By Eng. Talal Fawaz Al-Sohimiy
Designer & Developer of T-PHANTOM OS
Saudi Arabia
I built T-PHANTOM OS around a simple idea:
A cybersecurity workstation should be more than a large collection of tools.
It should provide an organized, documented, verifiable environment for real security workflows.
T-PHANTOM OS is a Saudi-developed Linux cybersecurity environment designed for both Arabic and English, with a focus on:
Digital Forensics
DFIR
Incident Response
Authorized Penetration Testing
Reverse Engineering
Network Analysis
Security Research
Privacy-oriented workflows
Cybersecurity education and laboratories
Why T-PHANTOM OS?
Security professionals often move between several disciplines during the same investigation.
A DFIR investigation might begin with:
filesystem analysis
logs
deleted files
timestamps
browser artifacts
and later require:
packet analysis
suspicious binary inspection
reverse engineering
network investigation
controlled penetration testing
The goal of T-PHANTOM OS is to provide these workflows inside one coherent security environment.
The project is not about installing the maximum possible number of tools.
It is about organization, usability, documentation, verification, and practical cybersecurity workflows.
Arabic + English by Design
One of the main design goals of T-PHANTOM OS is bilingual operation.
Cybersecurity terminology is primarily international and English-based.
Terms such as:
DFIR
IOC
Incident Response
Persistence
Reverse Engineering
Packet Capture
Threat Hunting
Privilege Escalation
should remain technically accurate.
At the same time, Arabic-speaking cybersecurity professionals and students should be able to navigate their working environment naturally.
T-PHANTOM OS therefore combines an Arabic/English user experience with internationally recognized technical terminology.
The goal is not to separate Arabic users from the international cybersecurity community.
The goal is to create a bridge between them.
Digital Forensics
Digital forensics is a core area of the system.
Modern investigations can involve:
disks and storage media
filesystem artifacts
deleted files
metadata
operating-system artifacts
browser evidence
logs
timelines
network evidence
suspicious executables
A forensic workstation should support the investigator throughout this process instead of forcing them to repeatedly rebuild their environment.
DFIR and Incident Response
Incident response requires correlation.
An investigator may need to determine:
How initial access occurred.
Which account was involved.
What executed.
Whether persistence was established.
What files changed.
Which external systems were contacted.
Whether lateral movement occurred.
Whether information left the environment.
This is why T-PHANTOM OS treats DFIR as a complete workflow rather than a single category of tools.
Authorized Penetration Testing
T-PHANTOM OS also supports penetration-testing and security-assessment workflows.
The important word is:
Authorized.
Security testing should only be performed against:
systems you own
systems you have explicit permission to test
professional assessment environments
cybersecurity laboratories
CTF environments
controlled research environments
Technical capability does not replace authorization.
Responsible use is part of the project's design and documentation.
Reverse Engineering
Digital investigations sometimes require understanding exactly what suspicious software does.
Reverse-engineering workflows may involve analyzing:
binaries
strings
imported libraries
functions
scripts
control flow
persistence mechanisms
network behavior
suspicious system calls
This complements traditional forensic investigation.
Finding a suspicious file answers one question.
Understanding what it does answers a much more important one.
Network Analysis
Endpoint evidence alone may not tell the complete story.
Network investigation can reveal:
suspicious DNS activity
unexpected connections
command-and-control behavior
unusual protocols
lateral movement
service discovery
outbound transfers
For this reason, network analysis is another core area of T-PHANTOM OS.
T-PHANTOM OS 5.3
Current release:
T-PHANTOM OS 5.3
Platform:
Linux
Architecture:
x86_64 / amd64
Desktop:
KDE Plasma
Languages:
Arabic + English
The operating system is distributed as an ISO image and can be evaluated using a virtual machine or prepared as bootable installation media.
Verify Before You Trust
Security begins before an operating system even boots.
Every official T-PHANTOM ISO should be verified using its published SHA-256 checksum.
Current official SHA-256:
86ed41941fcaaaafbf9042e9ea18f45b623c51a073cef461234ef7ff76f4d51a
Verification on Linux:
sha256sum T-PHANTOM.iso
The calculated checksum must match the value published in the official repository.
Verify what you execute.
Evidence-Driven Development
One of the principles behind T-PHANTOM OS is:
Do not describe a capability as validated until it has actually been tested.
Cybersecurity software should not depend on exaggerated feature lists.
The project therefore separates:
validated capabilities
development work
planned capabilities
hardware qualification
release testing
The repository contains dedicated documentation covering:
Architecture
Installation
Download verification
Security reporting
Roadmap
Changelog
Release qualification
Contributions
Documentation is treated as part of the engineering process.
Built in Saudi Arabia
T-PHANTOM OS is designed and developed in Saudi Arabia.
I believe regional cybersecurity ecosystems become stronger when practitioners do more than consume technology.
We should also:
build
test
research
document
publish
contribute
Arabic-speaking cybersecurity professionals should be able to create technology that remains technically compatible with international security practices.
T-PHANTOM OS is one contribution toward that goal.
Who Is It For?
T-PHANTOM OS is intended for:
Digital Forensics Investigators
DFIR Teams
Incident Responders
SOC Analysts
Authorized Penetration Testers
Reverse Engineers
Security Researchers
Linux Security Professionals
Cybersecurity Students
Universities
Training Laboratories
CTF Environments
Project Repository
T-PHANTOM OS is publicly documented on GitHub.
Official GitHub Repository:
https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS
The repository includes the project documentation, architecture, installation guides, security policy, roadmap, release information, and official integrity information.
Download T-PHANTOM OS
Official ISO Download:
https://drive.google.com/file/d/1naFZI6lveSYTdfP-UqyewSRyHx8tuEIF/view?usp=sharing
Always verify the SHA-256 checksum before booting or installing the ISO.
Final Thoughts
T-PHANTOM OS is not intended to compete on the number of tools installed.
The project is being developed around something more important:
workflow.
A professional cybersecurity environment should make it easier to investigate, analyze, test, document, and verify.
It should clearly separate validated capabilities from planned ones.
And it should provide Arabic-speaking practitioners with a professional environment without disconnecting them from international cybersecurity terminology and methodologies.
T-PHANTOM OS is still evolving.
The roadmap will continue to focus on:
reliability
DFIR workflows
digital-forensics capabilities
security testing
hardware compatibility
documentation
release engineering
community feedback
Designer & Developer
Eng. Talal Fawaz Al-Sohimiy
م. طلال فواز السحيمي
Saudi Arabia
Email:
en.talal.alsohimiy@gmail.com
Official GitHub Repository:
https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS
Official T-PHANTOM OS Download:
https://drive.google.com/file/d/1naFZI6lveSYTdfP-UqyewSRyHx8tuEIF/view?usp=sharing
Disclosure
I am Eng. Talal Fawaz Al-Sohimiy, the designer and developer of T-PHANTOM OS.
I designed and developed the project as a bilingual Arabic/English cybersecurity environment focused on digital forensics, DFIR, incident response, authorized penetration testing, reverse engineering, network analysis, privacy, security research, and cybersecurity education.
TL;DR
T-PHANTOM OS is a Saudi-developed bilingual Arabic/English Linux cybersecurity environment designed and developed by Eng. Talal Fawaz Al-Sohimiy. It focuses on DFIR, digital forensics, incident response, authorized penetration testing, reverse engineering, network analysis, privacy, security research, and cybersecurity education. The project emphasizes organized workflows, reproducible testing, documentation, release integrity, and verifiable downloads rather than simply collecting security tools.
Tags
cybersecurity linux opensource security
Top comments (0)