Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Kali Linux

Kali

Reviews from AWS customer

26 AWS reviews

External reviews

16 reviews
from

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    Ciyagi Ciyagi

Runs efficiently across devices and streamlines penetration testing workflows

  • November 13, 2025
  • Review provided by PeerSpot

What is our primary use case?

I use Kali Linux for penetration testing, network security, and application security, utilizing various tools available on the platform.

The primary use case for Kali Linux is to achieve anonymity, which allows me to maintain significant control over my security measures. My day-to-day use case involves penetration testing and application security.

What is most valuable?

Kali Linux offers excellent features including being lightweight with low memory usage, easy installation, portability, and multiple architectures such as ARM architecture and server architecture. I can easily install various tools on these architectures and even create my own tools.

Kali Linux has positively impacted my organization because I can utilize various tools on the platform and create custom tools. The architecture is specific enough that I can run Kali Linux on my mobile device and install it on my tablet.

What needs improvement?

Kali Linux could be improved by including more tools.

I would personally like to see improvements in Kali Linux, particularly regarding Grub issues that sometimes occur when installing the VM. Additionally, I have experienced problems when updating Kali Linux from a higher version to a lower version, which resulted in crashes. These Grub issues should be resolved.

I face significant challenges with Kali Linux regarding a major issue with the Grub loader becoming corrupted, which makes it very difficult to recover data.

For how long have I used the solution?

I have been using Kali Linux for more than seven to eight years.

What do I think about the stability of the solution?

Kali Linux is stable based on my experience.

What do I think about the scalability of the solution?

I find Kali Linux very scalable.

How are customer service and support?

There is no customer support available for Kali Linux, so I have no comment on that aspect. However, I hope that customer support should be provided in the future, though I have never attempted to use it.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I previously used Parrot OS before switching to Kali Linux.

How was the initial setup?

I can easily install Kali Linux during the installation process.

What was our ROI?

I have seen a return on investment with Kali Linux, particularly in time-saving.

Kali Linux is a time-saving and cost-saving solution.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Kali Linux is straightforward because it is open source. I simply create a VM, so there are no costs involved.

Which other solutions did I evaluate?

Before choosing Kali Linux, I evaluated Parrot OS.

What other advice do I have?

I would rate Kali Linux an eight out of ten.

I chose this rating because the Grub issue should be resolved, and I would like to see more penetration testing tools added. Parrot OS has some excellent features for anonymity, and other current Linux distributions also have anonymity features that should be included in Kali Linux. My overall review rating for this product is eight out of ten.


    Arka Sarkar

Penetration testing and vulnerability assessments have improved internal processes and client security

  • November 10, 2025
  • Review from a verified AWS customer

What is our primary use case?

I use Kali Linux typically for different report generation based on customers and for queries related to customers. When I am troubleshooting in a live customer node, all of the customer nodes are based on the Linux environment. I need to troubleshoot different issues using basic commands and troubleshooting steps, which are all based on Kali Linux. All servers, virtual and metal servers, are based on Kali Linux only.

Last month, penetration testing was conducted in our organization for security purposes. Due to some issues in the server at that time, we switched from other servers to Kali Linux, and those experiences were very seamless. Identifying vulnerabilities and fixing those in ASAP mode was a very prominent work performed using Kali Linux. The penetration testing was successful due to Kali Linux because it simulated attacks to find and fix vulnerabilities in our systems and networks before malicious actors could exploit them. In terms of penetration testing and security auditing, it helped us significantly.

Kali Linux is used for security auditing purposes and vulnerability assessment purposes.

What is most valuable?

One of the most exciting features about Kali Linux is Wireshark, a network protocol analyzer for monitoring traffic, which is very important in my day-to-day work. We analyze TCP dumps to analyze network issues, port issues, and connectivity issues such as port open and close connections and different problems that may occur. Using Wireshark for TCP dump analysis with Kali Linux is one of the best parts I can see.

