NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

README.md (17605B)


      1 <div align="center">
      2 
      3 <h1>☧ N I X D A E M O N</h1>
      4 
      5 <p><em>A declarative NixOS offensive-security workstation, as one flake.<br/>
      6 The successor to IceBreaker.</em></p>
      7 
      8 <a href="docs/install.md"><img src="https://readme-typing-svg.demolab.com?font=JetBrains+Mono&weight=600&size=16&duration=4200&pause=1100&color=CBF7AD&center=true&vCenter=true&width=760&lines=%24+git+clone+%E2%80%A6%2FNixDaemon+%26%26+nixos-install+--flake+.%23nixdaemon;%3E+one+file+of+settings.+any+machine.+x86_64+%C2%B7+aarch64.;%3E+htbup+%E2%86%92+htbbox+new+%E2%86%92+htbscan+full+%E2%86%92+revshell;%3E+ALL+SYSTEMS+OPERATIONAL." alt="typing: git clone, nixos-install, htbup, htbbox, htbscan, revshell"/></a>
      9 
     10 <p>
     11   <img src="https://img.shields.io/badge/NIXOS-unstable-c4a7e7?style=for-the-badge&logo=nixos&logoColor=cbf7ad&labelColor=0a0e14" alt="NixOS unstable"/>
     12   <img src="https://img.shields.io/badge/FLAKE-dendritic-cbf7ad?style=for-the-badge&labelColor=0a0e14" alt="dendritic flake"/>
     13   <img src="https://img.shields.io/badge/ROS%C3%89_PINE-dark-eb6f92?style=for-the-badge&labelColor=0a0e14" alt="Rosé Pine"/>
     14   <br/>
     15   <img src="https://img.shields.io/badge/x86__64-linux-7ee8fa?style=for-the-badge&labelColor=0a0e14" alt="x86_64-linux"/>
     16   <img src="https://img.shields.io/badge/aarch64-linux-7ee8fa?style=for-the-badge&labelColor=0a0e14" alt="aarch64-linux"/>
     17   <img src="https://img.shields.io/badge/CATEGORIES-23-c4a7e7?style=for-the-badge&labelColor=0a0e14" alt="23 categories"/>
     18   <img src="https://img.shields.io/badge/SMOKE_TESTED-every_category-ffb347?style=for-the-badge&labelColor=0a0e14" alt="every category smoke-tested"/>
     19 </p>
     20 
     21 <p>
     22   <a href="docs/install.md"><img src="https://img.shields.io/badge/%E2%96%B6_INSTALL-cbf7ad?style=for-the-badge&labelColor=0a0e14" alt="Install"/></a>
     23   <a href="#03-daily-ops"><img src="https://img.shields.io/badge/%E2%8C%A8_DAILY_OPS-c4a7e7?style=for-the-badge&labelColor=0a0e14" alt="Daily ops"/></a>
     24   <a href="#04-arsenal"><img src="https://img.shields.io/badge/%E2%96%A6_ARSENAL-eb6f92?style=for-the-badge&labelColor=0a0e14" alt="Arsenal"/></a>
     25   <a href="docs/install.md#9-when-something-goes-wrong"><img src="https://img.shields.io/badge/%E2%9A%A0_FLATLINE-ffb347?style=for-the-badge&labelColor=0a0e14" alt="Troubleshooting"/></a>
     26 </p>
     27 
     28 </div>
     29 
     30 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
     31 
     32 <a id="what-is-this"></a>
     33 <div align="center"><img src="docs/images/headers/00-what-is-this.png" width="800" alt="// WHAT IS THIS"/></div>
     34 
     35 NixDaemon is a complete pentesting workstation declared in code: every tool,
     36 every helper script, the desktop, the shell and the theme come from this
     37 flake. One command builds the whole machine, and the same command rebuilds
     38 it identically anywhere else. A bad change is undone by booting the previous
     39 generation.
     40 
     41 It is built for authorised work — HackTheBox, the CPTS path, labs and scoped
     42 engagements — and organised around that workflow: connect the VPN, open a
     43 box, scan, enumerate, catch a shell, record it all for the write-up.
