README.md (17605B)
1 <div align="center"> 2 3 <h1>☧ N I X D A E M O N</h1> 4 5 <p><em>A declarative NixOS offensive-security workstation, as one flake.<br/> 6 The successor to IceBreaker.</em></p> 7 8 <a href="docs/install.md"><img src="https://readme-typing-svg.demolab.com?font=JetBrains+Mono&weight=600&size=16&duration=4200&pause=1100&color=CBF7AD¢er=true&vCenter=true&width=760&lines=%24+git+clone+%E2%80%A6%2FNixDaemon+%26%26+nixos-install+--flake+.%23nixdaemon;%3E+one+file+of+settings.+any+machine.+x86_64+%C2%B7+aarch64.;%3E+htbup+%E2%86%92+htbbox+new+%E2%86%92+htbscan+full+%E2%86%92+revshell;%3E+ALL+SYSTEMS+OPERATIONAL." alt="typing: git clone, nixos-install, htbup, htbbox, htbscan, revshell"/></a> 9 10 <p> 11 <img src="https://img.shields.io/badge/NIXOS-unstable-c4a7e7?style=for-the-badge&logo=nixos&logoColor=cbf7ad&labelColor=0a0e14" alt="NixOS unstable"/> 12 <img src="https://img.shields.io/badge/FLAKE-dendritic-cbf7ad?style=for-the-badge&labelColor=0a0e14" alt="dendritic flake"/> 13 <img src="https://img.shields.io/badge/ROS%C3%89_PINE-dark-eb6f92?style=for-the-badge&labelColor=0a0e14" alt="Rosé Pine"/> 14 <br/> 15 <img src="https://img.shields.io/badge/x86__64-linux-7ee8fa?style=for-the-badge&labelColor=0a0e14" alt="x86_64-linux"/> 16 <img src="https://img.shields.io/badge/aarch64-linux-7ee8fa?style=for-the-badge&labelColor=0a0e14" alt="aarch64-linux"/> 17 <img src="https://img.shields.io/badge/CATEGORIES-23-c4a7e7?style=for-the-badge&labelColor=0a0e14" alt="23 categories"/> 18 <img src="https://img.shields.io/badge/SMOKE_TESTED-every_category-ffb347?style=for-the-badge&labelColor=0a0e14" alt="every category smoke-tested"/> 19 </p> 20 21 <p> 22 <a href="docs/install.md"><img src="https://img.shields.io/badge/%E2%96%B6_INSTALL-cbf7ad?style=for-the-badge&labelColor=0a0e14" alt="Install"/></a> 23 <a href="#03-daily-ops"><img src="https://img.shields.io/badge/%E2%8C%A8_DAILY_OPS-c4a7e7?style=for-the-badge&labelColor=0a0e14" alt="Daily ops"/></a> 24 <a href="#04-arsenal"><img src="https://img.shields.io/badge/%E2%96%A6_ARSENAL-eb6f92?style=for-the-badge&labelColor=0a0e14" alt="Arsenal"/></a> 25 <a href="docs/install.md#9-when-something-goes-wrong"><img src="https://img.shields.io/badge/%E2%9A%A0_FLATLINE-ffb347?style=for-the-badge&labelColor=0a0e14" alt="Troubleshooting"/></a> 26 </p> 27 28 </div> 29 30 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 31 32 <a id="what-is-this"></a> 33 <div align="center"><img src="docs/images/headers/00-what-is-this.png" width="800" alt="// WHAT IS THIS"/></div> 34 35 NixDaemon is a complete pentesting workstation declared in code: every tool, 36 every helper script, the desktop, the shell and the theme come from this 37 flake. One command builds the whole machine, and the same command rebuilds 38 it identically anywhere else. A bad change is undone by booting the previous 39 generation. 40 41 It is built for authorised work — HackTheBox, the CPTS path, labs and scoped 42 engagements — and organised around that workflow: connect the VPN, open a 43 box, scan, enumerate, catch a shell, record it all for the write-up. 44 45 ```text 46 $ htbup # VPN up, shows your tunnel IP 47 $ htbbox new Sauna 10.10.10.175 win easy # box directory + box.json + $TARGET + /etc/hosts 48 $ htbscan full # -p- then -sC -sV on what is open → recon/, box.json 49 $ revshell ps64 9001 # base64 PowerShell for your tunnel IP 50 $ htbbox flag user 3f2a… # status follows: active → user → root 51 ``` 52 53 <div align="center"><img src="docs/images/jack-in-flow.svg" width="900" alt="clone → edit _settings.nix → nixos-install → jack in"/></div> 54 55 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 56 57 <a id="00-payload-manifest"></a> 58 <div align="center"><img src="docs/images/headers/01-payload-manifest.png" width="800" alt="[00] PAYLOAD MANIFEST"/></div> 59 60 | Layer | What you get | 61 |---|---| 62 | **Toolkit** | 23 categories, each one switch. 