Features & Tools

RedBSD ships with a complete, organized red team toolkit on top of a FreeBSD base. The category overview and complete provisioning inventory below reflect the tools RedBSD installs.

Base System

A FreeBSD base with an XFCE desktop, SDDM login manager, VMware Tools integration, local development tooling, and custom boot/UEFI branding — tuned for VM-based labs.

Xorg D-Bus XFCE desktop SDDM Firefox ESR FoxyProxy Thunar Engrampa VMware Tools ImageMagick
Desktop & Engagements

A themed Xfce workspace with desktop utilities and an included engagement workspace.

Greybird Dark Papirus icons Ristretto Xfce Screenshooter pavucontrol VS Code Geany Mousepad RTFMv2 Community Edition
Shell & Workspace

Interactive shells, privilege helpers, terminal multiplexers, and everyday file utilities.

bash zsh sudo doas vim nano tmux screen tree lsof htop ripgrep zip unzip 7-Zip rsync curl wget
Network & Services

Network discovery, traffic inspection, containers, web services, and Windows interoperability.

bind-tools nmap socat tcpdump whois Podman podman-compose Apache nginx lighttpd PHP Samba Kerberos OpenLDAP client FreeRDP
Runtimes & Build Tools

Language runtimes and native build tooling for compiling, adapting, and running security tools.

Python pip / virtualenv Ruby Perl Node.js / npm Go Rust OpenJDK .NET SDK Lua GCC LLVM GDB Git CMake Ninja Zig MinGW-w64
Data & Cryptography

Data-processing, database, certificate, and cryptographic utilities for assessments and tooling.

jq yq xmlstarlet SQLite DB Browser for SQLite PostgreSQL client MariaDB client Redis GnuPG OpenSSL Certbot ca_root_nss
Wireless Attacks

Audit and exploit Wi-Fi networks with the classic and modern wireless toolkits.

aircrack-ng nmap reaver pixiewps kismet bettercap wifite2
Command & Control

Sliver is installed for adversary simulation and post-exploitation. Deployment notes are also supplied for Havoc, Covenant, and optional Mythic.

Sliver (server & client)
Social Engineering

Run phishing campaigns and social engineering assessments end to end.

GoPhish evilginx2 SET
Privilege Escalation

Enumerate and exploit local privilege escalation paths on Linux and Windows targets.

PEASS-ng pspy sudo_killer LES GTFOBins checksec
Tunneling & Pivoting

Pivot through compromised hosts and tunnel traffic across network boundaries.

proxychains-ng chisel ligolo-ng sshuttle rpivot socat redsocks
Reverse Engineering

Disassemble, debug, and exploit binaries with a complete RE toolchain.

radare2 rizin GDB + GEF pwntools ROPgadget checksec
Wordlists

Generate and customize wordlists for password attacks and content discovery.

SecLists rockyou.txt crunch cupp CeWL hashcat John the Ripper
Cloud & Container Security

Assess Kubernetes clusters, containers, and cloud accounts for misconfigurations.

kubectl trivy AWS CLI pacu ScoutSuite Prowler Azure CLI cloudfox Helm
Reporting

Document findings and produce client-ready reports without leaving the distro. RTFMv2 Community Edition is bundled for engagement notes and tracking.

RTFMv2 Community Edition CherryTree pwndoc pandoc wkhtmltopdf
Active Directory Exploitation

Enumerate, attack, and move laterally across Active Directory environments.

impacket kerbrute pypykatz evil-winrm adidnsdump enum4linux-ng NetExec bloodhound-python
OSINT

Gather intelligence on people, domains, and infrastructure during recon.

recon-ng Sherlock h8mail PhoneInfoga SpiderFoot theHarvester Holehe Photon
Web Application Testing

Optional local installer for Burp Suite when its vendor-supplied JAR is included with the RedBSD bundle.

Burp Suite (optional)
Local AI

Optional on-device language-model inference for lab workflows, with a lightweight starter model.

llama.cpp llama-server Qwen3-1.7B GGUF model