     44 
     45 ```text
     46 $ htbup                                   # VPN up, shows your tunnel IP
     47 $ htbbox new Sauna 10.10.10.175 win easy  # box directory + box.json + $TARGET + /etc/hosts
     48 $ htbscan full                            # -p- then -sC -sV on what is open → recon/, box.json
     49 $ revshell ps64 9001                      # base64 PowerShell for your tunnel IP
     50 $ htbbox flag user 3f2a…                  # status follows: active → user → root
     51 ```
     52 
     53 <div align="center"><img src="docs/images/jack-in-flow.svg" width="900" alt="clone → edit _settings.nix → nixos-install → jack in"/></div>
     54 
     55 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
     56 
     57 <a id="00-payload-manifest"></a>
     58 <div align="center"><img src="docs/images/headers/01-payload-manifest.png" width="800" alt="[00] PAYLOAD MANIFEST"/></div>
     59 
     60 | Layer | What you get |
     61 |---|---|
     62 | **Toolkit** | 23 categories, each one switch. 12 on by default (the CPTS set): recon, AD, web, pivot, crack, shells, payloads, wordlists, BloodHound CE, Python/impacket, GUI tools, core. 11 more one line away: DFIR, reversing, wireless, radio, hardware, C2, database, cloud, OSINT, social, mobile. |
     63 | **HTB workflow** | `htbvpn`/`htbup` (OpenVPN as a systemd unit), `htbtarget` (`$TARGET` in every terminal + `/etc/hosts` for Kerberos), `htbtime` (clock skew), `htbbox` (per-box tree and `box.json`), `htbscan`, `revshell`, `hcmode`, `htbcast` (session recording → write-up transcript), `payload-serve` |
     64 | **Arsenal** | `~/pentesting/` with permanent `$privesc $potatoes $mimikatz $ad $sharp $ligolo $chisel …` variables and `htbpaths` to find things. ligolo-ng, chisel, fscan and pspy cross-compiled from source for every OS/arch; the potato family, SharpCollection, PEASS, mimikatz, static nmap/socat — every download pinned by hash. |
     65 | **Desktop** | Niri (scrolling Wayland) + Noctalia shell in Rosé Pine by default. For VMs without 3D, two X11 desktops in Rosé Pine, **off until you choose one**: XFCE (full desktop) or i3 (lightweight tiling). Or headless + SSH. |
     66 | **VM support** | guest tools for VMware, VirtualBox, QEMU/KVM/UTM and Hyper-V from one setting; VMware/VirtualBox shared folders with `sharedFolders = true`. |
     67 | **Claude Code skill** | `~/.claude/skills/nixdaemon` is installed for you, so `claude` knows how the system is built and how to troubleshoot it ([skills/nixdaemon](skills/nixdaemon/SKILL.md)). |
     68 | **Shell** | zsh, starship prompt with `$TARGET`, fzf, zoxide, kitty with tmux-style keys, Neovim (nvf), yazi. |
     69 | **Cards** | `pentest-cheat`, `niri-cheat`, `nix-cheat` — the whole workflow in the terminal, section by section. |
     70 | **Tests** | `nix flake check`: every category's binaries are resolved and run, impacket alias collisions are caught, and NixOS VM tests boot the VPN, target and clock helpers. |
     71 
     72 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div>
     73 
     74 <a id="01-system-requirements"></a>
     75 <div align="center"><img src="docs/images/headers/02-system-requirements.png" width="800" alt="[01] SYSTEM REQUIREMENTS"/></div>
     76 
     77 | | Minimum | Comfortable |
     78 |---|---|---|
     79 | CPU | x86_64 or aarch64 | 4+ cores |
     80 | RAM | 4 GB | 8–16 GB |
     81 | Disk | 60 GB | 100 GB |
     82 | Firmware | UEFI or legacy BIOS | UEFI, Secure Boot off |
     83 | Runs on | bare metal · VMware · VirtualBox · QEMU/KVM · Proxmox · UTM · Parallels · Hyper-V | |
     84 
     85 On aarch64 everything works except BloodHound CE (switched off for you) and
     86 the `mobile` category. Only want the tools on an existing Linux or WSL? See
     87 [Path C](docs/install.md#5-path-c--just-the-tools-any-linux-wsl).
