
Kali Linux is used for penetration testing, security auditing and digital forensics: it is a free Debian-based distribution from OffSec (formerly Offensive Security) that ships hundreds of pre-packaged tools for checking how well systems are protected. It is legal to download and use, but only against systems you own or have written permission to test.
What is Kali Linux used for?
Under the hood Kali is Debian with a curated repository of security tools: network scanners, traffic analyzers, web application scanners, password auditing utilities and forensic toolkits. You could install most of these programs on Ubuntu or plain Debian yourself, but in Kali they are already packaged, updated from one repository and tested to work together. That convenience is the whole point of the distribution.
Kali is the successor to BackTrack and follows a rolling release model. Packages update continuously, and every quarter the project publishes a snapshot numbered by year and release (for example, 2025.1). So "the latest version" simply means downloading the current image and keeping it updated with apt.
What are the main uses of Kali Linux?
- Penetration testing — authorized, contract-based tests of networks and applications, ending in a report for the system owner.
- Internal security auditing — administrators inventorying their own networks: which hosts exist, which services listen, what crosses the wire.
- Digital forensics and incident response — examining disk and memory images after a breach.
- Training — students and CTF players practising on intentionally vulnerable lab machines.
Why would someone use Kali Linux instead of a regular distro?
Because the tooling is ready on first boot and maintained by one team. A tester who arrives at a client site, or spins up a lab for a week-long engagement, does not want to spend a day compiling tools and resolving dependencies. Kali also ships as ready-made virtual machines, a live USB image, containers and a WSL package, so the same environment can run almost anywhere.
Is Kali Linux for hackers?
It is for security professionals, which is not the same thing as a "hacker OS". Kali does not break into anything by itself; every tool in it is also available elsewhere, and results depend entirely on the operator's skill and authorization. It is also a poor daily driver. The developers themselves do not recommend Kali as a general-purpose desktop: its defaults are tuned for auditing work, not for office apps, gaming or media. If you want Linux for everyday use, pick Ubuntu, Debian or Fedora, and keep Kali in a virtual machine.
| Question | Kali Linux | Ubuntu / Debian |
|---|---|---|
| Main purpose | Security testing and forensics | General-purpose desktop and server |
| Security tools preinstalled | Yes, grouped into metapackages | No, installed individually |
| Release model | Rolling, quarterly snapshots | Fixed releases (Ubuntu LTS, Debian stable) |
| Good as a daily driver | Not recommended | Yes |
| Best way to run it | Virtual machine or live USB | Bare metal or VM |
Is Kali Linux legal or illegal?
Kali Linux itself is legal. It is open-source software distributed openly and used in universities, training courses and professional security work. What can be illegal is what you do with it.
- Use the tools only on systems you own, or on systems whose owner has given you written permission with a defined scope: which addresses, which techniques, which time window.
- In the United States, unauthorized access to computers falls under the Computer Fraud and Abuse Act; in the United Kingdom, under the Computer Misuse Act 1990; most countries have equivalent laws. In Russia, unauthorized access to computer information is prosecuted under chapter 28 of the Criminal Code.
- "I was only scanning" is not a defense. Scans and login attempts show up in the target's logs, and hosting providers act on abuse reports.
- Legitimate work looks like a signed engagement or an internal authorization, an agreed scope and a written report for the system owner.
To practise legally, build an isolated lab of your own virtual machines (intentionally vulnerable images such as Metasploitable or DVWA exist for exactly this) or join CTF platforms where participation implies consent.
Kali Linux download: which image to choose
Download only from the official Get Kali page. Re-packaged ISOs from file-sharing sites are a bad idea for a system you will run with administrator rights. For a typical PC or laptop choose amd64; for Apple Silicon Macs and ARM boards choose arm64.
- Pre-built virtual machines for VirtualBox, VMware, Hyper-V and QEMU — the fastest way to start.
- Installer ISO — the Debian installer with a choice of desktop and tool sets.
- Live image — boots from USB without touching the hard drive.
- WSL, containers, cloud and NetHunter for Windows, Docker/LXC, cloud providers and Android devices.
