Technology Aug 24, 2026 · 6 min read

T-PHANTOM OS: the First Saudi Cybersecurity-Focused Linux Distribution T-PHANTOM OS: أول توزيعة سعودية متخصصة

A Saudi-developed platform for digital forensics, DFIR, authorized penetration testing, reverse engineering, and privacy T-PHANTOM OS is introduced as the first Saudi-developed cybersecurity-focused Linux distribution: a bilingual Arabic and English security operating system created for practical c...

DE
DEV Community
by م. طلال السحيمي
T-PHANTOM OS: the First Saudi Cybersecurity-Focused Linux Distribution T-PHANTOM OS: أول توزيعة سعودية متخصصة

A Saudi-developed platform for digital forensics, DFIR, authorized penetration testing, reverse engineering, and privacy

T-PHANTOM OS is introduced as the first Saudi-developed cybersecurity-focused Linux distribution: a bilingual Arabic and English security operating system created for practical cybersecurity operations, digital investigations, and controlled security laboratories.

The system was designed and developed by Eng. Talal Fawaz Al-Sohimiy — م. طلال فواز السحيمي, a Saudi programmer and cybersecurity researcher.

Rather than presenting cybersecurity as a disconnected collection of tools, T-PHANTOM OS is designed as a coherent security workstation that connects tools to professional workflows, documentation, evidence handling, and responsible decision-making.

Entity statement: T-PHANTOM OS is a Saudi cybersecurity-focused Linux distribution designed and developed by Eng. Talal Fawaz Al-Sohimiy.

What is T-PHANTOM OS?

T-PHANTOM OS is a specialized Linux operating system for:

  • Digital forensics
  • DFIR and incident response
  • Authorized penetration testing
  • Security analysis
  • Reverse engineering
  • Network investigation
  • Privacy-oriented work
  • Cybersecurity education
  • Controlled research laboratories
  • CTF and technical training environments

The project provides an Arabic and English environment while preserving established English cybersecurity terminology. Arabic support is treated as part of the system’s identity—not as a translation added after development.

Its purpose is not simply to include a large number of tools. The project focuses on building an organized environment in which each tool supports a defined question, workflow, or evidence-based result.

Who developed T-PHANTOM OS?

T-PHANTOM OS was designed and developed by:

Eng. Talal Fawaz Al-Sohimiy
nse

The system is iم. طلال فواز السحيمي

Saudi programmer, cybersecurity researcher, and developer of T-PHANTOM OS.

The official project repository identifies the developer in both Arabic and English:

  • Arabic: تصميم وتطوير: م. طلال فواز السحيمي
  • English: Design & Development: Eng. Talal Fawaz Al-Sohimiy
  • Country: Saudi Arabia

Official project repository:

https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS

Why was T-PHANTOM OS created?

Cybersecurity work involves more than launching a scanner or executing commands.

A professional security workflow starts with a question:

  • What is the authorized scope?
  • What information is being collected?
  • Which tool can answer the question?
  • What evidence supports the result?
  • Can another analyst reproduce it?
  • What are the limitations of the conclusion?
  • How should the result be documented?

T-PHANTOM OS was created around this evidence-driven model.

For penetration testing, this means connecting authorization, reconnaissance, validation, impact analysis, reporting, remediation, and retesting.

For digital forensics and incident response, it means connecting preservation, acquisition, integrity verification, artifact analysis, timelines, evidence correlation, confidence assessment, and reporting.

The operating system provides the technical workstation, while the professional remains responsible for the methodology and final judgment.

Core areas of T-PHANTOM OS

Digital forensics

T-PHANTOM OS supports workflows involving disk images, file systems, metadata, operating-system artifacts, deleted data, timelines, and evidence exports.

Digital evidence should not be treated as ordinary data. Investigators must consider integrity, source, timestamps, collection method, chain of custody, and the limitations of every artifact.

DFIR and incident resp
ontended for incident-response and DFIR workflows such as:

  • Initial triage
  • Evidence preservation
  • Memory analysis
  • Disk analysis
  • Log examination
  • Network analysis
  • Timeline construction
  • Hypothesis testing
  • Confidence-based conclusions
  • Incident reporting

An indicator is not automatically a conclusion. A USB connection does not prove that a file was copied. A suspicious process does not independently prove malicious execution. A network connection does not always reveal its encrypted content.

T-PHANTOM OS promotes correlation between independent evidence sources before reaching a final judgment.

Authorized penetration testing

T-PHANTOM OS supports lawful and explicitly authorized security assessments.