     88 
     89 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
     90 
     91 <a id="02-installation"></a>
     92 <div align="center"><img src="docs/images/headers/03-installation.png" width="800" alt="[02] INSTALLATION — ANY MACHINE"/></div>
     93 
     94 The full walk-through — partitioning, every hypervisor, an existing NixOS,
     95 first boot, troubleshooting — is **[docs/install.md](docs/install.md)**.
     96 The short version, from the NixOS minimal ISO with your disk mounted at
     97 `/mnt`:
     98 
     99 ```sh
    100 nix-shell -p git
    101 git clone https://gitlab.com/DAEMON-404/NixDaemon.git /mnt/home/operator/NixDaemon
    102 cd /mnt/home/operator/NixDaemon
    103 
    104 nano modules/hosts/generic/_settings.nix          # user, arch, boot mode, VM, desktop, categories
    105 nixos-generate-config --root /mnt --show-hardware-configuration \
    106   > modules/hosts/generic/_hardware-configuration.nix
    107 
    108 nixos-install --flake .#nixdaemon && reboot
    109 ```
    110 
    111 Everything about *your* machine is in those two files. `_settings.nix` looks
    112 like this:
    113 
    114 ```nix
    115 {
    116   user = "operator";
    117   hostName = "nixdaemon";
    118   system = "x86_64-linux";   # or "aarch64-linux"
    119   boot = "efi";              # or "bios"
    120   vm = "none";               # vmware | virtualbox | qemu | hyperv
    121   desktop = "niri";          # "xfce" / "i3" for VMs without 3D (off by default), "none" for headless
    122   sharedFolders = false;     # VMware /mnt/hgfs, VirtualBox /media/sf_*
    123   pentest = { dfir = false; reversing = true; wireless = false; … };
    124 }
    125 ```
    126 
    127 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
    128 
    129 <a id="03-daily-ops"></a>
    130 <div align="center"><img src="docs/images/headers/04-daily-ops.png" width="800" alt="[03] DAILY OPS"/></div>
    131 
    132 **The machine**
    133 
    134 ```sh
    135 nh os switch -H nixdaemon             # rebuild after an edit: diff, sudo, activate
    136 nix flake update && nh os switch -H nixdaemon   # update everything
    137 sudo nixos-rebuild switch --rollback  # undo the last rebuild (or pick a generation at boot)
    138 nh clean all --keep 5                 # free disk (also runs weekly by itself)
    139 ```
    140 
    141 **An engagement**
    142 
    143 ```sh
    144 htbup                                 # VPN (profiles in ~/.config/htb/vpn/)
    145 htbbox new EscapeTwo 10.10.11.202 win medium sequel.htb dc01.sequel.htb
    146 htbscan full                          # nmap into $BOXDIR/recon, ports into box.json
    147 htbtime                               # fix Kerberos clock skew against the DC
    148 revshell bash                         # payload on stdout, the listener to run on stderr
    149 hcmode kerb                           # which hashcat -m?
    150 htbbox cred sql_svc 'P@ss' mssql      # record as you go
    151 htbbox info                           # the box card: ports, creds, flags, notes
    152 htbcast -n foothold                   # record the terminal for the write-up
    153 ```
    154 
    155 `pentest-cheat` has all of it; `pentest-cheat ad`, `pentest-cheat pivot` …
    156 print one section.
    157 
    158 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div>
    159 
    160 <a id="04-arsenal"></a>
    161 <div align="center"><img src="docs/images/headers/05-arsenal.png" width="800" alt="[04] ARSENAL — CATEGORIES"/></div>
    162 
    163 <div align="center"><img src="docs/images/arsenal-map.svg" width="900" alt="arsenal map: the twelve default categories and the eleven optional ones"/></div>
    164 
    165 Each category is one file in `modules/features/pentest/` and one switch
    166 (`daemon.pentest.<name>.enable`, set from `pentest = { … }` in
    167 `_settings.nix`). Tools go into the system profile, so `sudo nmap -sS` and
    168 `sudo responder` just work. `nix develop .#pentest-<name>` gives you any
    169 category in a throwaway shell without installing it.