The pre-installed toolset is one of the important features of Kali Linux because it comes with around 500-550 penetration testing, security auditing, and digital forensic tools, which are very important to me.

Kali Linux can run directly from a USB drive without installation, which is very ideal for forensic analysis as it prevents accidental data contamination in the host system. This is one important aspect of using Kali Linux.

The vulnerability assessments and auditing capabilities are very strong using Kali Linux because built-in tools such as OpenVAS and Burp Suite enable comprehensive network and application scanning. This helped our clients proactively assess and fix weaknesses. When a vulnerability comes in a particular ICP version, that part is already being fixed in a specific version. The assessments and auditing part of vulnerabilities are one of the important features which helped our organization.

My organization uses Kali Linux as the platform for internal and commercial cybersecurity training programs, such as different certifications. This created an additional revenue stream and ensures that teams have cutting edge skills.

Financial benefits are evident because our organization used Kali Linux to simulate real-world attacks on clients' networks, web applications, and systems to identify vulnerabilities before malicious actors do. In some latest products, our organization made a profit around 213 SEK billion by fixing one vulnerability which could have caused significant damage to our system. This was prevented by using Kali Linux and penetration testing.

Some of our work has already been automated using Kali Linux and some headcount has already been reduced. Though this is not ideal for employees, in terms of today's AI-related market, it reduced costs significantly and made a profit for the organization.

What needs improvement?

Kali Linux can increase its stability. As a rolling release distribution based on Debian testing or unstable, Kali Linux can sometimes experience breakage during updates. More robust testing before pushing updates to the main repositories could help, or offering a more stable branch for users who prioritize reliability over the absolute latest tool versions would be beneficial.

The distribution comes with over 400 penetration testing tools, many of which are never used by an average user. It could use an easier approach with more granular ways to install or remove tool groups or meta-packages.

Kali Linux can optimize resource management. Although Kali Linux is designed to be lightweight, users often report performance issues, specifically when using virtual machines or on less powerful hardware. Improvements could be made in these areas. In our Ericsson environment, we use virtual machines only for live customer servers. Sometimes we experience different issues with performance degradation, especially in virtual machines. These areas can be improved.

Trial packs for one or two months at a cheaper cost would be beneficial to switch from different providers to Kali Linux. This could be explored further.

For how long have I used the solution?

I have been using Kali Linux for about four years.

What do I think about the stability of the solution?

Kali Linux is stable, but it can increase its stability. As a rolling release distribution based on Debian testing, Kali Linux can sometimes experience breakage during updates. This aspect can be improved.

What do I think about the scalability of the solution?

Scalability is absolutely fine with Kali Linux.

How are customer service and support?

Customer support is quite good for Kali Linux. They support within hours by solving the TTs.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used to try different solutions such as Linux Ubuntu and Oracle Linux before switching back.

What other advice do I have?

The vulnerability assessments and auditing capabilities are very strong using Kali Linux because built-in tools such as OpenVAS and Burp Suite enable comprehensive network and application scanning. This has helped our clients proactively assess and fix weaknesses. When a vulnerability comes in a particular ICP version, that part is already being fixed in a specific version. The assessments and auditing part of vulnerabilities are one of the important features which helped our organization. My organization uses Kali Linux as the platform for internal and commercial cybersecurity training programs, such as different certifications. This created an additional revenue stream and ensures that teams have cutting edge skills.

Kali Linux can optimize resource management. Although Kali Linux is designed to be lightweight, users often report performance issues, specifically when using virtual machines or on less powerful hardware. Improvements could be made in these areas. In our Ericsson environment, we use virtual machines only for live customer servers. Sometimes we experience different issues with performance degradation, especially in virtual machines. These areas can be improved.

Trial packs for one or two months at a cheaper cost would be beneficial to switch from different providers to Kali Linux. This could be explored further.

