Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Kali Purple

Kali Linux's defensive/purple-team security operations platform

specializedbased on Kali LinuxBlue Team

Kali Purple has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗

Last verified September 5, 2026

Kali Purple is Kali Linux’s defensive/blue-team counterpart to its usual offensive tooling — it doesn’t maintain a separate tool catalog of its own, it inherits Kali’s, which is already covered by this site’s Kali sync (GVM/OpenVAS, Suricata, Zeek, CyberChef, and more). It also layers in a handful of additional “SOC-in-a-box” components — Malcolm, TheHive, Arkime, OpenCTI — not yet in this site’s tool catalog.

Use it only against systems/networks you own or are explicitly authorized to monitor — see the disclaimer.

Notable bundled toolsmanually maintained

CyberChef

Decode and otherwise analyze data using this browser app.

openvas

Meta package for installing all OpenVAS components.

suricata

An Open Source Next Generation Intrusion Detection and Prevention Engine.

zeek

A powerful network analysis framework that is much different from the typical IDS you may know.

Getting started

Kali Purple isn't a separate distro — it's installed via a dedicated `kali-linux-purple-amd64.iso` on the standard Kali installer, or layered onto an existing Kali install via `kali-tools-*` metapackages. It's organized around the NIST Cybersecurity Framework 2.0 functions (Identify/Protect/Detect/Respond/Recover) rather than Kali's usual offense-oriented tool menu. Install/setup walkthroughs for its defensive stack live on a community-run wiki, linked from the get-kali page above, rather than Kali's polished per-tool docs.