    170 
    171 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
    172 
    173 <a id="05-adding-removing"></a>
    174 <div align="center"><img src="docs/images/headers/06-adding-removing.png" width="800" alt="[05] ADDING & REMOVING PACKAGES"/></div>
    175 
    176 **Into a toolkit category** — add the attribute to the category's `packages`
    177 list, and its binary name to `expectedBins` so `nix flake check` proves it
    178 installed:
    179 
    180 ```nix
    181 # modules/features/pentest/web.nix
    182 packages = pkgs: with pkgs; [
    183   ffuf gobuster feroxbuster
    184   wafw00f                     # ← new
    185 ];
    186 expectedBins = [ "ffuf" "gobuster" "feroxbuster" "wafw00f" ];
    187 ```
    188 
    189 **Anything else, just for your machine** — add it in
    190 `modules/hosts/generic/default.nix` under `environment.systemPackages`.
    191 
    192 **Finding names**: `nix search nixpkgs <word>`, or <https://search.nixos.org>.
    193 The attribute and the binary often differ (`thc-hydra` → `hydra`, `netexec` →
    194 `nxc`, `testssl` → `testssl.sh`); `expectedBins` is where that mismatch gets
    195 caught. Then `git add` any new file and `nh os switch`.
    196 
    197 **A whole new category** is one new file calling the category factory
    198 (`_sets.nix`) plus one line in `modules/features/pentest/default.nix`; copy
    199 `recon.nix` as the template.
    200 
    201 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
    202 
    203 <a id="06-architecture"></a>
    204 <div align="center"><img src="docs/images/headers/07-architecture.png" width="800" alt="[06] ARCHITECTURE"/></div>
    205 
    206 The flake is **dendritic**: [flake-parts](https://flake.parts) loads every
    207 `*.nix` under `modules/` (via import-tree) as a module, and each file declares
    208 the outputs it owns. Modules refer to each other by name through `self`, never
    209 by path. Files and directories whose path contains `/_` are skipped — that is
    210 where plain data and helper files live.
    211 
    212 ```text
    213 NixDaemon/
    214 ├── flake.nix                     inputs; outputs = import-tree ./modules
    215 ├── docs/install.md               installing, every platform
    216 └── modules/
    217     ├── hosts/
    218     │   ├── generic/              ← YOUR machine: nixosConfigurations.nixdaemon
    219     │   │   ├── _settings.nix         the one file you edit
    220     │   │   ├── _hardware-configuration.nix
    221     │   │   ├── default.nix           self.lib.mkHost settings → a NixOS system
    222     │   │   └── home.nix              the shared, self-contained home
    223     │   └── laptop/               the author's machine (needs his secrets; not for you)
    224     ├── features/
    225     │   ├── pentest/              23 categories + the HTB workflow + the arsenal
    226     │   │   ├── _sets.nix             category factory: package list → module + check + dev shell
    227     │   │   ├── htb.nix vpn.nix boxes.nix time.nix casts.nix helpers.nix
    228     │   │   └── payloads.nix paths.nix _pkgs/   the pinned, cross-built arsenal
    229     │   └── desktop/              niri + noctalia (`nix run .#niri`); xfce.nix, i3.nix, x11.nix for VMs
    230 ├── skills/nixdaemon/             the Claude Code skill: system map, traps, diagnosis
    231     └── home/                     home-manager modules (terminal, prompt, neovim, cheats …)
    232 ```
    233 
    234 Two hosts share one toolkit. `nixdaemon` (generic) is built from
    235 `_settings.nix` and nothing personal; `nixos` (the author's laptop) layers his
    236 identity, secrets, dotfiles and hardware fixes on top. The generic host builds
    237 without anyone's keys.