I would recommend that organizations try Kali Linux for several months to understand the changes and then decide according to their organization's specifications and needs before starting to use Kali Linux and purchasing packages on the marketplace. This review has received an overall rating of 9.


    Mathews Daniel

Has accelerated website vulnerability assessments and internal testing with built-in tools and cloud deployments

  • October 27, 2025
  • Review from a verified AWS customer

What is our primary use case?

My main use case for Kali Linux is for security testing, checking websites, security, analyzing malware, and open-source intelligence gathering.

I have WordPress websites, so I want to identify whether they are vulnerable or not. Kali Linux has many inbuilt tools such as WPScan, which I can use readily and analyze whether a website is secure or not, and whether the code running on it is up-to-date or has vulnerabilities. I have used it for checking Wi-Fi security, identifying whether the SSIDs are vulnerable to brute-force attacks or any other cracking attempts.

I have used Kali Linux for penetration testing, bypassing antivirus and gaining access to machines, virtual machines for testing. I have used Metasploit, which is in-built with Kali Linux, and I have utilized many Metasploit exploits and modules to achieve this.

What is most valuable?

Kali Linux has every tool needed to get started in-built, and it comes along with the OS itself. All we need to do is a bit of update and some slight configuration, but everything else is in-built. It doesn't require extensive time configuring things. It's adopted and available everywhere, including cloud, AWS or Azure, where you can readily deploy the images. It's based on Debian Linux, which is one of the most user-friendly flavors of Linux, making it very easy to modify or create new modules.

In my organization, Kali Linux has positively impacted my day-to-day job, where I perform proof of concepts mostly around endpoint security testing or web vulnerability testing. Kali Linux has helped me significantly in simulating penetration testing and other activities. I can pick an exploit from Metasploit or any other Exploit-DB using Kali Linux in-built features. It has saved me considerable time and effort, and since all the tools are open source, I can easily modify and customize them based on my needs.

What needs improvement?

Some tools in Kali Linux lack documentation and details on how to use them, which is one area where it can be improved. It's still advertised as a Linux distro used only for security testing, and many of the tools run as root by default or with the highest privileges. If something could be modified to make it more an everyday OS, activating the security testing part and all other modules on a need-to-activate basis would be very beneficial. Additionally, it could be optimized to suit some low-powered machines.

The UI in Kali Linux could be improved. In the drop-down menus, it takes a while to load. Trimming down the graphics and other animations could focus more on the speed of opening things and menus.

For how long have I used the solution?

I have been using Kali Linux for 12 years.

What do I think about the stability of the solution?

Kali Linux is stable.

What do I think about the scalability of the solution?

Kali Linux is very scalable, and when deployed from the public cloud, it offers every feature available on public cloud scalability as.

How are customer service and support?

The customer support for Kali Linux is good. Since most of the tools and other things are community-based, the documentation and other community support are very good.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I previously used Parrot Linux and BackBox Linux, but these were not up to the mark for what we expected, so we switched to Kali Linux.

How was the initial setup?

I purchased Kali Linux through the AWS Marketplace. My experience with pricing, setup cost, and licensing for Kali Linux has been good. The pricing and the deployment, resource usage are all spot on and clearly defined, making it helpful and useful for me to deploy and calculate costs.

What about the implementation team?

I evaluated Parrot, BackBox Linux, and some options Ubuntu with custom tools before choosing Kali Linux. We felt Kali Linux was the most versatile solution.

What was our ROI?

Kali Linux has provided a very good return on investment. When we needed training for employees, we wanted 20 or 30 instances of Kali Linux. The availability on AWS Marketplace was helpful for us to spin up the VMs and deploy them readily. Once the need was over, we removed the instances, saving costs. If we had installed it on-premises or through other means, it would have incurred significant money and effort to create the VMs, deploy it on machines, and then delete and format it after use. The fact that it was available on public cloud helped us achieve about an 85% return on investment.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Kali Linux has been good. The pricing and the deployment, resource usage are all spot on and clearly defined, making it helpful and useful for me to deploy and calculate costs.

