kali Web
Kali Linux — penetration-testing OS
How to use it
Download the ISO or VM image, boot it in VirtualBox/VMware or bare metal, and launch pre-installed tools from the menu. The /tools page documents every bundled tool.
Pre-built security operating systems and lab environments that bundle hundreds of tools, so you can be productive in minutes instead of configuring for days.
Kali Linux — penetration-testing OS
Download the ISO or VM image, boot it in VirtualBox/VMware or bare metal, and launch pre-installed tools from the menu. The /tools page documents every bundled tool.
Kali Linux — penetration-testing OS
Download the ISO or VM image, boot it in VirtualBox/VMware or bare metal, and launch pre-installed tools from the menu. The /tools page documents every bundled tool.
Parrot OS
Security/privacy Linux distro — lighter alternative to Kali with similar toolset.
BlackArch
Arch-based distro with 2800+ security tools for advanced users.
Tails amnesic OS
Boot from USB for anonymous, leave-no-trace sessions routed through Tor.
Qubes OS
Security-by-isolation OS: compartmentalize work into separate VMs to contain compromise.
Security Onion
Free network-security-monitoring distro bundling Zeek, Suricata and Elastic — deploy a VM to monitor network traffic end-to-end.
REMnux malware-analysis distro
Ubuntu-based toolkit preloaded with malware-analysis tools; run as a VM lab.
FLARE-VM (Windows analysis VM)
PowerShell installer that turns a Windows VM into a full malware-analysis workstation.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Most entries here are GitHub projects — clone the repository and follow the README's install steps (pip, npm, go or cargo). A Kali Linux VM gives you many of them pre-installed.
Public-record lookups and defensive/research use are generally lawful, but rules vary by country and tool. Only test systems you own or have written authorization to test, respect each site's terms of service, and never use personal data unlawfully.
Start with the web-based tools at the top of the list — they need no setup. Read each card's “How to use it” panel, run one real query, and only then move to installable tools.