Skip to content
← Back to Work
Active V1 Beta (hardware testing) Linux OSINT & DFIR Apache 2.0

One operating system for the investigation workflow.

Investigation-focused Linux OS for OSINT, DFIR, secure research, intelligence gathering, and evidence-driven workflows. Two flagship interfaces: Investigation Terminal + Investigation Browser with integrated Tor. Case Vault uses content-addressed SHA-256 storage with an append-only, hash-chained audit trail. Apache 2.0. Built by P4inz. Core V1 implementation is complete: a candidate ISO exists and has passed automated QEMU boot and live-flow validation. Not yet a public download -- hardware and manual testing is the current phase.

GitHub repository card for p4inz-code/pursue-os.
Banner art from the project README. Not a product screenshot.

Development notice. PURSUE OS is V1 Beta: core implementation is complete and a candidate ISO has passed automated QEMU boot and live investigation-flow validation. It is not yet production-certified and has no public release download — hardware and manual testing on real devices is the current phase.

The idea

One operating system for the investigation workflow.

Instead of assembling a large collection of unrelated tools, PURSUE aims to provide a coherent environment where investigators can research, collect, analyze, connect, preserve, and report information from one system.

Two flagship interfaces sit alongside the broader investigation platform:

  • Investigation Terminal — a purpose-built command-line environment for investigators.
  • Investigation Browser — secure, configurable browsing and research workflows with integrated Tor capabilities.

Core areas

What it's being designed to support.

OSINT + intelligence gatheringSecure investigation browsingIntegrated Tor workflowsInvestigation-focused terminalCase managementEvidence storage + provenanceInvestigation graphsTimelines + orgDFIR workflowsGEOINTInfrastructure intelligenceCTI workflowsMedia analysisReporting + exportModular investigation toolsPlugin extensibilityOptional local AI

AI policy

Assistant, not authority.

AI in PURSUE may help with: organizing information, summarizing investigator-selected material, explaining technical output, assisting terminal workflows, and helping navigate supported tasks.

AI must not silently manipulate evidence or replace the investigator's judgment. The source remains the source of truth. AI functionality is optional and configurable.

Privacy + security

Privacy-first workflows

Sensible defaults that respect investigator autonomy.

Integrated Tor

First-class Tor capabilities across the browser and research tooling.

Evidence integrity

Provenance and traceability built into the case system.

Minimal telemetry

Strong defaults, user-controlled environment. Nothing hidden.

Development status

V1 build complete. Hardware testing underway.

PlanningComplete
Repository foundationComplete
Core implementationComplete
Automated validationPassed · QEMU + full test suite
Hardware testingIn progress
Public release downloadNot available yet

Apache 2.0. Third-party software distributed with future releases may use separate licenses. An independent project created and maintained by P4inz.

Not investigation advice. This page describes an in-progress operating system designed to support OSINT & DFIR and evidence-collection workflows. It is not a substitute for training or professional standards in those fields. Verify capabilities and legal fitness for your jurisdiction against the source repository before relying on any component for real casework.