What other advice do I have?

I would advise others looking into using Kali Linux to start with the public cloud instances or marketplace deployment if possible, and to utilize the predefined templates and other options. I would advise going through the documentation since most things are documented. Additionally, use the persistent and other forensic modules that help securely delete data after use.

Kali Linux is a very good project and distro that can be used for multiple applications, including security testing, penetration testing, or even basic learning of information security or IT security.

I rate Kali Linux eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Gaurav Pratap Singh

Has improved penetration testing efficiency through pre-installed tools and supports faster secure deployments

  • September 30, 2025
  • Review provided by PeerSpot

What is our primary use case?

My main use case for Kali Linux is primarily for testing and cybersecurity, specifically for doing penetration testing on applications and network applications that we utilize for network monitoring.

A specific penetration test I performed using Kali Linux was for the application related to DDI, which encompasses DNS, DHCP infrastructure, and network monitoring as well as authentication for Cisco ISE, during which I used tools such as Hydra, Nmap, Ncat, and Wireshark to capture and analyze network packets.

Kali Linux fits into my team because I mainly work with network tools and focus primarily on DNS; it plays a crucial role in penetration testing and ensuring that my applications are secure against attacks through various cybersecurity criteria.

What is most valuable?

The best features Kali Linux offers include its Debian-based architecture and being open source, which is important for many reasons, such as allowing for live USB boot and custom ISOs, making penetration testing simpler with comprehensive pre-installed toolsets such as Nmap, useful for vulnerability scanning.

The live USB and custom ISO options help me specifically as they allow for quick access to a wide selection of pre-installed security tools, saving me time on installations and configurations through live USB boot functionality, which lets me get up and running quickly.

The integration of cloud and containers within Kali Linux is something I wish more people knew about, as it allows for utilizing containerized versions that provide scalability and eliminate the need for a virtual machine setup.

Kali Linux has positively impacted my organization by improving efficiency in penetration testing; its open-source nature permits extensive customization and inclusion of numerous comprehensive pre-installed tools, contributing to a secure network environment with effective monitoring of network applications.

The outcomes from using Kali Linux in our organization are significant; we experienced reduced cybersecurity attacks and improved application security, leading to decreased attack surfaces and quicker testing cycles that enabled faster launches and installations.

What needs improvement?

There are areas for improvement in Kali Linux, particularly regarding its use of the Linux kernel, which requires external additional patching, and the fact that network services are disabled by default, which complicates usage; enhancing user-friendliness through more GUI-based tools and better integration could be beneficial.

While Kali Linux is open source, it lacks vendor support, and I believe that improving documentation and community engagement is essential, making it more user-friendly and encouraging the use of GUI tools can significantly enhance the overall experience.

For how long have I used the solution?

I have been using Kali Linux for around five years, starting in 2018 or 2019, and I continue to use it until 2024, with plans to keep using Kali Linux starting in January 2025.

Which solution did I use previously and why did I switch?

Before switching to Kali Linux, we used Fedora for penetration testing. The decision to move to Kali Linux was influenced by its open-source nature, which reduced costs while facilitating easier automation with DevOps tools.

What was our ROI?

Integrating Kali Linux with DevOps tools has resulted in reduced operational costs due to automated test cases, making it a worthwhile investment with significant returns by decreasing the attack surface area and the frequency of attack incidents.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing for Kali Linux has been positive, as it operates under an open-source model with setup costs primarily related to hardware and virtual machines, eliminating the need for vendor-specific licenses.

Which other solutions did I evaluate?

We evaluated alternatives to Kali Linux, including Parrot OS, BlackArch, BackBox, and the Network Security Toolkit (NST), but Kali Linux was chosen for its stability, open-source nature, and strong community support.

What other advice do I have?

