Stingray Labs presents

ArxOSthe security workstation, rebuilt from the kernel up.

A performance and security operating system on a clean Arch Linux base. It ships a native package manager, a live arsenal of security tools, a tuned kernel, fail-closed anonymity, and a Control Center that runs the whole machine.

Arch base · rolling linux-arxos 7.2.0 · tuned kernel 2,858 security tools Fail-closed privacy
Why ArxOS

Most security distros bolt tools onto someone else's desktop. ArxOS is tuned as one system, and ships things no other distro does.

Kernel, package manager, tools, privacy, and the desktop are built together and tuned together, tested on real hardware before every release. Every card below is engineering specific to ArxOS, verified working on this exact system.

Fast where it counts

Compiled native code handles the heavy paths: a repeated search or lookup returns in milliseconds, and an install runs the real transaction at full native speed, with a live per-package view instead of a wall of scrollback.

Tuning compiled into the kernel

linux-arxos carries a responsive scheduler, full preemption, a high timer rate, and faster networking compiled in, so the tuning survives every update instead of living in a fragile dotfile you have to reapply.

Small, then as big as you want

The base install is lean with a default loadout of essential tools. Pull the full 2,858-tool arsenal only when a job needs it.

Private by default, verified not assumed

Full-disk encryption, a command guard that vets every command, and fail-closed anonymity compiled into the kernel itself. anond proves the kill switch, Tor, and DNS pin are all actually up before it ever reports active.

Red and blue on one machine

Offense, defense, and forensics share one tuned base, so you switch tasks without switching computers.

Exclusive to ArxOS

arx's foreign-package installer scans every .deb/.rpm maintainer script for danger before it runs, auto-imports the AUR's missing GPG signing keys instead of failing cold, and every browser ships wired so WebRTC and DNS cannot quietly route around your anonymity. No other distro does all three.

What's inside

Everything the workstation needs, built by us.

Each part is an ArxOS-native tool, self-updating, tested on the machine before it ships. No grab-bag of unmaintained scripts.

arx, the package manager

One command for the official repositories, the AUR, and local .deb / .rpm / .AppImage files. It self-heals keyring, mirror, and database errors, and shows a clean per-package loader while it works.

arx install · update · weapons

Control Center

A native app that runs the whole system: live stats, updates, the arsenal, kernels, direct CPU control, a live network panel with port hardening, and privacy, all in one glass deck.

native · Rust + Tauri

The arsenal

2,858 security tools, organised by category. Grab a ready loadout (default, top 10, or the full set) or install a single category live, with the repository set up on the fly and torn down when it finishes.

bug bounty · offense · defense · research

Tuned kernel

Two ArxOS kernels on the latest base: a responsive default and a real-time build. Live patching, kernel-level privacy primitives, and fast device access are compiled in.

linux-arxos 7.2.0

anond privacy

Whole-system anonymity, fail-closed: the kill switch is armed before Tor and removed last, DNS is pinned to Tor, IPv6 is dropped, and an optional i2p overlay rides alongside. It proves each layer before it reports active.

Tor · i2p · verified

Guarded shell

A zero-trust command guard scans every command before it runs and blocks the dangerous ones, so a bad paste or a hostile script does not get a free shot.

pre-exec scan

Hardened browsers

Firefox, Waterfox, and Brave ship pre-patched: WebRTC cannot leak your real IP even through a transparent proxy, built-in DNS-over-HTTPS is off so lookups defer to anond's Tor-pinned resolver instead of quietly bypassing it, and every telemetry and tracking channel is closed. Reapplied automatically after every browser update.

WebRTC-safe · DNS deferred to anond · auto-reapplied
The kernel

Two kernels. Pick the one your work needs.

Both share the same tuning and the same tools. They differ in one thing: how they handle timing. The default is installed and starts on its own; the real-time build sits next to it, ready at the boot menu.

linux-arxos default · 7.2.0

The daily driver. Balanced, fast, and responsive for desktop use, security work, and servers: high throughput with low latency. This one starts by default.

Use it for almost everything.

linux-arxos-rt real-time · 7.2.0

Hard real-time timing. Predictable, bounded response for radio, SDR, and wireless capture, where a late sample is a lost sample. It trades a little raw throughput for timing you can count on.

Use it for RF, SDR, and live signal work.

What every ArxOS kernel carries

Live kernel patchingSecurity and stability fixes apply to the running kernel without a reboot, so the machine stays current without downtime.
Kernel-level privacyModern packet filtering, WireGuard, network and user isolation, and encrypted key storage are compiled in, so anonkit works at the kernel level itself.
Low-level device accessFast, direct device input and output, including raw USB and a high-performance I/O path, so hardware tools talk to devices quickly and reliably.
Performance baseA responsive scheduler, faster networking, a high timer rate, full preemption for low latency, and better memory behaviour under load.
Performance

Fast on the first run. Instant on the next.

arx remembers what it reads and refreshes the moment your package databases change, so a repeated search or lookup returns in milliseconds with results that stay exactly correct.

