← All distributions
Tsurugi Linux
An Ubuntu-based digital forensics and OSINT distribution with a dedicated computer-vision analysis toolset and kernel-level device write-blocking, aimed at DFIR investigators and researchers.
Specialty & NicheforensicsOSINTUbuntu-basedDFIRmalware-analysisDownload ↗Official site ↗Docs / Wiki ↗
Based on
Ubuntu
First released
2018
Package manager
APT (.deb)
Desktop environments
XFCE (customized)
Tsurugi Linux focuses on digital forensics and incident response (DFIR), open-source intelligence (OSINT) gathering, and malware analysis, distinguishing itself from CAINE and other forensics distributions with a dedicated computer-vision analysis section for image/video evidence and an OSINT profile switcher for tailoring the environment to different investigation types. Like CAINE, it implements device write-blocking at the kernel level to prevent accidental modification of evidence media during acquisition and analysis, a non-negotiable requirement for forensically sound work. It's actively maintained by an international team of forensics practitioners and continues to see regular tool updates, unlike some older, more dormant forensics-distribution projects.
MirrorNest doesn't mirror distro ISOs — installation media should always come straight from the project's own official download page (linked above), so you get the correct checksum/signature to verify against.