Kali Linux's scalability is commendable; it allows for easy expansion through containerized versions and custom ISOs, although support is primarily dependent on the community rather than vendor assistance.

My advice for others looking into using Kali Linux is to ensure they have a strong foundation in Linux knowledge and are familiar with the various toolsets available within Kali Linux so that they can select the right tools for their specific needs.

I believe Kali Linux is a valuable open-source tool with great potential for growth through community involvement, and continuous development can enhance its position as a leading solution for penetration testing.

On a scale of one to ten, I rate Kali Linux an eight out of ten.


    Aditya Pillai

Has helped me learn penetration testing through hands-on tasks and faster workflows

  • September 27, 2025
  • Review provided by PeerSpot

What is our primary use case?

I mainly use Kali Linux for educational purposes, such as learning pen testing and Linux fundamentals.

I have been using Kali Linux for the TryHackMe section and applying that learning into different automated scenarios of pen testing that are available on the TryHackMe website.

I haven't used Kali Linux for my organization, only for my learning purposes.

What is most valuable?

Since Kali Linux is a security-focused Linux distro, that would be its main advantage compared to Ubuntu or Arch Linux.

The overall focus on security in Kali Linux is what I find most useful.

TryHackMe has an inbuilt Linux distro for doing the assigned tasks, but sometimes network issues may arise or lag may occur. I use Kali Linux because it is fast and there are no hindrances. It provides quick results and helps me gain a deeper understanding of how something works.

What needs improvement?

It would be helpful if Kali Linux could be involved in more systems or laptops. Windows is a standard for many laptops and comes pre-installed on many devices available in the market. If Kali Linux could do the same and increase their reach to better areas, it would be beneficial.

They could improve Kali Linux's UI/UX. They have been following a standard UI/UX. They could add more options, similar to how CachyOS distro of Arch Linux has many different UI options to select from. Making Kali Linux more customizable would allow users to personalize it to their style.

Many users utilize Kali Linux through virtual machines. Sometimes Kali Linux has issues detecting hardware such as inbuilt or external Wi-Fi adapters. Improving device detection would be beneficial.

For how long have I used the solution?

I have been using Kali Linux for a couple of years.

What do I think about the stability of the solution?

Kali Linux is pretty stable.

What do I think about the scalability of the solution?

With enough resources, Kali Linux can handle enough tasks.

Which solution did I use previously and why did I switch?

I used Ubuntu before. I wasn't aware of Kali Linux when I first started. I was using Ubuntu for learning about cybersecurity and pen testing. Then I discovered Kali Linux.

I compared Ubuntu and Kali Linux, as there weren't many security-focused Linux distros available.

How was the initial setup?

Kali Linux is free software, an operating system that's available to download without any cost or licensing fees.

What was our ROI?

Kali Linux has helped me learn faster and understand concepts better. You get a sense of appreciation when completing tasks on your own machine without help or hints from available tools or operating systems, with minimal guidance.

I have saved time by avoiding the lag I sometimes face on the TryHackMe in-built machine, and I have learned more efficiently.

What's my experience with pricing, setup cost, and licensing?

Kali Linux is free software, an operating system that's available to download without any cost or licensing fees.

What other advice do I have?

Other than increasing my knowledge of the Linux distro, Kali Linux has helped me in automated scenarios and increased my knowledge in cybersecurity pen testing. I am still learning.

I would recommend starting with Ubuntu, learning basic Linux commands and Linux-related knowledge, including Debian. Then make the switch to Kali Linux when ready, starting with small tasks before moving on to bigger things.

On a scale of 1-10, I rate Kali Linux an 8.


    NilutpalDutta

Provides valuable real-time data scanning for vulnerability assessment

  • August 29, 2025
  • Review from a verified AWS customer

What is our primary use case?

We have some entirely backend services that function as an integration layer, where multiple applications exchange data through it. For any frontend and API control such as Acunetix or Qualys, they are not supported for those kinds of backend services. For that purpose, we are using Kali Linux. Kali Linux has the capability of real-time data scanning for vulnerability assessment for backend services. That is actually very far more valuable.