9ms
A repeated package search
the standard tool: ~310 ms, every time
~34×
Faster on repeated searches
with the exact same results
10ms
A repeated package lookup
the standard tool: ~285 ms
1
Tool for repos, the AUR, and local files
no extra helper to install

Measured on ArxOS against the standard Arch tools on the same package databases. The first search of the day matches the standard tool; every repeat after it is near-instant.

One command

arx. One command for the system and the tools.

arx
# update the system, the kernel, and the ArxOS tools, in one step
$ arx update

# ask for several at once. arx finds each one for you:
$ arx install obs vlc google-chrome
  arch repo (2)  obs  vlc
  AUR (1)       google-chrome  (build from source)
  proceed? [Y] all found  [s] select  [n] stop

# grab a whole category of security tools, live
$ arx weapons install default

One package manager. Everything in reach.

arx installs from the official repositories and the AUR without any extra helper. Ask for several packages at once and arx sorts them for you: what is in the repositories, what needs building, and what was not found. You choose how to proceed.

  • Official repositories and the AUR, built in. No second tool to install.
  • Installs .deb, .rpm, .AppImage, and archive files alongside Arch packages.
  • Checks AUR build files for risky patterns before it builds them.
  • Repairs keyring, mirror, lock, and database errors on its own.
  • Installs the security arsenal by category, or a ready loadout, in one line.
See it

One identity, from first boot to the desktop.

The ArxOS look carries all the way through: the boot splash, the menu, the lock screen, the desktop, the terminal, and the native Control Center that runs the whole system. Tap any shot for the full view.

Before you start

System requirements.

ArxOS runs on any 64-bit PC from the last decade, and on virtual machines. These are comfortable minimums; more memory and an SSD make it noticeably snappier.

Processor
64-bit x86_64
Any Intel or AMD CPU from the last ~10 years.
Memory
4 GB minimum
8 GB or more recommended for heavy tools.
Disk
30 GB free
An SSD is recommended. More for the full arsenal.
Firmware
UEFI or BIOS
Both boot modes are supported.
Installer
8 GB USB stick
To flash the ISO and boot from it.
Graphics
Any GPU
Intel, AMD, or NVIDIA. Works in a VM too.
Installation

From download to desktop, step by step.

New to Linux? Follow these in order. You will download one file, put it on a USB stick, boot from it, try ArxOS live, then install it. It takes about twenty minutes, most of which is the computer copying files.

1

Download the ISO

The ISO is one file (about 7.6 GB) that contains the whole operating system. Download it from the ArxOS releases, then, on the same page, download the SHA256 checksum next to it.

Verify it downloaded cleanly. On Linux or macOS run sha256sum arxos-*.iso (or shasum -a 256) and check the number matches the checksum file. On Windows: certutil -hashfile arxos.iso SHA256. If they match, the file is intact.
2

Put the ISO on a USB stick

This "flashes" the ISO onto an 8 GB or larger USB stick and makes it bootable. It erases everything on the stick, so use an empty one. Pick whichever tool matches your current computer.

