Skip to content

DetectOps

A Debian 12 (bookworm) live-build Detection Engineering OS — every tool baked into the ISO at build time, fully offline-capable once installed.

94Tools
10Categories
7.2 GBISO
bookwormDebian amd64

Get started Browse the tools


Categories

01
Attack Simulation
14 tools · adversary emulation & BAS
02
Detection Engineering
6 tools · Sigma, YARA, osquery
03
Threat Hunting & Endpoint Analysis
8 tools · triage & forensic timelines
04
Logging & SIEM
10 tools · forwarders & staged SIEM stacks
05
Network Security
5 tools · IDS, capture & analysis
06
Malware & Forensics
7 tools · static/dynamic triage
07
AD & Enterprise Security
6 tools · Active Directory attack/defense
08
Cloud & Kubernetes Security
25 tools · AWS/Azure/GCP/K8s, incl. RedCloudOS
09
Dev / Scripting Toolchain
8 tools · the daily-driver toolchain
10
Security Utilities
5 tools · recon & password auditing

What's on every page

Every tool page in this documentation includes:

  • What it is — a one-line description of the tool and why it's here
  • Where it lives — the absolute path inside the installed system
  • How to run it — the exact command to type, copy-paste ready
  • A real screenshot — captured live from a running DetectOps VM, not a vendor marketing image
  • Notes — anything that needs a manual step first (credentials, an internet connection, a .NET SDK, etc.)

A green NEW badge marks tools sourced from RedCloudOS/vm-packages.

:octicons-arrow-right-24: See what's staged vs. baked-in