1 Introduction
This article can be considered as me fulfilling a goal I set for myself many years ago. The origin was that back when I was testing the company's anti-DDoS products, I needed to write a user manual for common traffic simulation tools (used to simulate various network attack traffic). I thought: why don't I just write one? In the end, I procrastinated and never wrote it (back then, I didn't have the initiative I have now for writing blog posts; I would delay as much as possible and avoid writing if I could~).
Additionally, in today's Simplified Chinese internet environment, such articles are already hard to find. Even if you can find a few scattered ones, the download methods, installation procedures, and even usage steps of many tools have changed, making it difficult for friends who want to learn to obtain complete information, and easily misleading them with outdated information. Given this, I might as well compile an article to systematically record the installation, configuration, and basic usage of these tools, hoping to help those in need and fill the gap in this area. At the same time, it can be considered as giving closure to my past self.
Note: To put it nicely, but actually, after upgrading to Cloudflare Pro, I wanted to see how the WAF's managed rules and defense against automated traffic really perform, treating it as a simple security test. Therefore, I needed a test tool machine. Since I had to install and configure one anyway, I might as well record the process, and write a filler article along the way~.
However, when I still wanted to use my most familiar Debian system for deployment, I accidentally discovered Kali Linux, a security testing distribution that already has many built-in network attack simulation tools. Compared to manually installing various tools on Debian, Kali directly provides an out-of-the-box environment, saving a lot of trouble with installation, dependency management, and configuration.
So, what exactly is Kali Linux? What makes it unique?
2 Introduction to Kali Linux
Kali Linux is an operating system specifically designed forpenetration testing, cybersecurity research, and computer forensics, and its predecessor is BackTrack Linux。
**The Origins of Kali Linux**
• 2006 年: BackTrack Linux was born, developed by Offensive Security(the company behind the OSCP certification), focusing on cybersecurity and penetration testing.
• 2013 年: BackTrack was discontinued, andKali Linux was officially releasedas the successor to BackTrack.
• 2020 年: Kali Linux introduced non-root default user modeto enhance security, and providedmultiple desktop environments (GNOME, XFCE, KDE)。
Why does Kali Linux have so many built-in penetration tools?
- Born for penetration testing
• Kali Linux is maintained by Offensive Security(the OSCP certification body), and their goal is to provide security researchers, red teams, and hackers with anout-of-the-box security testing environment。
- Built-in 600+ cybersecurity tools
• Kali integrates a large number of famous security tools by default, including:
• Information Gathering: Nmap, Maltego, theHarvester
• Vulnerability Scanning: Nikto, SQLmap, OpenVAS
• Password Cracking: John the Ripper, Hashcat, Hydra
• Wireless Penetration: Aircrack-ng, Kismet, Wifite
• Web Penetration Testing: Burp Suite, ZAP, OWASP tools
• Social Engineering: Social-Engineer Toolkit (SET)
• Post-Exploitation: Metasploit, Empire, PowerShell attack tools
• Anonymity Tools: Tor, ProxyChains, I2P
Most of these tools are open-source and can be installed independently, but Kali integrates them directly, saving the trouble of separate configuration.
- Customized kernel, suitable for security testing
• Kali uses a custom Linux kernel, allowing the enablement ofwireless card monitor mode (Monitor Mode), packet injectionand other advanced features, facilitating wireless security testing.
- Suitable for offline/portable testing
• Kali can run on Live USB, VMs, WSL, ARM devices (Raspberry Pi), allowing security testing anytime, anywhere.
• Kali NetHunter is a Kali version suitable for Android devices, supporting wireless testing on mobile phones.
I took a quick look, and besides the commonly used penetration tools, some of the tools I wanted to install are already pre-installed in Kali, such as hping3 and slowloris. Plus, since I haven't played with Kali Linux yet, I'll change things up this time, skip Debian, and mess around with Kali.
3 Installing Kali Linux
1 Choice of Installation Method
Kali Linux supports multiple installation methods:

Among them, the more commonly used ones should be the several methods marked in the red box in the image above: Installer Images, Virtual Machines, Containers (further divided into docker and lxc/lxd). Below is a comparison of these methods:
| Method | Installer Images (ISO Installation) | Virtual Machines (Pre-installed VM Images) | Docker (Containers) | LXC/LXD (Lightweight Containers) |
|---|---|---|---|---|
| Core Differences | Traditional complete installation method | Pre-installed Kali, suitable for VM environments | Lightweight application containers, running single or partial tools | Lightweight system containers, complete Kali experience |
| Applicable Scenarios | Physical machine or VM requiring complete Kali | Running in VM software (such as VirtualBox, VMware, PVE) | Only need specific Kali tools, automated tasks | Need complete Kali, but don't want to use a VM |
| System Completeness | Complete | Complete | Only partial tools | Nearly complete, but may have compatibility issues |
| Performance Consumption | Best performance on physical machines | Limited by VM resource allocation | Lightweight | Lightweight, more efficient than VM |
| Has GUI? | Supported by default | Pre-installed GUI | No GUI by default | Optional GUI installation (but not default) |
| Suitable for penetration testing | Best suited | Suitable | Only suitable for CLI tools | Suitable, but may require additional configuration |
| Suitable for Proxmox VE | Feasible, but not efficient enough | Suitable | Requires additional configuration | Feasible, but no official PVE template |
| Installation method | Install via ISO | Directly download VM hard disk image (OVA/VMDK) | docker pull to run container | lxc-create or lxc launch |
| Suitable for long-term use | Suitable | Suitable | Mainly used for temporary testing | Suitable, but the management method is different from traditional PVE LXC |
| Portability | Migration is not very convenient (requires manual cloning or reinstallation) | Easy to migrate | High, can be moved at any time | High, can be moved at any time |
Originally, in my opinion, when deploying Kali on PVE, if the LXC method was available, I would definitely prioritize the LXC method. After all, LXC has the advantages of lighter resource usage, faster startup speed, and sharing the kernel with the host. However, Kali's LXC/LXD method is quite different from the common LXC template installation method on PVE. It is actually manually installed based on the Debian system (this installation method is also suitable for other Linux distributions), rather than providing a ready-made PVE-compatible template that can be used directly. This means that using LXC to run Kali on PVE requires manual configuration, which is not as convenient as the common LXC template method, so it feels a bit useless to me.
In contrast,Virtual Machines (Pre-installed VM image) method is simpler and more efficient. The official OVA/VMDK images can be directly imported into PVE without manual installation and configuration, saving the tedious steps of ISO installation (the official initialization work has already been completed). At the same time, it is closer to the full Kali experience than the LXC method, supporting GUI and avoiding issues where certain tools cannot run properly due to the container environment. Therefore, in the end, I chose the Virtual Machines (Pre-installed VM Images) method to deploy Kali, balancing installation convenience, system integrity, and long-term stability.
Note: If you want to use Kali on PVE, but are not very familiar with the Virtual Machines (Directly import VM image) method, you can also choose the Install Images method. The specific approach is: create a new VM on PVE, download the Install Images ISO image and mount it as an optical drive, then boot from the CD and install Kali step-by-step according to the prompts. This method is relatively simple and suitable for users who do not want to hassle. However, compared to directly using the Virtual Machines method (mounting a pre-installed image), this method has many more steps (after all, it is equivalent to installing the system from scratch). Therefore, if you use PVE to install Kali and want to save performance overhead, it is still recommended to prioritize theVirtual Machinesmethod.
2 Deploying Kali on PVE Using Virtual Machines Method
Note: Since this method requires using theqm disk importcommand to import the qcow2 format image file into the specified VM, you need to create the VM first to get its VM ID.
Step 1: Create a VM on PVE
Create a VM on PVE according to the following image tutorial:








Step 2: Download the image and import it into the VM

The downloaded file is a compressed package with a ”.7z” extension. After decompression, it is a VM image file in qcow2 format (assuming the image file name is kali.qcow2). Upload the ”kali.qcow2" image file to any path on PVE using any method (sftp, ftp, smb), assuming it is/var/lib/vz/images/, and then use theqm disk importcommand to import it into the previously created VM (in this example, the ”VM ID” is 112, and the storage is ”local-lvm”):
qm disk import 112 /var/lib/vz/images/kali.qcow2 local-lvm
After the command finishes running, the image file will be attached to VM 112 as an ”unused disk”:






Finally, you can power it on in the console:

4 Initializing Kali
1 Logging into Kali via PVE Console
When starting for the first time, you need to log in to the Kali system from the PVE console (the default username and password for logging in are both ”kali”):

Enter the system:

Note: The password for obtaining privileges with the sudo command is also ”kali”.
2 Configuring SSH Remote Login
In fact, it is just configuring the SSH remote login for the Debian system. By default, the openssh-server software is already installed, so you only need to configure the relevant configuration files. Taking allowing the kali account to log in to the system remotely via SSH using a username and password as an example, the following settings are required:
* Allow logging in to SSH using the kali account name and password
By default, Kali's SSH only allows logging in using public keys. If you want to log in using a username and password, you can follow the steps below.
Editssh_configfile:
sudo vim /etc/ssh/ssh_config
Remove thePasswordAuthentication'#' symbol on the left#and save:

Then restart the SSH service, and after that, you can log in via SSH using the kali account and password:
sudo systemctl restart ssh
Then set the SSH service to start on boot:
sudo systemctl enable ssh
Note: Remember to use thesudo passwdcommand to change the default password of the kali account.
- Allow logging in to SSH using the root account (not recommended from a security perspective)
Like other Debian systems, Kali's default setting is that the root account is normally forbidden from logging in via SSH. If you want to allow the root account to log in via SSH, you can follow the steps below.
Editsshd_configfile:
sudo vim /etc/ssh/sshd_config
Remove thePermitRootLogin'#' symbol on the left#'#' symbol, and changeprohibit-passwordin the red box toto yes, then save:

Then restart the SSH service, and after that, you can log in via SSH using the root account and password:
sudo systemctl restart ssh
Note: Remember to use thesudo passwd rootcommand to change the default password of the root account.
3 Logging into Kali via Remote Desktop Using a VNC Client
3.1 Ramblings
Since I only need SSH, and getting Kali to support remote desktop access (whether VNC or XRDP) requires some extra effort, I was really too lazy to do it (and crucially, it affects system stability). However, for the sake of the article's completeness, I will write a brief guide.
3.2 Installing and Configuring tightvncserver
- Install VNC Server
sudo apt update
sudo apt install tightvncserver
- sudo apt install tightvncserver
Initialize the VNC server and set a password
vncserver
- vncserver
Stop the VNC server
vncserver -kill :1
- Configure VNC startup script
Create an xstartup file, usually located in the ~/.vnc directory, and edit it to configure the desktop environment you want to start:
vim ~/.vnc/xstartup
Modify the file content to ensure it contains your preferred desktop environment (e.g., xfce4), then save it:
#!/bin/sh
xrdb $HOME/.Xresources
startxfce4 &
- Restart VNC server
Start VNC server:
vncserver :1
This way, the VNC server will start on :1 (port 5901), allowing remote desktop access via a VNC client.
Finally, you just need to use a VNC client (such as TigerVNC, RealVNC, or Vinagre , etc.) to connect to the Kali VNC server at the address Kali_IP:1, where Kali_IP is the IP address of Kali Linux, and :1 is the display number of the VNC session.
Note: If you do not use the VNC method, the xrdp method is also fine. There are many tutorials online, so I won't repeat them here.
5 Overview of Kali's Default Integrated Tools
The following are some commonly used tools integrated by default in Kali Linux, organized by functional category:
1、 Information Gathering
- Nmap: Network scanning tool, used to discover hosts, services, operating systems, and other information on the network.
- Netdiscover: Network discovery tool, mainly used to discover active hosts on a local area network.
- Whois: A tool for querying domain name registration information.
- Dnsrecon: DNS information gathering tool.
- theHarvester: Used to gather email addresses, domain names, and other information through search engines.
- Shodan: A tool for searching internet-connected devices.
- Maltego: Graphical information gathering and analysis tool, suitable for social engineering, network analysis, etc.
2、Vulnerability Analysis
- Nikto: Web server vulnerability scanner, capable of detecting various vulnerabilities such as SQL injection, cross-site scripting, etc.
- OpenVAS: Open-source vulnerability scanning tool, providing comprehensive vulnerability scanning and management.
- Nessus: Commercial vulnerability scanning tool, not included by default in Kali, but can be installed.
- Burp Suite: Integrated Web application security testing platform, providing features such as proxy, spider, scanner, and vulnerability analysis.
- W3AF: Web application security scanning tool, focusing on finding Web application vulnerabilities
3、Wireless Attacks
- Aircrack-ng: Wireless network cracking tool, supporting attacks on wireless encryption protocols such as WEP, WPA, and WPA2.
- Reaver: Attack tool targeting WPS (Wi-Fi Protected Setup).
- Kismet: Wireless network sniffing tool, capable of capturing Wi-Fi network traffic and signals.
- Fern WiFi Cracker: Wireless network cracking tool provided in a graphical interface format.
4、Web Application Analysis
- OWASP ZAP (Zed Attack Proxy): Web application security scanning tool provided by OWASP, suitable for automated and manual testing.
- Dirbuster: Web directory brute-forcing tool, detecting hidden directories or files through brute-force methods.
- Burp Suite: Mainly used for Web application security testing, including man-in-the-middle proxy, automated scanning, etc.
- Wfuzz: Highly flexible Web directory and file brute-forcing tool.
- Sqlmap: Automated SQL injection attack tool that helps users discover and exploit SQL injection vulnerabilities.
5 、Password Attacks
- Hydra: Fast password cracking tool supporting multiple protocols such as SSH, FTP, HTTP, Telnet, etc.
- John the Ripper: Powerful password cracking tool supporting multiple algorithms and hash formats.
- Medusa: Network login brute-forcing tool similar to Hydra.
- Hashcat: One of the world's fastest password cracking tools, supporting multiple algorithms.
- CeWL: Web scraper tool that can generate dictionaries for password cracking.
6、Post Exploitation
- Metasploit Framework: Classic penetration testing framework providing a rich set of exploit and post-exploitation tools.
- Empire: PowerShell and Python post-exploitation framework supporting command and control.
- BeEF: Browser exploitation framework focusing on web browsers, allowing attackers to exploit them.
- Mimikatz: Windows password extraction and credential harvesting tool.
- Netcat: Networking tool commonly used for reverse shells and port listening.
- SET (Social-Engineer Toolkit): Focuses on social engineering attacks, allowing attacks to be delivered via email, USB scripts, etc.
7、Penetration Testing Frameworks (Exploitation Tools)
- Metasploit Framework: A comprehensive penetration testing framework covering exploit development, attack modules, payload generation, and other functions.
- Armitage: Graphical front-end tool for Metasploit, simplifying the penetration testing workflow.
- Veil Framework: Generates effective payloads that can bypass antivirus software.
- Cobalt Strike: Commercial penetration testing tool providing comprehensive post-exploitation and command and control capabilities.
8、Social Engineering
- SET (Social-Engineer Toolkit): Provides a range of tools for social engineering attacks, such as phishing emails, web attacks, etc.
- Evilginx2: A man-in-the-middle proxy tool for phishing attacks, capable of efficiently capturing and forwarding login credentials.
9、Malware Analysis
- Radare2: Powerful open-source reverse engineering framework suitable for malware analysis.
- Cutter: Graphical front-end for Radare2.
- PEStudio: Tool for analyzing Windows executable files.
- Volatility: Memory forensics tool, widely used for malware analysis and digital forensics.
10、Anti-forensics tools (Forensics)
- Autopsy: Digital forensics analysis tool, used to analyze hard drives and file systems.
- Sleuth Kit: Contains multiple digital forensics tools, suitable for analyzing file systems.
- Plaso: Used to extract and construct event timelines from event logs.
11、Network Sniffing and Monitoring (Sniffing and Spoofing)
- Wireshark: Network protocol analysis tool, used to capture and analyze network traffic.
- Ettercap: Network sniffing and man-in-the-middle attack tool, suitable for traffic interception and modification in local area networks.
- Bettercap: Efficient network sniffing tool, supporting ARP spoofing and man-in-the-middle attacks.
- Dnsmasq: Tool used for network traffic analysis and domain name resolution.
12、Privacy and Cryptography Tools (Privacy and Cryptography)
- Tor: Anonymous communication tool, used to encrypt and hide users' network traffic.
- OpenSSL: Open-source cryptography tool, supporting multiple encryption algorithms.
- GPG (GNU Privacy Guard): Tool used to encrypt and sign emails or files.
- TrueCrypt/VeraCrypt: Hard drive encryption tool, protecting data privacy.
Everyone can choose different tools according to their own needs.
6 Afterword
Although this article is only Part 1, it can also be regarded as an article specifically about Kali Linux deployment. However, for network attack testing, a few classic tools are still missing, which will be discussed in Part 2. But I won't be able to write Part 2 for a while, because my ”Cloud Disaster Recovery Center” has moved from Tencent Cloud Lighthouse server to Racknerd's VPS, and there are many things to record. I can only make up for Part 2 when I have time in the future~.