For backend service, Kali Linux is a very good tool, so I can recommend it for that.

What is most valuable?

Kali Linux has the capability of real-time data scanning for vulnerability assessment for backend services. That is actually very far more valuable.

The toolset on the security framework in Kali Linux is fulfilling our purpose of doing the assessment. We are good with that.

Kali Linux has the capability to expand more.

What needs improvement?

We don't know if Kali Linux has the port scanning capability yet, but that is an area of improvement because we are working with DMZ zones and customized ports. If we can add featured customized port scanning and DMZ zone capability, then it will be a very great tool. It might be there, but we are not exploring it yet.

We are not exploring 100% of Kali Linux capabilities. If real-time customized port scanning can be added, for example, instead of a default port such as 8080 or 443, if we can use a customized port such as 9876, that capability would be great.

The only point that I didn't find on Kali Linux for now is the ability to customize port scanning.

For how long have I used the solution?

It has been only five to six months, and the team is getting used to it now.

What do I think about the stability of the solution?

I should rate the stability of the product as average, good. I would rate it eight, minus two because I don't know about other capabilities.

What do I think about the scalability of the solution?

Kali Linux has the capability to expand more, so I would rate it nine.

Which solution did I use previously and why did I switch?

I won't compare Kali Linux with Linux from other vendors because we are installing it on top of Red Hat.

How was the initial setup?

The initial setup of Kali Linux is okay—not pretty complex or very simple.

It could be simplified from Kali's side for a GUI user, but if we are doing it as command mode, it is okay. We don't find it very hard to install or pretty complex.

For a regular user, they might find it complex. For the technical staff, it's not very complex.

What about the implementation team?

Our DevOps team is doing it, so it is somewhat customized.

Which other solutions did I evaluate?

I won't compare Kali Linux with Linux from other vendors because we are installing it on top of Red Hat. We can say the competitors of Acunetix, such as Burp Suite and Qualys Guard, those are the real competitors. Kali Linux is good because Sysbench is one kind of tool that has the capability of port scanning, but we don't know much about Sysbench as of now.

What other advice do I have?

We are not working with the multi-language support function as of now because we are very new to it, so we are exploring the stuff entirely.

We are not working with the resource constrainer system function. We just use scanning for incoming and outgoing data services as of now.

We are not exploring 100% of Kali Linux capabilities. If real-time customized port scanning can be added, for example, instead of a default port such as 8080 or 443, if we are able to use a customized port such as 9876, that capability would be great.

I prefer not to comment further because we are very new to the tool. We don't explore 100%, so I can't comment on it with my capacity right now.

I'm not sure about the pricing model because we got a community version of Kali Linux. The customer has purchased it, so I'm not sure about the pricing.

On a scale of one to ten, I rate Kali Linux an eight.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Reaux

💡 For anyone still trying to figure out the correct SSH username:

  • April 14, 2025
  • Review from a verified AWS customer

Just adding to the conversation because this wasn’t smooth sailing for me either — but also, I’m a beginner.

When I first launched the AMI in us-east-1, I tried logging in with the username kali and it didn’t work. So I tried the other usual suspects: root, ec2-user, admin — nothing worked.

Eventually, after some trial and error (terminating the instance and starting fresh using the same key pair), I used root again and saw the message from the Kali devs saying that kali is the correct username. I tried it again — and this time it worked.

The first time I used root I didn’t get that message at all. The second time I did. No idea why kali didn’t work initially, or why I didn’t get the dev message the first time. Maybe the instance wasn’t fully initialized yet, maybe I made a typo, maybe it’s just AWS being AWS.

If you’re hitting the same wall, don’t assume you’re doing something wrong — it might just take a few tries. It may have absolutely nothing to do with whether you “read the instructions.” I read them too. Still had issues.

