Think like an attacker.
Map attack surface, inspect protocols, assess applications, audit credentials, and understand exposure within an explicit authorization boundary.
Platform
Nulx is being engineered as one deliberate workstation for offensive operators, defenders, researchers, and security engineers—not a collection of unexamined tools.
Map attack surface, inspect protocols, assess applications, audit credentials, and understand exposure within an explicit authorization boundary.
Analyze evidence, hunt threats, audit systems, monitor integrity, inspect network activity, and build reproducible response workflows.
Capability map
Reviewed workflows for reconnaissance, network analysis, web assessment, wireless testing, and password auditing—always for owned or explicitly authorized targets.
Traffic inspection, host auditing, integrity monitoring, detection, DFIR, malware triage, and response tooling in one cohesive environment.
The installed baseline passed four-theme, terminal, lock, login, and no-virtual-keyboard gates. The new strict-reference Plasma shell adds a left rail, centered dock, status capsule, live overview, and four workspaces in validated source; rebuilt-ISO runtime review remains.
All 57 approved Debian routes and every selectable team profile passed separate clean-system installation tests. Public installer integration remains under review.
A discoverable command surface for tool planning, projects, diagnostics, updates, appearance, system information, and help.
A native control surface now reads real system metrics, workspaces, projects, tools, network, update, hardware, and health state. Source validation passed; the rebuilt ISO and visual runtime gates remain.
The strict-reference beta chat and provider-neutral contract now exist in validated source. Offline Guide is the only active provider and remains local, read-only, explain-only, account-free, and unprivileged.
The fail-closed policy passed the complete isolated package transaction, and the base installed system passed package, service, journal, network, and command diagnostics. Installer-profile integration remains.
Development status
The current exact candidate passed source, build, QEMU, clean Hyper-V installation, direct boot, and the complete installed-session diagnostic gate.
The installed candidate passed the earlier four-theme, lock, login, unlock, and logout gates. The strict-reference left rail, centered dock, status capsule, live overview, and four-workspace source now pass validation; rebuilt-ISO runtime acceptance remains.
The current candidate passed a clean 80 GB installation, verified ISO ejection, and direct UEFI disk boot in Hyper-V.
All 57 approved routes and every selectable team profile passed separate isolated package and service-policy tests; installer integration remains.
The native registry-backed search, categories, filters, favorites, related tools, installed-state probes, and explain-first actions pass source validation; rebuilt-ISO runtime acceptance remains.
The native dashboard and functional pages now use real local metrics, profiles, tools, projects, network, updates, hardware, health, AI, and settings data. Source validation passed; rebuilt-ISO runtime acceptance remains.
The strict-reference beta shell and provider-neutral offline/local/hosted contract pass source validation. Only the local, explain-only Offline Guide is active; no account, remote endpoint, API key, or tool execution is enabled.
Generation 2 live networking, terminal baseline, clean install, direct disk boot, installed diagnostics, lock screen, and greeter return passed on the current exact candidate.
Bounded host metadata and Debian integrations now target QEMU/KVM, Proxmox, VMware, and VirtualBox; only completed host-specific tests become verified.
A separate ARM64 artifact starts after amd64 public Beta acceptance; no ARM64 download exists today.
Broad bare-metal and Secure Boot validation are future gates.
No public ISO has been released.