No network, by construction
The kernel has no IP stack and no network drivers. There is no firewall to misconfigure because there is nothing to filter.
esOS 1.0 · Encryption Studio OS
esOS is a live operating system for file encryption. It boots from a USB stick, runs entirely in memory and has no network stack. You work with your files, power off, and nothing is left on the computer.
esOS 1.0 starting - kernel 6.18.54-esOS (x86-64-v3) ========================================================== esOS 1.0 - Encryption Studio OS kernel 6.18.54-esOS (x86-64-v3) Copyright (c) 2026 Koray USTUNDAG. ========================================================== Getting started: keyboard_setup choose your keyboard layout (default: US) esx --help encrypt / decrypt files hwreport hardware and security summary poweroff power off (USB sticks are unmounted safely) esOS:~# mount /dev/sdb1 /mnt esOS:~# esx encrypt -i /mnt/report.pdf -o /mnt/report.enc -k public.pem esOS:~#
Design
Most hardening adds rules on top of a full system. esOS starts from an empty kernel configuration and adds only what file encryption needs.
The kernel has no IP stack and no network drivers. There is no firewall to misconfigure because there is nothing to filter.
The whole system unpacks into RAM. No swap, no hibernation, no core dumps. Memory is zeroed when it is allocated and when it is freed.
Kernel lockdown, Yama ptrace limits and an IOMMU on by default. No loadable modules, kexec, BPF, io_uring or user namespaces.
Every upstream source archive is checked against its SHA-256 and its maintainer's signature before it is compiled. The full source of each release is published.
How it works
Copy the 26 MB image to a USB stick with dd, Rufus or balenaEtcher. Nothing is installed.
Start the computer from the stick. esOS boots on UEFI and legacy BIOS machines, from USB or DVD.
Choose your keyboard with keyboard_setup, mount your storage, and encrypt with a password or an RSA key using esx.
Run poweroff. Mounted file systems are unmounted in reverse order. esOS does not touch the computer's own drives unless you mount one.
Inside esOS 1.0
esOS is built from source with a fixed set of components. The kernel has every driver built in, the init process is about 500 lines of C, and the image fits in 26 MB.
Full component list with licenses: Licenses.
| Kernel | Linux 6.18.54 LTS · x86-64-v3 · modules off |
|---|---|
| Boot loader | GRUB 2.16 · UEFI + legacy BIOS |
| C library | glibc 2.44 |
| Cryptography | OpenSSL 3.5.8 LTS · cryptsetup 2.8.8 (LUKS2) |
| Application | Encryption Studio X (esx) · .NET NativeAOT |
| Shell and tools | bash 5.3 · coreutils 9.12 · util-linux 2.42.4 |
| File systems | ext4 · FAT · exFAT · NTFS · ISO 9660 · Btrfs · XFS |
| Storage | USB · NVMe · SATA · SD/eMMC |
| Keyboard layouts | TR-Q · TR-F · US · UK · DE · FR · ES · IT · RU |
| Network | none (AF_UNIX only) |
Intel Haswell (2013) or AMD Excavator/Zen and newer. Secure Boot must be turned off.