Every file on the download page has a SHA256 checksum next to it. Compare it before using the image:
# Windows PowerShell
Get-FileHash .\kali.iso -Algorithm SHA256
# Linux
sha256sum kali.iso
# macOS
shasum -a 256 kali.iso
Replace kali.iso with the actual file name. If the hash differs, download again.
How to install Kali Linux in VirtualBox
- From the Virtual Machines section of the download page, get the VirtualBox image and extract the
.7zarchive (7-Zip on Windows works). - In VirtualBox choose Machine → Add and select the extracted
.vboxfile. - Give the VM at least 2 GB of RAM and two CPU cores if your host can spare them.
- Boot, log in with the default credentials below and change the password immediately.
- Take a snapshot so you can roll back after experiments.
If you prefer the installer ISO, create a new VM with type Linux and version Debian (64-bit), and allocate at least 20 GB of disk. For a lab, switch the network adapter from NAT to Host-only or Internal Network so Kali only sees your own machines. Hypervisor settings, network modes and snapshots are covered in detail in our VirtualBox guide. If clipboard sharing or display resizing does not work after an ISO install, run:
sudo apt update
sudo apt install -y virtualbox-guest-x11
Kali Linux on Windows with WSL
For command-line tools only, run this in an elevated PowerShell:
wsl --install -d kali-linux
The WSL image is minimal, so add tools with a metapackage: sudo apt update && sudo apt install -y kali-linux-default. Networking tools have limitations under WSL because the subsystem has no direct access to network adapters.
Default Kali Linux username and password
The pre-built virtual machines and the live image use kali / kali, as listed on the official Default Credentials page. An installer-based system has no default password: you set it during installation. Root login is not the default; administrative commands go through sudo.
Change the default password right after the first login:
passwd
This matters most if you enable SSH or put the VM on a shared network, because kali/kali is one of the first pairs bots try. If you plan to reach the VM over SSH, switch to key-based login as described in our SSH key setup guide.
First commands after installing Kali
sudo apt update
sudo apt full-upgrade -y
cat /etc/os-release
Tools are grouped into metapackages: kali-linux-default (the standard set), kali-linux-large, kali-linux-everything and kali-linux-headless for systems without a desktop, plus themed kali-tools-* packages. Browse them with apt search kali-linux and apt search kali-tools.
Tool categories at a glance
The Kali menu mirrors the stages of a security assessment. Typical categories: network and port scanning (Nmap), traffic analysis (Wireshark, tcpdump), web application testing (OWASP ZAP, Burp Suite Community, Nikto), wireless auditing (Aircrack-ng, which needs a compatible adapter), password auditing (John the Ripper, Hashcat) and forensics (Autopsy, The Sleuth Kit). Each of them is legitimate only within the scope you are authorized to test.
Do website owners need Kali Linux?
Usually not. Most site owners and web developers want answers to a few concrete questions: are internal files exposed, are security headers set, is the certificate valid, which server ports are reachable from the internet. That does not require installing a pentest distribution; an external check of your own domain is enough. The full routine is in our website security checklist.
How to check your own site without Kali
- Security scanner — checks security headers and whether the
.gitdirectory or.envfile is exposed. - SSL check — your domain's certificate.
- Port scanner — for your own host only: shows which ports are reachable from outside. What to do with the results is explained in how to check open ports.
Kali makes sense when you need an in-depth audit from inside your own network or application and have the time and authority to do it.
Frequently asked questions
Is Kali Linux free?
Yes. All official images are free to download from kali.org, no registration required.
What is the default password for Kali Linux?
kali / kali for the pre-built virtual machines and the live image. With the installer, you choose it. Change it with passwd after the first login.
Can I use Kali Linux as my main operating system?
You can, but it is not recommended. It is designed for security work; Ubuntu, Debian or Fedora are better daily drivers.
Is it illegal to have Kali Linux installed?
No. Owning and learning the software is legal. Using it against systems without the owner's permission is what breaks the law.
How do I check which Kali version I have?
Run cat /etc/os-release. Keep it current with sudo apt update and sudo apt full-upgrade.