Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

PALADIN

SUMURI's forensic disk-imaging and write-blocking live distribution

forensicsbased on UbuntuBlue Team

PALADIN has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗

Last verified September 5, 2026

PALADIN is a forensic-imaging distribution built by SUMURI around preserving evidence integrity by default — disk imaging and cloning, memory analysis via Volatility 3, mobile/vehicle forensics, data recovery and carving, and BitLocker decryption, bundled with Autopsy and The Sleuth Kit for analysis.

Use it only against systems/media you own or are explicitly authorized to examine — see the disclaimer.

Notable bundled toolsmanually maintained

autopsy

Graphical interface to SleuthKit

sleuthkit

Tools for forensics analysis on volume and filesystem data

Volatility Framework

Memory forensics tool and framework.

Getting started

PALADIN LTS (currently version 9, built on Ubuntu 24.04 LTS) ships as a live bootable USB in 64-bit (LTS) and 32-bit (Edge) editions, and also supports bringing your own ISO. It boots with write-blocking and auto-mount disabled from the start so connected media isn't altered during acquisition. It's free to use personally under a "name your price" model; corporate use requires a minimum donation.