I’m building DaemonCore Linux — a Debian-based pentesting and defensive-security distro
I’m building DaemonCore Linux — a Debian-based pentesting and defensive-security distro Source: https://github.com/gtited-jpg/DaemonCore-Linux-Distro
I’m building DaemonCore Linux — a Debian-based pentesting and defensive-security distro
Description
I’m building DaemonCore Linux — a Debian-based pentesting and defensive-security distro Source: https://github.com/gtited-jpg/DaemonCore-Linux-Distro
Reddit Discussion
Hey everyone,
I’ve been working on DaemonCore Linux, a custom Debian 13–based Linux distribution for authorized penetration testing, defensive security, incident response, forensics, and cybersecurity education.
GitHub: https://github.com/gtited-jpg/DaemonCore-Linux-Distro
DaemonCore is currently a work in progress. The repository contains the reproducible live-build source needed to produce the ISO; i t is not a finished stable release yet.
Main features
- Debian 13 Stable base
- Lightweight XFCE desktop
- Live USB boot
- Optional USB persistence
- Calamares graphical installer
- UEFI and legacy BIOS support
- Non-root live session with
sudo - Firewalld enabled by default
- Unnecessary network services disabled
- Custom DaemonCore branding
- Custom LightDM login screen
- Two custom GTK themes
- Three original wallpapers
- Offline cybersecurity guidebook
- Reproducible ISO build scripts
- No embedded credentials or untrusted binary downloads
- Security tools installed from Debian repositories
Network discovery and analysis
- Nmap
- Masscan
- ARP-Scan
- Netdiscover
- Traceroute
- Whois
- DNSUtils
- IPRoute2
- Ethtool
- iPerf3
- Tcpdump
- Wireshark
- TShark
- Termshark
- NGrep
- Netcat
- Socat
- Bettercap
- Bettercap Caplets
Wireless security
- Aircrack-ng
- HCXDumpTool
- HCXTools
- Reaver
Wireless testing requires a compatible adapter. Monitor mode and packet injection depend on the adapter’s chipset and driver.
Service and protocol assessment
- Enum4linux
- SMBClient
- LDAP Utilities
- SNMP utilities
- OneSixtyOne
- SSLScan
Web application testing
- Nikto
- SQLmap
- DIRB
- WFuzz
- FFUF
- Gobuster
Password auditing
- Hydra
- John the Ripper
- Hashcat
- HashID
- Crunch
Forensics and reverse engineering
- Binwalk
- Foremost
- Sleuth Kit
- ExifTool
- YARA
- GDB
- Strace
- Ltrace
- Hexedit
- Binutils
- XXD
Development and scripting
- Python 3
- Pip
- Python virtual environments
- Pipx
- Ruby
- Perl
- Build Essential
- ShellCheck
- Git
- Curl
- Wget
Desktop applications
- XFCE
- XFCE Goodies
- Firefox ESR
- QTerminal
- Mousepad
- File Roller
- Thunar archive integration
- NetworkManager
- NetworkManager graphical controls
- Pavucontrol
- PipeWire
- Calamares installer
- LightDM
System utilities
- Firewalld
- Sudo
- PolicyKit
- Htop
- Rsync
- Vim
- Less
- Man pages
- Unzip
- 7-Zip
- GVFS
- Debian live-boot and live-config components
There are currently 96 explicitly selected packages, plus the dependencies Debian installs for them.
Custom appearance
DaemonCore includes two selectable themes:
- DaemonCore Dark — graphite with violet and teal accents
- DaemonCore Black — higher-contrast black with cyan highlights
It also includes three original wallpapers:
- Core Horizon
- Silent Grid
- Neon Citadel
Core Horizon is the default desktop and login-screen wallpaper.
Offline Security Gudebook
The desktop includes a completely offline guidebook covering:
- Building an isolated testing lab
- Establishing authorization and scope
- Network discovery
- Packet analysis with Wireshark and Tcpdump
- Safe web-testing exercises
- Password auditing with disposable test hashes
- Wireless-security checks
- Linux incident response
- Evidence collection and reporting
The examples use localhost or documentation-only IP ranges and emphasize authorized lab testing.
Security defaults
- Regular desktop sessions do not run as root
- Firewalld starts automatically
- IP forwarding is disabled by default
- Kernel pointer and log access are restricted
- Common link-based privilege-escalation protections are enabled
- SSH and Apache are disabled unless deliberately enabled
- Packet-capture access uses group permissions instead of requiring a root desktop session
Current status
DaemonCore is still an early project. The source structure and package manifest validate successfully, but the image still needs broader ISO builds, VM boot testing, installer testing, hardware testing, and community review before it should be considered stable.
I’d appreciate feedback on:
- Additional defensive or pentesting tools
- Package organization
- Documentation
- Accessibility
- Hardware compatibility
- Installer behavior
- Secure default settings
- Contributors interested in testing the ISO build
DaemonCore is intended only for systems and networks you own or have explicit authorization to test.
Links cited in this discussion
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a8f94c0acd9273b49a260b0
Added to database: 08/27/2026, 01:37:04 UTC
Last updated: 08/27/2026, 02:52:02 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.