Elif Linux Distribution is a Kali-based, XFCE-first CTF workstation tuned for legal security competitions (Reverse Engineering, PWN, Cryptography). It builds a bootable ISO for VMware Workstation Pro using Kali live-build.
- Name: Elif Linux Distribution
- ISO label:
ELIF_LINUX - Hostname:
elif - Default user:
noor(sudo enabled; password required) - Desktop: XFCE with a consistent “space dark” theme
- Debian-based builder VM (Kali recommended)
- 4+ cores, 16+ GB RAM, 40+ GB free disk
- Internet access to Kali repositories
make bootstrap
make allThe ISO is written to build/elif-linux.iso with SHA256 in build/ISO.sha256.
- Create a new VM and select the ISO.
- Use UEFI firmware (recommended).
- Install using the on-ISO installer option.
- Login with
noor/noorand change password immediately.
- Firmware: UEFI
- CPU: 4 vCPU
- RAM: 8–16 GB
- Disk: 80 GB (thin-provisioned)
- Display: enable 3D acceleration
- Guest isolation: enable copy/paste and drag/drop if desired
Run scripts/vmware-notes.sh for a printable summary.
The elif-firstboot.service runs once after install to:
- Ensure user
noorexists and is insudo - Apply XFCE theme defaults and wallpaper
- Populate
/etc/skelconfigs and~/CTF/templates - Update icon and desktop caches
- Ensure wordlists presence and optionally extract
rockyou.txt.gz
- Reverse: Ghidra, radare2, Cutter, binutils, patchelf, apktool, jadx
- PWN: gdb, gdb-multiarch, pwndbg, pwntools, ROPgadget, qemu, compilers, libc6-dbg
- Crypto: sage (if available), sympy, z3, pycryptodome, gmpy2, pari-gp
- Wordlists: seclists, wordlists (rockyou extraction script included)
- QoL: git, curl, wget, ripgrep, fd, bat, eza, jq, tmux, docker (installed, not enabled)
- VMware: open-vm-tools + desktop integration
Provide a legal installer and run:
sudo /usr/local/bin/elif-install-ida.sh /path/to/ida-installer.runCursor is not bundled. Provide the official .deb or URL and run:
sudo /usr/local/bin/elif-install-cursor.sh /path/to/cursor.debSettings and recommended extensions templates are under /usr/local/share/elif/configs/cursor/.
sudo apt-get update
sudo apt-get install -y git make
git clone <your-repo> elif-linux
cd elif-linux
make bootstrap
make alllibc6-dbgis installed for local debugging.- For per-challenge libc isolation, use the provided libc from the challenge and run under
LD_PRELOADto avoid mismatched system symbols.
make verifysudo /usr/local/bin/elif-self-test.shsudo /usr/local/bin/elif-rockyou-setup.shIf you install GEF separately, switch default gdbinit:
sudo /usr/local/bin/elif-use-gef.shThis distro is intended for legal CTFs and authorized security labs only. Do not use it for unauthorized access.