Fedora Security Lab
Fedora spin for security auditing, forensics, and teaching security testing
Fedora Security Lab has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Last verified September 5, 2026
Fedora Security Lab is an official Fedora spin built for security auditing, digital forensics, and system rescue, oriented toward teaching security-testing methodology as well as hands-on use.
Use it only against systems you own or are explicitly authorized to test — see the disclaimer.
Notable bundled toolsmanually maintained
ettercap
Multipurpose sniffer/interceptor/logger for switched LAN
medusa
Fast, parallel, modular, login brute-forcer for network services
nmap
The Network Mapper
scap-workbench
SCAP Scanner And Tailoring Graphical User Interface.
skipfish
Fully automated, active web application security reconnaissance tool
sqlninja
SQL server injection and takeover tool
wireshark
Network traffic analyzer - graphical interface
yersinia
Network vulnerabilities check software
Getting started
Fedora Security Lab ships as a live/installable ISO with an Xfce desktop and a customized menu laid out around a security-testing workflow. Its official page features nine named tools directly (Etherape, Ettercap, Medusa, Nmap, Scap-workbench, Skipfish, Sqlninja, Wireshark, and Yersinia) rather than a larger structured catalog, and it's aimed as much at teaching security testing methodology as at day-to-day pentest work.