Skip to content
RU
← All articles

What Is Kali Linux Used For? Uses, Install, Legality

A laptop running a Linux desktop with several terminal windows

Kali Linux is used for penetration testing, security auditing and digital forensics: it is a free Debian-based distribution from OffSec (formerly Offensive Security) that ships hundreds of pre-packaged tools for checking how well systems are protected. It is legal to download and use, but only against systems you own or have written permission to test.

What is Kali Linux used for?

Under the hood Kali is Debian with a curated repository of security tools: network scanners, traffic analyzers, web application scanners, password auditing utilities and forensic toolkits. You could install most of these programs on Ubuntu or plain Debian yourself, but in Kali they are already packaged, updated from one repository and tested to work together. That convenience is the whole point of the distribution.

Kali is the successor to BackTrack and follows a rolling release model. Packages update continuously, and every quarter the project publishes a snapshot numbered by year and release (for example, 2025.1). So "the latest version" simply means downloading the current image and keeping it updated with apt.

What are the main uses of Kali Linux?

  • Penetration testing — authorized, contract-based tests of networks and applications, ending in a report for the system owner.
  • Internal security auditing — administrators inventorying their own networks: which hosts exist, which services listen, what crosses the wire.
  • Digital forensics and incident response — examining disk and memory images after a breach.
  • Training — students and CTF players practising on intentionally vulnerable lab machines.

Why would someone use Kali Linux instead of a regular distro?

Because the tooling is ready on first boot and maintained by one team. A tester who arrives at a client site, or spins up a lab for a week-long engagement, does not want to spend a day compiling tools and resolving dependencies. Kali also ships as ready-made virtual machines, a live USB image, containers and a WSL package, so the same environment can run almost anywhere.

Is Kali Linux for hackers?

It is for security professionals, which is not the same thing as a "hacker OS". Kali does not break into anything by itself; every tool in it is also available elsewhere, and results depend entirely on the operator's skill and authorization. It is also a poor daily driver. The developers themselves do not recommend Kali as a general-purpose desktop: its defaults are tuned for auditing work, not for office apps, gaming or media. If you want Linux for everyday use, pick Ubuntu, Debian or Fedora, and keep Kali in a virtual machine.

QuestionKali LinuxUbuntu / Debian
Main purposeSecurity testing and forensicsGeneral-purpose desktop and server
Security tools preinstalledYes, grouped into metapackagesNo, installed individually
Release modelRolling, quarterly snapshotsFixed releases (Ubuntu LTS, Debian stable)
Good as a daily driverNot recommendedYes
Best way to run itVirtual machine or live USBBare metal or VM

Kali Linux itself is legal. It is open-source software distributed openly and used in universities, training courses and professional security work. What can be illegal is what you do with it.

  • Use the tools only on systems you own, or on systems whose owner has given you written permission with a defined scope: which addresses, which techniques, which time window.
  • In the United States, unauthorized access to computers falls under the Computer Fraud and Abuse Act; in the United Kingdom, under the Computer Misuse Act 1990; most countries have equivalent laws. In Russia, unauthorized access to computer information is prosecuted under chapter 28 of the Criminal Code.
  • "I was only scanning" is not a defense. Scans and login attempts show up in the target's logs, and hosting providers act on abuse reports.
  • Legitimate work looks like a signed engagement or an internal authorization, an agreed scope and a written report for the system owner.

To practise legally, build an isolated lab of your own virtual machines (intentionally vulnerable images such as Metasploitable or DVWA exist for exactly this) or join CTF platforms where participation implies consent.

Kali Linux download: which image to choose

Download only from the official Get Kali page. Re-packaged ISOs from file-sharing sites are a bad idea for a system you will run with administrator rights. For a typical PC or laptop choose amd64; for Apple Silicon Macs and ARM boards choose arm64.

  • Pre-built virtual machines for VirtualBox, VMware, Hyper-V and QEMU — the fastest way to start.
  • Installer ISO — the Debian installer with a choice of desktop and tool sets.
  • Live image — boots from USB without touching the hard drive.
  • WSL, containers, cloud and NetHunter for Windows, Docker/LXC, cloud providers and Android devices.