    238 
    239 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div>
    240 
    241 <a id="07-when-things-break"></a>
    242 <div align="center"><img src="docs/images/headers/08-when-things-break.png" width="800" alt="[07] WHEN THINGS BREAK"/></div>
    243 
    244 | Symptom | Fix |
    245 |---|---|
    246 | "path does not exist" / missing attribute | `git add -A` — flakes only see tracked files |
    247 | Black screen after logging in to Niri | no 3D in the VM: `desktop = "xfce"` or `"i3"`, rebuild from a text console (Ctrl+Alt+F2) |
    248 | Stuck on anything | run `claude` — the installed `nixdaemon` skill knows this system's layout and traps |
    249 | `Failed assertions: _settings.nix: …` | a value is misspelled; the message names it |
    250 | Doesn't boot after install | wrong `boot` mode or `biosDevice`; fix from the ISO and re-run `nixos-install` |
    251 | Build killed / frozen | out of RAM: add `--max-jobs 1 --cores 2` |
    252 | `hash mismatch` on a payload | upstream changed a release file: `pentest-update` |
    253 | Anything after a rebuild | boot the previous generation; nothing is lost |
    254 
    255 More in [docs/install.md § 9](docs/install.md#9-when-something-goes-wrong).
    256 
    257 > **Honest note.** NixDaemon is one person's toolkit opened up. The Niri desktop and the toolkit are what get daily use; XFCE, i3, aarch64 and some hypervisor combinations are newer and less tested, so things will not always work flawlessly. Issues and fixes are welcome.
    258 
    259 <div align="center"><img src="docs/images/dividers/phosphor.png" width="600" alt=""/></div>
    260 
    261 <a id="08-documentation"></a>
    262 <div align="center"><img src="docs/images/headers/09-documentation.png" width="800" alt="[08] DOCUMENTATION"/></div>
    263 
    264 | Where | What |
    265 |---|---|
    266 | [docs/install.md](docs/install.md) | installing on bare metal, every hypervisor, an existing NixOS, or just the tools |
    267 | `pentest-cheat` · [cheats/pentest.md](modules/home/cheats/pentest.md) | the toolkit and the HTB workflow, by section |
    268 | `niri-cheat` · [cheats/niri.md](modules/home/cheats/niri.md) | the desktop's keys |
    269 | `nix-cheat` · [cheats/nix.md](modules/home/cheats/nix.md) | rebuilding, updating, rollback, the repo |
    270 | [modules/hosts/generic/_settings.nix](modules/hosts/generic/_settings.nix) | every machine setting, commented |
    271 | the header comment of each `modules/**/*.nix` | why that file is the way it is |
    272 
    273 <div align="center"><img src="docs/images/dividers/rose.png" width="600" alt=""/></div>
    274 
    275 <a id="09-lineage"></a>
    276 <div align="center"><img src="docs/images/headers/10-lineage.png" width="800" alt="[09] LINEAGE — FROM ICEBREAKER"/></div>
    277 
    278 NixDaemon replaces **IceBreaker**, the earlier NixOS pentest flake (12
    279 categories, XFCE/Hyprland, a `setup.sh` installer, pipx for the Python
    280 tools). What changed, and what came across:
    281 
    282 | IceBreaker | NixDaemon |
    283 |---|---|
    284 | `setup.sh` edits files, then rebuilds | one `_settings.nix`, then plain `nixos-install` / `nixos-rebuild` |
    285 | pipx installs Python tools at runtime | one pinned Python env; impacket scripts by bare name, collision-guarded |
    286 | `ligolo-fetch.sh` downloads agents | ligolo-ng, chisel, fscan, pspy cross-built from source per OS/arch |
    287 | `newbox`, `flag`, `cred`, `~/targets/` | `htbbox` with `box.json`, writes `/etc/hosts`, imports nmap XML |
    288 | `settarget` + `~/.target.env` | `htbtarget`, live in every open terminal at its next prompt |
    289 | `nmap-init` / `nmap-allports` / `nmap-targeted` | `htbscan [full\|ports\|udp]`, straight into the box |
    290 | `revshell`, `hcmode` | carried over: `revshell` uses the tunnel IP, `hcmode` searches the installed hashcat |
    291 | presets | `pentest = { … }` switches in `_settings.nix` |
    292 | — | `nix flake check`: every category smoke-tested, VM tests for the HTB helpers |
    293 
    294 The section headers, dividers and diagrams on this page are IceBreaker's
    295 graphics, redrawn for NixDaemon.
    296 
    297 ---
    298 
    299 <p align="center">☧ · <a href="https://rosepinetheme.com/">Rosé Pine</a> all the way down · authorised targets only</p>