Platform

Built for both sides of security.

Nulx is being engineered as one deliberate workstation for offensive operators, defenders, researchers, and security engineers—not a collection of unexamined tools.

RED / 01

Think like an attacker.

Map attack surface, inspect protocols, assess applications, audit credentials, and understand exposure within an explicit authorization boundary.

BLUE / 02

Operate like a defender.

Analyze evidence, hunt threats, audit systems, monitor integrity, inspect network activity, and build reproducible response workflows.

Capability map

Reality, clearly labelled.

01In development

Offensive security

Reviewed workflows for reconnaissance, network analysis, web assessment, wireless testing, and password auditing—always for owned or explicitly authorized targets.

02In development

Defensive security

Traffic inspection, host auditing, integrity monitoring, detection, DFIR, malware triage, and response tooling in one cohesive environment.

03In development

Engineered desktop

The installed baseline passed four-theme, terminal, lock, login, and no-virtual-keyboard gates. The new strict-reference Plasma shell adds a left rail, centered dock, status capsule, live overview, and four workspaces in validated source; rebuilt-ISO runtime review remains.

04In development

Reviewed tool profiles

All 57 approved Debian routes and every selectable team profile passed separate clean-system installation tests. Public installer integration remains under review.

05Verified

Nulx command suite

A discoverable command surface for tool planning, projects, diagnostics, updates, appearance, system information, and help.

06In development

Nulx Command Center

A native control surface now reads real system metrics, workspaces, projects, tools, network, update, hardware, and health state. Source validation passed; the rebuilt ISO and visual runtime gates remain.

07In development

Nulx AI

The strict-reference beta chat and provider-neutral contract now exist in validated source. Offline Guide is the only active provider and remains local, read-only, explain-only, account-free, and unprivileged.

08In development

Controlled services

The fail-closed policy passed the complete isolated package transaction, and the base installed system passed package, service, journal, network, and command diagnostics. Installer-profile integration remains.

Development status

What has been verified so far.

Core OS

The current exact candidate passed source, build, QEMU, clean Hyper-V installation, direct boot, and the complete installed-session diagnostic gate.

Verified

Desktop

The installed candidate passed the earlier four-theme, lock, login, unlock, and logout gates. The strict-reference left rail, centered dock, status capsule, live overview, and four-workspace source now pass validation; rebuilt-ISO runtime acceptance remains.

In development

Installer

The current candidate passed a clean 80 GB installation, verified ISO ejection, and direct UEFI disk boot in Hyper-V.

Verified

Security tools

All 57 approved routes and every selectable team profile passed separate isolated package and service-policy tests; installer integration remains.

In development

Nulx Launcher

The native registry-backed search, categories, filters, favorites, related tools, installed-state probes, and explain-first actions pass source validation; rebuilt-ISO runtime acceptance remains.

In development

Command Center

The native dashboard and functional pages now use real local metrics, profiles, tools, projects, network, updates, hardware, health, AI, and settings data. Source validation passed; rebuilt-ISO runtime acceptance remains.

In development

Nulx AI

The strict-reference beta shell and provider-neutral offline/local/hosted contract pass source validation. Only the local, explain-only Offline Guide is active; no account, remote endpoint, API key, or tool execution is enabled.

In development

Hyper-V validation

Generation 2 live networking, terminal baseline, clean install, direct disk boot, installed diagnostics, lock screen, and greeter return passed on the current exact candidate.

Verified

VM portability

Bounded host metadata and Debian integrations now target QEMU/KVM, Proxmox, VMware, and VirtualBox; only completed host-specific tests become verified.

In development

ARM64 architecture

A separate ARM64 artifact starts after amd64 public Beta acceptance; no ARM64 download exists today.

Planned

Physical hardware

Broad bare-metal and Secure Boot validation are future gates.

Planned

Public Beta

No public ISO has been released.

Not released