✅ Try terminating the instance and launching a fresh one. That’s what finally worked for me.

Just keep troubleshooting. You’ll get in. 💻🔥


    VishalSingh15

A stable and reliable solution for penetration and session testing

  • May 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

Kali Linux's use cases are quite diverse. It can be used as an operating system for learning Linux, penetration testing, ethical hacking, and much more.

What is most valuable?

The most effective features of Kali Linux include its stability as a Linux operating system, its flexibility in configuring resources such as partitions, its powerful and stable file system, and its multi-user capability, which allows for setting user privileges and rights. Additionally, Kali Linux provides access to a wide range of free and open-source applications for testing and development purposes.

The tool's most valuable features for security tasks include its resistance to viruses, ability to configure and filter incoming connections, and security measures that make it difficult for hackers to break into the system. Linux systems are known for their strong security measures, including numerous checkpoints and gates that make hacking attempts difficult. As a result, many financial and scientific institutions prefer to use Linux for its enhanced security compared to Windows.

With access to a vast repository of tools, users can install third-party tools and perform various tasks related to network testing, penetration testing, and session testing.

What needs improvement?

The tool is slightly difficult to learn.

What do I think about the stability of the solution?

I rate the tool's stability a nine out of ten.

What do I think about the scalability of the solution?

Kali Linux's scalability depends on the available resources. Depending on the resources available, users can install multiple instances of Kali Linux, which can be scaled up to meet the needs of various user sizes.

How are customer service and support?

I've never contacted Kali Linux for technical support. Most issues and their resolutions are readily available on the internet.

How was the initial setup?

The solution's deployment is easy and takes about ten minutes to deploy.

What other advice do I have?

I rate the overall product a nine out of ten. For aspiring ethical hackers, I highly recommend using Kali Linux. It's stable and reliable. However, remember that while Kali Linux is very reliable, new bugs and issues may arise occasionally, and driver support for new hardware can sometimes be lacking.

Additionally, it's worth noting that Linux operating systems like Kali Linux are not designed for general entertainment purposes like gaming. They are preferred by developers, engineers, and technical users who want to customize and utilize the full potential of their operating system. If you're looking for a system for general purposes like internet browsing and gaming, Windows or macOS may be more suitable options.


    reviewer1232808

Very user-friendly and offers good performance

  • May 09, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution in my company for penetration testing. The product is used to check if there is any vulnerability within a system.

What is most valuable?

The solution's most valuable feature is that it is very easy to use. The tool is very user-friendly, and its performance is very good.

What needs improvement?

From an improvement perspective, it should be made possible for users to learn about the product easily.

For how long have I used the solution?

I have been using Kali Linux for three months.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a nine out of ten.

How was the initial setup?

The product's initial setup phase was straightforward.

One just needs to create a bootable drive to install the product.

The solution is deployed on an on-premises model.

What about the implementation team?

I can take care of the product's installation myself.

What's my experience with pricing, setup cost, and licensing?

I have used the free version.

What other advice do I have?

I strongly recommend the product to others who plan to use it since it is a reliable tool.

When it comes to the learning curve for new users who plan to use the product, I would say that if someone is not familiar with cybersecurity, then they would need at least six months to a year to learn about the product.

In terms of the value derived from the use of the product, I could see that with the solution, I was able to see the vulnerabilities.

I rate the solution an eight out of ten.


    Rohit Srivastava

SQLmap for web application testing and good for web application penetration testing, network testing, vulnerability assessment of any devices or domains

  • April 22, 2024
  • Review provided by PeerSpot

What is our primary use case?

In my cybersecurity work, I use Kali Linux for web application penetration testing, network testing, vulnerability assessment of any devices or domains, multiple testing types, and code testing. Those are certain basic use cases.

I used Kali Linux in multiple companies like banks, IT companies, and even smaller companies like music departments or other departments. But mostly, I use it for IT companies and banks.

How has it helped my organization?