Every file on the download page has a SHA256 checksum next to it. Compare it before using the image:

# Windows PowerShell
Get-FileHash .\kali.iso -Algorithm SHA256

# Linux
sha256sum kali.iso

# macOS
shasum -a 256 kali.iso

Replace kali.iso with the actual file name. If the hash differs, download again.

How to install Kali Linux in VirtualBox

  1. From the Virtual Machines section of the download page, get the VirtualBox image and extract the .7z archive (7-Zip on Windows works).
  2. In VirtualBox choose Machine → Add and select the extracted .vbox file.
  3. Give the VM at least 2 GB of RAM and two CPU cores if your host can spare them.
  4. Boot, log in with the default credentials below and change the password immediately.
  5. Take a snapshot so you can roll back after experiments.

If you prefer the installer ISO, create a new VM with type Linux and version Debian (64-bit), and allocate at least 20 GB of disk. For a lab, switch the network adapter from NAT to Host-only or Internal Network so Kali only sees your own machines. Hypervisor settings, network modes and snapshots are covered in detail in our VirtualBox guide. If clipboard sharing or display resizing does not work after an ISO install, run:

sudo apt update
sudo apt install -y virtualbox-guest-x11

Kali Linux on Windows with WSL

For command-line tools only, run this in an elevated PowerShell:

wsl --install -d kali-linux

The WSL image is minimal, so add tools with a metapackage: sudo apt update && sudo apt install -y kali-linux-default. Networking tools have limitations under WSL because the subsystem has no direct access to network adapters.

Default Kali Linux username and password

The pre-built virtual machines and the live image use kali / kali, as listed on the official Default Credentials page. An installer-based system has no default password: you set it during installation. Root login is not the default; administrative commands go through sudo.

Change the default password right after the first login:

passwd

This matters most if you enable SSH or put the VM on a shared network, because kali/kali is one of the first pairs bots try. If you plan to reach the VM over SSH, switch to key-based login as described in our SSH key setup guide.

First commands after installing Kali

sudo apt update
sudo apt full-upgrade -y
cat /etc/os-release

Tools are grouped into metapackages: kali-linux-default (the standard set), kali-linux-large, kali-linux-everything and kali-linux-headless for systems without a desktop, plus themed kali-tools-* packages. Browse them with apt search kali-linux and apt search kali-tools.

Tool categories at a glance

The Kali menu mirrors the stages of a security assessment. Typical categories: network and port scanning (Nmap), traffic analysis (Wireshark, tcpdump), web application testing (OWASP ZAP, Burp Suite Community, Nikto), wireless auditing (Aircrack-ng, which needs a compatible adapter), password auditing (John the Ripper, Hashcat) and forensics (Autopsy, The Sleuth Kit). Each of them is legitimate only within the scope you are authorized to test.

Do website owners need Kali Linux?

Usually not. Most site owners and web developers want answers to a few concrete questions: are internal files exposed, are security headers set, is the certificate valid, which server ports are reachable from the internet. That does not require installing a pentest distribution; an external check of your own domain is enough. The full routine is in our website security checklist.

How to check your own site without Kali

Kali makes sense when you need an in-depth audit from inside your own network or application and have the time and authority to do it.

Frequently asked questions

Is Kali Linux free?

Yes. All official images are free to download from kali.org, no registration required.

What is the default password for Kali Linux?

kali / kali for the pre-built virtual machines and the live image. With the installer, you choose it. Change it with passwd after the first login.

Can I use Kali Linux as my main operating system?

You can, but it is not recommended. It is designed for security work; Ubuntu, Debian or Fedora are better daily drivers.

Is it illegal to have Kali Linux installed?

No. Owning and learning the software is legal. Using it against systems without the owner's permission is what breaks the law.

How do I check which Kali version I have?

Run cat /etc/os-release. Keep it current with sudo apt update and sudo apt full-upgrade.

Check your website right now

Check your site's security →
More articles: Security
Security
How to Check a Website for Malware: 4 Layers and a Cleanup
01.04.2026 · 1 217 views
Security
Cookie Security Flags: HttpOnly, Secure, SameSite
14.03.2026 · 620 views
Security
Web Server Security Hardening Checklist: Nginx and Apache
16.03.2026 · 615 views
Security
How to Check a Website for Fraud: 12 Signs of a Phishing Site
18.07.2026 · 523 views