Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tsurugi Linux

Ubuntu-based distribution for digital forensics, OSINT, and malware analysis

forensicsbased on UbuntuBlue Team

Tsurugi Linux has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗

Last verified September 5, 2026

Tsurugi Linux is a forensics-focused distribution bundling several hundred curated DFIR, OSINT, and malware-analysis tools, built around forensic soundness (write-blocking, non-destructive analysis modes) by default.

Use it only against systems/media you own or are explicitly authorized to examine — see the disclaimer.

Notable bundled toolsmanually maintained

mimikatz

Uses admin rights on Windows to display passwords in plaintext

Getting started

Tsurugi Linux is built on Ubuntu 24.04 LTS with a custom kernel, intended primarily as an installed forensics lab (a live mode is also supported), with kernel-level write-blocking and a dedicated computer-vision analysis mode. Its official documentation lists over 500 bundled tools by category (imaging, hashing, and more) at tsurugi-linux.org's tools listing, but as bare names with no per-tool links or descriptions — genuinely large and official, but not structured enough to link out to individual sources here.