12 on by default (the CPTS set): recon, AD, web, pivot, crack, shells, payloads, wordlists, BloodHound CE, Python/impacket, GUI tools, core. 11 more one line away: DFIR, reversing, wireless, radio, hardware, C2, database, cloud, OSINT, social, mobile. | 63 | **HTB workflow** | `htbvpn`/`htbup` (OpenVPN as a systemd unit), `htbtarget` (`$TARGET` in every terminal + `/etc/hosts` for Kerberos), `htbtime` (clock skew), `htbbox` (per-box tree and `box.json`), `htbscan`, `revshell`, `hcmode`, `htbcast` (session recording → write-up transcript), `payload-serve` | 64 | **Arsenal** | `~/pentesting/` with permanent `$privesc $potatoes $mimikatz $ad $sharp $ligolo $chisel …` variables and `htbpaths` to find things. ligolo-ng, chisel, fscan and pspy cross-compiled from source for every OS/arch; the potato family, SharpCollection, PEASS, mimikatz, static nmap/socat — every download pinned by hash. | 65 | **Desktop** | Niri (scrolling Wayland) + Noctalia shell in Rosé Pine by default. For VMs without 3D, two X11 desktops in Rosé Pine, **off until you choose one**: XFCE (full desktop) or i3 (lightweight tiling). Or headless + SSH. | 66 | **VM support** | guest tools for VMware, VirtualBox, QEMU/KVM/UTM and Hyper-V from one setting; VMware/VirtualBox shared folders with `sharedFolders = true`. | 67 | **Claude Code skill** | `~/.claude/skills/nixdaemon` is installed for you, so `claude` knows how the system is built and how to troubleshoot it ([skills/nixdaemon](skills/nixdaemon/SKILL.md)). | 68 | **Shell** | zsh, starship prompt with `$TARGET`, fzf, zoxide, kitty with tmux-style keys, Neovim (nvf), yazi. | 69 | **Cards** | `pentest-cheat`, `niri-cheat`, `nix-cheat` — the whole workflow in the terminal, section by section. | 70 | **Tests** | `nix flake check`: every category's binaries are resolved and run, impacket alias collisions are caught, and NixOS VM tests boot the VPN, target and clock helpers. | 71 72 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div> 73 74 <a id="01-system-requirements"></a> 75 <div align="center"><img src="docs/images/headers/02-system-requirements.png" width="800" alt="[01] SYSTEM REQUIREMENTS"/></div> 76 77 | | Minimum | Comfortable | 78 |---|---|---| 79 | CPU | x86_64 or aarch64 | 4+ cores | 80 | RAM | 4 GB | 8–16 GB | 81 | Disk | 60 GB | 100 GB | 82 | Firmware | UEFI or legacy BIOS | UEFI, Secure Boot off | 83 | Runs on | bare metal · VMware · VirtualBox · QEMU/KVM · Proxmox · UTM · Parallels · Hyper-V | | 84 85 On aarch64 everything works except BloodHound CE (switched off for you) and 86 the `mobile` category. Only want the tools on an existing Linux or WSL? See 87 [Path C](docs/install.md#5-path-c--just-the-tools-any-linux-wsl). 88 89 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 90 91 <a id="02-installation"></a> 92 <div align="center"><img src="docs/images/headers/03-installation.png" width="800" alt="[02] INSTALLATION — ANY MACHINE"/></div> 93 94 The full walk-through — partitioning, every hypervisor, an existing NixOS, 95 first boot, troubleshooting — is **[docs/install.md](docs/install.md)**. 