All vendors

Vendor lineage

OffSec (Offensive Security)

Gives the tool away and charges for the proof that you can use it.

Mati Aharoni started what became Offensive Security around 2007 - the company was incorporated in 2008 - working from his living room with his wife Iris, and Wikipedia names Devon Kearns as co-founder. It makes Kali Linux, maintains ExploitDB, and issues the OSCP, whose 24-hour practical examination has a reputation that most certifications would trade a great deal for.

**The lineage of the tool runs backwards through two mergers.** BackTrack first appeared in May 2006, formed by combining WHAX - Aharoni's own Slax-based distribution, earlier called Whoppix and based on Knoppix - with the Auditor Security Collection. It ran on Slackware for three versions, moved to Ubuntu for two more, and ended at 5 R3 in August 2012. In March 2013 the team rebuilt it on Debian and released it as **Kali Linux**, which is a harder decision than it sounds: throwing away a distribution with an established name and a large user base, in favour of a foundation that made packaging and long-term maintenance tractable. **They chose the maintainable base over the familiar name, which is the correct call and almost never the popular one.**

**The business model is worth stating plainly because it inverts the usual one. The tool is free and the proof is expensive.** Kali costs nothing, is open source, and is used by people who will never buy anything. What OffSec sells is training and certification - and the free tool is what builds the audience for it. **Compare that with the vendors elsewhere on this timeline who sell the product and give away the training**; both models work, and they select for entirely different kinds of customer.

**And then the assessment, which is the reason this entry sits beside Pearson VUE and Prometric rather than apart from them.** Those companies exist to run controlled examinations in supervised rooms, where the question is whether the right person answered. The OSCP does the opposite: twenty-four hours, real machines on a test network, compromise them, then write the report. **The exam is the work rather than a proxy for it.** You cannot bluff a shell you did not get.

**That inverts the trust problem rather than solving it, and the inversion has a documented cost.** A multiple-choice examination can be memorised, which is why the delivery companies invest so heavily in verifying that the person in the chair is the candidate. A practical examination cannot be bluffed - but the target machines are reusable, so knowing them in advance is the cheat. In 2019 a critic published a walkthrough of one exam machine and threatened more, alleging that cheating was widespread and that the certification's value was being eroded from inside.

**Put the two failure modes side by side and the general principle falls out. Every assessment model is vulnerable in exactly the place its strength comes from.** Standardisation makes an exam scalable and memorisable. Realism makes an exam unfakeable and leakable. There is no design that is strong in both directions, which is why the serious question about any certification is not whether it can be gamed but **which way it can be gamed, and whether the people relying on it know.**

Aharoni left in 2019 after more than two decades in security. Jim O'Gorman took over as Kali project lead, with Raphaël Hertzog - a Debian developer - as a third technical pillar. **The founder leaving without the project faltering is worth noting**, because the timeline elsewhere records several tools that did not survive their author's departure.

The distribution also carries a cultural footprint disproportionate to its user count, having appeared repeatedly in *Mr. Robot* - which is the rare case of screen technology being accurate enough that practitioners were not embarrassed by it.