Michael Reed keeps his ports closed, has passwordless SSH and two locks on his bicycle.
HOW WE TESTED…
We began by installing the latest stable release of the AMD64 edition of each distribution into a VirtualBox virtual machine. VMs are good for this sort of work as you can make sure that each distro is working within an identical environment. Apart from general use, we tried hacking tutorials using the distros themselves. Where available, we used tutorials and examples aimed at each particular distribution.
All of the distros came with all the pen-testing tools you’d expect to find. There were some differences in exactly what they offered, but you’d have to be at an advanced level for this to make a difference. Instead, we focused on the organisation and documentation for these tools.
This time around, we didn’t create a section to test the resource usage of the distributions because, as long as none of them were resource hogs (they weren’t), being lightweight isn’t especially relevant to this sort of work.