96 The short version, from the NixOS minimal ISO with your disk mounted at 97 `/mnt`: 98 99 ```sh 100 nix-shell -p git 101 git clone https://gitlab.com/DAEMON-404/NixDaemon.git /mnt/home/operator/NixDaemon 102 cd /mnt/home/operator/NixDaemon 103 104 nano modules/hosts/generic/_settings.nix # user, arch, boot mode, VM, desktop, categories 105 nixos-generate-config --root /mnt --show-hardware-configuration \ 106 > modules/hosts/generic/_hardware-configuration.nix 107 108 nixos-install --flake .#nixdaemon && reboot 109 ``` 110 111 Everything about *your* machine is in those two files. `_settings.nix` looks 112 like this: 113 114 ```nix 115 { 116 user = "operator"; 117 hostName = "nixdaemon"; 118 system = "x86_64-linux"; # or "aarch64-linux" 119 boot = "efi"; # or "bios" 120 vm = "none"; # vmware | virtualbox | qemu | hyperv 121 desktop = "niri"; # "xfce" / "i3" for VMs without 3D (off by default), "none" for headless 122 sharedFolders = false; # VMware /mnt/hgfs, VirtualBox /media/sf_* 123 pentest = { dfir = false; reversing = true; wireless = false; … }; 124 } 125 ``` 126 127 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 128 129 <a id="03-daily-ops"></a> 130 <div align="center"><img src="docs/images/headers/04-daily-ops.png" width="800" alt="[03] DAILY OPS"/></div> 131 132 **The machine** 133 134 ```sh 135 nh os switch -H nixdaemon # rebuild after an edit: diff, sudo, activate 136 nix flake update && nh os switch -H nixdaemon # update everything 137 sudo nixos-rebuild switch --rollback # undo the last rebuild (or pick a generation at boot) 138 nh clean all --keep 5 # free disk (also runs weekly by itself) 139 ``` 140 141 **An engagement** 142 143 ```sh 144 htbup # VPN (profiles in ~/.config/htb/vpn/) 145 htbbox new EscapeTwo 10.10.11.202 win medium sequel.htb dc01.sequel.htb 146 htbscan full # nmap into $BOXDIR/recon, ports into box.json 147 htbtime # fix Kerberos clock skew against the DC 148 revshell bash # payload on stdout, the listener to run on stderr 149 hcmode kerb # which hashcat -m? 150 htbbox cred sql_svc 'P@ss' mssql # record as you go 151 htbbox info # the box card: ports, creds, flags, notes 152 htbcast -n foothold # record the terminal for the write-up 153 ``` 154 155 `pentest-cheat` has all of it; `pentest-cheat ad`, `pentest-cheat pivot` … 156 print one section. 157 158 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div> 159 160 <a id="04-arsenal"></a> 161 <div align="center"><img src="docs/images/headers/05-arsenal.png" width="800" alt="[04] ARSENAL — CATEGORIES"/></div> 162 163 <div align="center"><img src="docs/images/arsenal-map.svg" width="900" alt="arsenal map: the twelve default categories and the eleven optional ones"/></div> 164 165 Each category is one file in `modules/features/pentest/` and one switch 166 (`daemon.pentest.<name>.enable`, set from `pentest = { … }` in 167 `_settings.nix`). Tools go into the system profile, so `sudo nmap -sS` and 168 `sudo responder` just work. `nix develop .