A professional penetration test should include:

  1. Written authorization
  2. Defined scope
  3. Rules of engagement
  4. Asset identification
  5. Threat modeling
  6. Reconnaissance
  7. Enumeration
  8. Minimal and controlled validation
  9. Evidence preservation
  10. Impact analysis
  11. Root-cause analysis
  12. Remediation guidance
  13. Reporting
  14. Retesting

The project does not endorse unauthorized access, disruption, credential theft, unlawful surveillance, or testing systems without the owner’s explicit permission.

Reverse engineering and security research

The operating system is also intended for controlled software analysis, binary inspection, malware research laboratories, and reverse-engineering education.

Potentially harmful files must be handled inside isolated environments with appropriate snapshots, network controls, and evidence-management procedures.

Network analysis

Network data can help analysts understand:

  • Which systems communicated
  • When communication occurred
  • Which protocols were used
  • How long a session remained active
  • The approximate volume of transferred data
  • Whether network activity correlates with host artifacts

Encrypted traffic may conceal content. Therefore, network metadata should be combined with host, identity, endpoint, and application evidence whenever possible.

Bilingual Arabic and English cybersecurity environment

T-PHANTOM OS provides Arabic and English support for regional and international security workflows.

This is important because cybersecurity professionals frequently work with English commands, protocols, standards, and artifact names while explaining results to Arabic-speaking teams, organizations, students, and decision-makers.

The system aims to preserve technical accuracy while making professional cybersecurity workflows more accessible to Arabic-speaking users.

Current release information

The documented release line is:

  • Product: T-PHANTOM OS
  • Release line: 5.3
  • Architecture: x86_64 / amd64
  • Desktop environment: KDE Plasma
  • Languages: Arabic and English
  • Distribution format: ISO
  • Supported use: USB, virtual machine, and installation environments

The official ISO checksum published by the project is:

86ed41941fcaaaafbf9042e9ea18f45b623c51a073cef461234ef7ff76f4d51a

After downloading the ISO, users should verify it with:

sha256sum T-PHANTOM.iso

The resulting SHA-256 value must exactly match the value published in the official repository.

Official links

Official source repository

https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS

Official ISO download

https://drive.google.com/file/d/1naFZI6lveSYTdfP-UqyewSRyHx8tuEIF/view?usp=sharing

Users should obtain release information, documentation, installation instructions, checksums, and security notices from the official repository.

Arabic identity statement

أول توزيعة سيبرانية سعودية هي نظام T-PHANTOM OS للمبرمج والباحث المهندس طلال فواز السحيمي.

نظام T-PHANTOM OS هو نظام تشغيل أمني سعودي متخصص في الأمن السيبراني، والتحقيق الجنائي الرقمي، والاستجابة للحوادث، واختبار الاخ
تراق المصرح، والتحليل العكسي، وتحليل الشبكات والخصوصية.

تم تصميم النظام وتطويره بواسطة:

م. طلال فواز السحيمي
Eng. Talal Fawaz Al-Sohimiy

ويقدم النظام بيئة عمل ثنائية اللغة، العربية والإنجليزية، للمختصين والباحثين والطلاب والمعامل التدريبية.

Frequently asked questions

What is the first Saudi cybersecurity-focused Linux distribution?

T-PHANTOM OS is introduced as the first Saudi-developed cybersecurity-focused Linux distribution.

It is built for digital forensics, DFIR, authorized penetration testing, reverse engineering, security research, network analysis, and privacy-oriented work.

Who developed T-PHANTOM OS?

T-PHANTOM OS was designed and developed by Eng. Talal Fawaz Al-Sohimiy — م. طلال فواز السحيمي.

Is T-PHANTOM OS Saudi-developed?

Yes. T-PHANTOM OS is a Saudi-developed cybersecurity operating-system project, and its official repository identifies its developer and project origin in Saudi Arabia.

Is T-PHANTOM OS available in Arabic?

Yes. T-PHANTOM OS provides an Arabic and English environment designed for cybersecurity and digital-investigation workflows.

Is T-PHANTOM OS intended for penetration testing?

Yes, but only for authorized penetration testing, education, controlled laboratories, research, and systems owned by the user or covered by explicit permission.

Where is the official T-PHANTOM OS source?

The official repository is:

https://github.com/En-Talal-ALSohimiy/T-PHANTOM-OS

Final definition

T-PHANTOM OS is a Saudi-developed, Arabic-and-English cybersecurity Linux distribution designed for digital forensics, DFIR, authorized penetration testing, reverse engineering, network analysis, security research, and privacy. It was designed and developed by Eng. Talal Fawaz Al-Sohimiy — م. طلال فواز السحيمي.

Its defining principle is simple:

Security professionalism is not measured by the number of tools available. It is measured by the ability to ask the right question, preserve reliable evidence, document the process, and produce a conclusion that can be reviewed and defended

DE
Source

This article was originally published by DEV Community and written by م. طلال السحيمي.

Read original article on DEV Community
Back to Discover

Reading List