The systems that are not completely updated create vulnerabilities on the system or on the domain. So first, we have to upgrade all the systems and apply complete security patches. In Windows, there are security patches; in Linux, there are also security patches. We'll upgrade the system.

Additionally, Kali Linux is wonderful. If there is a specific requirement for a lower version, then we have to put a specific script over the database or over the code so nobody can directly access that code.

What is most valuable?

I frequently use SQLmap for web application testing, along with other tools like Burp Suite and Vega.

When we execute commands on tools and the few scripts that I have prepared, we will use SQLmap to execute those scripts on the target system. This helps us find loopholes. Like, a report may show TXG is open or that the configuration password is in cleartext.

Based on this, we suggest vendors make the required changes, or if they are using an older version, they might need a newer upgrade. So there's a lot of capability in it. We suggest upgrading that version, and after completing the vulnerability assessment, we prepare a diagnostic report with suggestions.

Once we provide complete details, then they take some time to fix those vulnerabilities. After that, we'll again execute the vulnerability assessment as a second phase. If everything goes fine, then we will give them certification that their system and application are now secure.

What needs improvement?

Sometimes, I do face challenges. There's an issue where sometimes during the initial installation, it doesn't install properly. It gives multiple errors like packages not installing, so we have to install those tools separately. For instance, if we want to install a network or other tools, we have to install those complete toolkits manually.

So, the challenge is with the initial setup, where I sometimes get errors.

Regarding wireless attacks, OS attacks, and social engineering... the tools should be easier to learn because I know everything very well, but some people in my team struggle to understand. If there were GUI interfaces for the tools, it would help me guide my team in using them step-by-step. Command lines are very difficult for other team members who know the tool's purpose but not the Linux commands. GUI interfaces need more improvement.

So, the UI interface needs improvement to make it more visible and easier for users. Expert users can do everything without any issues, but new users will struggle.

For how long have I used the solution?

I've been working with Kali Linux for the last 10 to 12 years. I use the latest version.

What do I think about the stability of the solution?

The stability is good because I've been using it for the last ten years. I've completed many successful projects, providing good vulnerability assessments to my clients and vendors.

What do I think about the scalability of the solution?

It is a scalable solution. I would rate the scalability an eight out of ten.

We have about four to five users using Kali Linux. Two or three are basic users; they need to learn first before they can execute the scripts.

We do not plan to increase the further usage because we do not have the need. I and some other partners have good experience with it, and we are managing those parts.

How are customer service and support?

I tried to connect to customer support through email, but I received responses very slowly. In those situations, I do my own research and development to fix those particular errors.

For their understanding of the errors and providing solutions, I'd give them a ten out of ten. But about response time, I'll give it a five because it's very slow.

How would you rate customer service and support?

Neutral

How was the initial setup?

From my perspective, I can set up Kali Linux with information gathering, vulnerability analysis tools, and application analysis tools. I'm able to configure those.

However, now many people are interested in cybersecurity. So, I suggest that Kali Linux should improve things like the GUI interface, make it easier to use, and include a training portal that's easier for basic users to understand.

I use it sometimes on-premises and sometimes on the cloud.

Sometimes the setup takes only one hour, no more than that. But if we start getting errors, then it can take four to five hours to complete the setup of Kali Linux.

What's my experience with pricing, setup cost, and licensing?

The price is good because Kali Linux already provides a good bundle of tools. The price is sufficient if you want a good operating system with the necessary tools. So, the cost is not an issue.

What other advice do I have?

Kali Linux is much better than others because it gives you a good set of tools. It is preferred for vulnerability assessments and cybersecurity. You don't have to spend a lot of money on different tools like Tenable. We don't need those because everything is already there in Kali. You just need to explore, configure it properly, and it will provide you with good results.

Overall, I would rate it an eight out of ten because any new user or someone without deep expertise won't be able to understand how to scale or manage it, but an experienced person can.