A rescue USB is a bootable environment used when the installed operating system cannot start or should not be trusted. The best image depends on the job: copying files, repairing filesystems, imaging a disk, testing hardware, resetting a system, or securely erasing storage. One image rarely does every task well.
Choose the tool by objective
Use Rescuezilla when you need a graphical disk image or restore workflow. SystemRescue is suited to Linux filesystems, networking, partitioning, and command-line recovery. Hiren’s BootCD PE provides a Windows-oriented recovery environment. ShredOS is specialized for secure erasure, while Ultimate Boot CD focuses on diagnostics and legacy utilities. The OnlyCyber rescue directory links to each project and its download page.
If the goal is simply to reinstall Linux, use the distribution’s official installation image rather than a general rescue collection.
Prepare a trustworthy image
Download from the project’s official website or listed mirror. Verify the SHA-256 checksum using the ISO checksum guide. Keep a note of the version and architecture. Avoid repacked images from file-sharing sites because you cannot easily determine what was added or removed.
- Use x86-64 images for most current PCs.
- Check whether Secure Boot is supported.
- Download networking or storage drivers separately when working with unusual hardware.
Write the USB carefully
Tools such as Rufus, balenaEtcher, Fedora Media Writer, or the Linux dd command can write an image. Confirm the destination device by capacity and model before starting. Writing an image destroys the previous partition layout on that USB drive. Eject it cleanly after completion and label it with the tool and version.
For a multi-boot drive, Ventoy can present several ISO files from one USB device. Test every image because boot options, persistence, and Secure Boot behavior differ.
Boot without damaging evidence
When recovering important files or investigating an incident, avoid writing to the affected disk. Mount filesystems read-only where possible and copy data to a separate healthy drive. If legal or forensic preservation matters, create a verified image before attempting repairs. Ordinary repair tools can change timestamps, journals, and filesystem metadata.
Disconnect unnecessary drives to reduce the chance of selecting the wrong device. Photograph drive labels and record each action during high-value recovery work.
Test and maintain the rescue drive
A rescue USB is useful only if the target computer can boot it. Test UEFI boot, keyboard, display, storage visibility, network access, and any required decryption support before an emergency. Rebuild the drive periodically because certificates expire, hardware changes, and old tools accumulate unpatched vulnerabilities.
- Keep a second USB for critical environments.
- Store checksums and documentation beside the downloaded images.
- Never assume a successful boot means every recovery function works.
Related resources
Continue with the focused tools and guides below. Verify important findings against official documentation and preserve the source and date of anything you may need to reference later.