#pentest-<name>` gives you any 169 category in a throwaway shell without installing it. 170 171 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 172 173 <a id="05-adding-removing"></a> 174 <div align="center"><img src="docs/images/headers/06-adding-removing.png" width="800" alt="[05] ADDING & REMOVING PACKAGES"/></div> 175 176 **Into a toolkit category** — add the attribute to the category's `packages` 177 list, and its binary name to `expectedBins` so `nix flake check` proves it 178 installed: 179 180 ```nix 181 # modules/features/pentest/web.nix 182 packages = pkgs: with pkgs; [ 183 ffuf gobuster feroxbuster 184 wafw00f # ← new 185 ]; 186 expectedBins = [ "ffuf" "gobuster" "feroxbuster" "wafw00f" ]; 187 ``` 188 189 **Anything else, just for your machine** — add it in 190 `modules/hosts/generic/default.nix` under `environment.systemPackages`. 191 192 **Finding names**: `nix search nixpkgs <word>`, or <https://search.nixos.org>. 193 The attribute and the binary often differ (`thc-hydra` → `hydra`, `netexec` → 194 `nxc`, `testssl` → `testssl.sh`); `expectedBins` is where that mismatch gets 195 caught. Then `git add` any new file and `nh os switch`. 196 197 **A whole new category** is one new file calling the category factory 198 (`_sets.nix`) plus one line in `modules/features/pentest/default.nix`; copy 199 `recon.nix` as the template. 200 201 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 202 203 <a id="06-architecture"></a> 204 <div align="center"><img src="docs/images/headers/07-architecture.png" width="800" alt="[06] ARCHITECTURE"/></div> 205 206 The flake is **dendritic**: [flake-parts](https://flake.parts) loads every 207 `*.nix` under `modules/` (via import-tree) as a module, and each file declares 208 the outputs it owns. Modules refer to each other by name through `self`, never 209 by path. Files and directories whose path contains `/_` are skipped — that is 210 where plain data and helper files live. 211 212 ```text 213 NixDaemon/ 214 ├── flake.nix inputs; outputs = import-tree ./modules 215 ├── docs/install.md installing, every platform 216 └── modules/ 217 ├── hosts/ 218 │ ├── generic/ ← YOUR machine: nixosConfigurations.nixdaemon 219 │ │ ├── _settings.nix the one file you edit 220 │ │ ├── _hardware-configuration.nix 221 │ │ ├── default.nix self.lib.mkHost settings → a NixOS system 222 │ │ └── home.nix the shared, self-contained home 223 │ └── laptop/ the author's machine (needs his secrets; not for you) 224 ├── features/ 225 │ ├── pentest/ 23 categories + the HTB workflow + the arsenal 226 │ │ ├── _sets.nix category factory: package list → module + check + dev shell 227 │ │ ├── htb.nix vpn.nix boxes.nix time.nix casts.nix helpers.nix 228 │ │ └── payloads.nix paths.nix _pkgs/ the pinned, cross-built arsenal 229 │ └── desktop/ niri + noctalia (`nix run .#niri`); xfce.nix, i3.nix, x11.nix for VMs 230 ├── skills/nixdaemon/ the Claude Code skill: system map, traps, diagnosis 231 └── home/ home-manager modules (terminal, prompt, neovim, cheats …) 232 ``` 233 234 Two hosts share one toolkit. `nixdaemon` (generic) is built from 235 `_settings.nix` and nothing personal; `nixos` (the author's laptop) layers his 236 identity, secrets, dotfiles and hardware fixes on top. The generic host builds 237 without anyone's keys. 238 239 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div> 240 241 <a id="07-when-things-break"></a> 242 <div align="center"><img src="docs/images/headers/08-when-things-break.png" width="800" alt="[07] WHEN THINGS BREAK"/></div> 243 244 | Symptom | Fix | 245 |---|---| 246 | "path does not exist" / missing attribute | `git add -A` — flakes only see tracked files | 247 | Black screen after logging in to Niri | no 3D in the VM: `desktop = "xfce"` or `"i3"`, rebuild from a text console (Ctrl+Alt+F2) | 248 | Stuck on anything | run `claude` — the installed `nixdaemon` skill knows this system's layout and traps | 249 | `Failed assertions: _settings.nix: …` | a value is misspelled; the message names it | 250 | Doesn't boot after install | wrong `boot` mode or `biosDevice`; fix from the ISO and re-run `nixos-install` | 251 | Build killed / frozen | out of RAM: add `--max-jobs 1 --cores 2` | 252 | `hash mismatch` on a payload | upstream changed a release file: `pentest-update` | 253 | Anything after a rebuild | boot the previous generation; nothing is lost | 254 255 More in [docs/install.md § 9](docs/install.md#9-when-something-goes-wrong). 256 257 > **Honest note.** NixDaemon is one person's toolkit opened up. The Niri desktop and the toolkit are what get daily use; XFCE, i3, aarch64 and some hypervisor combinations are newer and less tested, so things will not always work flawlessly. Issues and fixes are welcome. 258 259 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div> 260 261 <a id="08-documentation"></a> 262 <div align="center"><img src="docs/images/headers/09-documentation.png" width="800" alt="[08] DOCUMENTATION"/></div> 263 264 | Where | What | 265 |---|---| 266 | [docs/install.md](docs/install.md) | installing on bare metal, every hypervisor, an existing NixOS, or just the tools | 267 | `pentest-cheat` · [cheats/pentest.md](modules/home/cheats/pentest.md) | the toolkit and the HTB workflow, by section | 268 | `niri-cheat` · [cheats/niri.md](modules/home/cheats/niri.md) | the desktop's keys | 269 | `nix-cheat` · [cheats/nix.md](modules/home/cheats/nix.md) | rebuilding, updating, rollback, the repo | 270 | [modules/hosts/generic/_settings.nix](modules/hosts/generic/_settings.nix) | every machine setting, commented | 271 | the header comment of each `modules/**/*.nix` | why that file is the way it is | 272 273 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div> 274 275 <a id="09-lineage"></a> 276 <div align="center"><img src="docs/images/headers/10-lineage.png" width="800" alt="[09] LINEAGE — FROM ICEBREAKER"/></div> 277 278 NixDaemon replaces **IceBreaker**, the earlier NixOS pentest flake (12 279 categories, XFCE/Hyprland, a `setup.sh` installer, pipx for the Python 280 tools). What changed, and what came across: 281 282 | IceBreaker | NixDaemon | 283 |---|---| 284 | `setup.sh` edits files, then rebuilds | one `_settings.nix`, then plain `nixos-install` / `nixos-rebuild` | 285 | pipx installs Python tools at runtime | one pinned Python env; impacket scripts by bare name, collision-guarded | 286 | `ligolo-fetch.sh` downloads agents | ligolo-ng, chisel, fscan, pspy cross-built from source per OS/arch | 287 | `newbox`, `flag`, `cred`, `~/targets/` | `htbbox` with `box.json`, writes `/etc/hosts`, imports nmap XML | 288 | `settarget` + `~/.target.env` | `htbtarget`, live in every open terminal at its next prompt | 289 | `nmap-init` / `nmap-allports` / `nmap-targeted` | `htbscan [full\|ports\|udp]`, straight into the box | 290 | `revshell`, `hcmode` | carried over: `revshell` uses the tunnel IP, `hcmode` searches the installed hashcat | 291 | presets | `pentest = { … }` switches in `_settings.nix` | 292 | — | `nix flake check`: every category smoke-tested, VM tests for the HTB helpers | 293 294 The section headers, dividers and diagrams on this page are IceBreaker's 295 graphics, redrawn for NixDaemon. 296 297 --- 298 299 <p align="center">☧ · <a href="https://rosepinetheme.com/">Rosé Pine</a> all the way down · authorised targets only</p>