest environment aimed at engagements where spinning up a full Kali VM is overkill — it layers 100+ offensive tools across categories (Active Directory, web, OSINT, cracking, reverse engineering, RFID, SDR, and more) onto a lightweight Debian base image, managed through its own CLI rather than a system package manager.

Use it only against systems/networks you own or are explicitly authorized to test — see the disclaimer.

Notable bundled toolsmanually maintained

ghidra

Software Reverse Engineering Framework

hashcat

World’s fastest and most advanced password recovery utility

nmap

The Network Mapper

wireshark

Network traffic analyzer - graphical interface

Getting started

Exegol isn't a bootable ISO — it's a Python CLI wrapper (`pip install exegol`) around a set of official Docker images, each aimed at a different engagement type (full, ad, web, osint, light). The install scripts behind those images are plain shell (not a structured, linkable per-tool registry like a package manager's metadata), so its catalog is hand-maintained here rather than sync-scripted, same as CommandoVM. `exegol start` pulls the chosen image and drops into a containerized environment with a shared workspace on the host.