Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

SecBSD

OpenBSD-based distribution for penetration testing and ethical hacking

general-purposebased on OpenBSDRed Team

SecBSD has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗Download ↗

Last verified September 6, 2026

SecBSD is a penetration-testing distribution built on OpenBSD rather than the Linux base used by most tools in this category, inheriting OpenBSD’s proactive security architecture (code auditing, exploit mitigations, minimal running services) as its starting point instead of a hardening layer applied afterward.

Use it only against systems, networks, or accounts you own or are explicitly authorized to test — see the disclaimer.

Notable bundled toolsmanually maintained

aircrack-ng

Wireless WEP/WPA cracking utilities

burpsuite

Platform for security testing of web applications

ffuf

Fast web fuzzer written in Go (program)

foremost

Forensic program to recover lost files

GnuPG

the GNU implementation of OpenPGP for email and data encryption and signing

hydra

Very fast network logon cracker

metasploit-framework

Framework for exploit development and vulnerability research

sqlmap

Automatic SQL injection tool

Getting started

SecBSD tracks OpenBSD's -current branch, rebuilding pre-compiled, dependency-resolved security tools against OpenBSD's own hardened base (pledge/unveil exploit mitigations, no systemd, minimal default attack surface) rather than layering a pentest toolkit onto a GNU/Linux base like most distributions in this category. Snapshot ISOs are published to the project's own mirror roughly monthly; the site groups its bundled tools by category (recon/OSINT, scanning, exploitation, privacy, forensics) on its own tools page, but as comma-separated names within each category rather than individual linked entries, so this entry is maintained by hand rather than synced. As of this writing the project has publicly paused new snapshot releases pending infrastructure funding, while the site and existing snapshot mirror remain live and current.