Ventoy easiestGet itWindows, Linux, macOS. Set it up once, then copy ISOs on like normal files forever after.
1. Open the download page above. Under Download, take ventoy-x.x.xx-windows.zip on Windows or ventoy-x.x.xx-linux.tar.gz on Linux.
2. Extract the archive (right-click → Extract All on Windows; tar -xf ventoy-*.tar.gz on Linux).
3. Plug in your USB stick. Run Ventoy2Disk.exe (Windows) or sudo ./VentoyGUI.x86_64 (Linux) from the extracted folder.
4. In the Device dropdown, pick your USB stick. Check the size matches your stick, since this erases it.
5. Click Install, confirm the two warnings. It finishes in about 30 seconds. This is the only time you ever format it.
6. The stick now shows up as a normal drive named Ventoy. Drag arxos.iso onto it, wait for the copy to finish, and eject safely. Done.
balenaEtcherGet itWindows, macOS, Linux. Point-and-click, three buttons.
1. Download from the link above and install it (on Linux, mark the .AppImage executable: chmod +x balenaEtcher-*.AppImage, then run it).
2. Plug in the USB stick and open Etcher.
3. Click Flash from file and select your downloaded arxos.iso.
4. Click Select target, tick your USB stick, then Select. Check the size matches, since this erases it.
5. Click Flash! and enter your password if asked. It writes, then verifies on its own.
6. Wait for "Flash Complete", then unplug. Ignore any Windows popup asking to format the drive.
RufusGet itWindows only. Portable, nothing to install.
1. On the link above, scroll to Download and take rufus-x.x.exe. Double-click it; there is no installer.
2. Plug in the USB stick. Rufus picks it up automatically under Device. Confirm it is the right one.
3. Next to Boot selection, click SELECT and choose your arxos.iso.
4. Leave Partition scheme on GPT and Target system on UEFI for any PC from the last decade. Only choose MBR/BIOS if the machine is genuinely old.
5. Click START. If it asks about ISOHybrid, keep Write in ISO Image mode and click OK. Accept the erase warning.
6. Wait for the bar to read READY, then close Rufus and unplug.
dd (Linux / macOS)Already installed. Fast, but it does exactly what you tell it, so identify the disk carefully.
1. With the USB unplugged, run lsblk (Linux) or diskutil list (macOS) and note what is listed.
2. Plug the USB in, run the same command again. The new entry is your stick, for example /dev/sdb or /dev/disk3. Match it by size.
3. Unmount it (do not eject): sudo umount /dev/sdX* on Linux, diskutil unmountDisk /dev/diskN on macOS.
4. Write it: sudo dd if=arxos.iso of=/dev/sdX bs=4M status=progress oflag=sync. Replace /dev/sdX with the whole disk, no partition number.
5. Wait for dd to print the bytes-copied summary, then run sync and unplug. Writing an 8 GB image takes several minutes with no output until it finishes.
No spare USB stick? Run it in a virtual machine instead: skip straight to booting the .iso as a virtual disc, no flashing needed. QEMU/KVM (Linux): qemu-system-x86_64 -enable-kvm -m 4096 -smp 2 -cdrom arxos.iso -drive file=arxos.qcow2,format=qcow2, or use virt-manager's GUI. VirtualBox: New VM (Linux, Arch 64-bit), 4 GB RAM, 30+ GB disk, then Settings → Storage → attach arxos.iso to the optical drive. VMware Workstation Player: New VM → "Installer disc image file (ISO)" → point at arxos.iso; choose "I will install the OS later" first if the wizard does not recognise ArxOS, then attach the ISO. In all three, boot the VM straight into the live desktop, same as real hardware.
3

Boot from the USB stick

Leave the stick plugged in and restart the computer. As it powers on, tap the boot-menu key repeatedly until a menu appears, then choose the USB stick (it often shows the brand name, or "USB"). Running in a VM instead? It boots straight from the attached ISO, so skip to the next step.

The boot-menu key depends on the maker: commonly F12, Esc, F10, or F9. To reach firmware settings it is often Del or F2. If Windows loads instead, restart and try the next key. In firmware, turn Secure Boot off if the USB will not start.
4

Try it live

ArxOS starts straight into a full live desktop running entirely off the USB stick. Nothing on your computer has changed yet. Look around, open the terminal, test your Wi-Fi and touchpad. When you are ready, double-click Install ArxOS on the desktop.

First double-click may ask to trust the launcher. The desktop shows an "Untrusted application launcher" prompt the first time. Choose Trust and Launch (or right-click the icon and pick Allow Launching) and it opens normally from then on.
5

Install ArxOS

The installer walks you through a few short screens: language, region and keyboard, then the disk. Choose Erase disk for a clean install, and tick Encrypt the system to protect the whole disk with a passphrase. Create your user, review the summary, and start. The computer copies the system across; this is the part that takes a little while.

Encryption is worth it. With full-disk encryption on, a lost or stolen laptop is just an unreadable brick without your passphrase. Choose a passphrase you will remember, because it cannot be recovered.
6

First login

When it finishes, remove the USB stick and restart. If you turned on encryption, you will be asked for your disk passphrase as the machine starts. Then the login screen appears: sign in with the user you created, and you are on your own ArxOS desktop, ready to work.

7

Run your first update

Do this before anything else. The ISO is a snapshot from build day; running an update brings the system, the kernel, and every ArxOS tool fully current the moment you log in. Open a terminal and run arx update, or open the Control Center and use the Update panel, then Update everything.

Not optional. Security patches, kernel fixes, and tool updates land continuously. Skipping this step means starting on day-one software with day-one bugs already fixed upstream.

Get ArxOS.

ArxOS is built in the open by Stingray Labs, and each release is made complete before it ships. Follow the build, read the docs, and grab the ISO when your download is ready.

Starting from zero? The free ArxOS beginner program runs from computer fundamentals through Linux, networking, C, assembly, and exploitation, with a daily schedule, labs, and a progress tracker. No subscription, every resource legitimately free.