NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

install.md (15156B)


      1 <div align="center">
      2   <img src="images/headers/03-installation.png" width="800" alt="[02] INSTALLATION — ANY MACHINE"/>
      3 </div>
      4 
      5 # Installing NixDaemon
      6 
      7 NixDaemon installs as the **generic host** (`nixosConfigurations.nixdaemon`,
      8 `modules/hosts/generic/`). It works on a PC, a laptop or a virtual machine,
      9 Intel/AMD or ARM, UEFI or legacy BIOS. You change **two files** and nothing
     10 else:
     11 
     12 | File | What goes in it |
     13 |---|---|
     14 | `modules/hosts/generic/_settings.nix` | user name, hostname, CPU architecture, boot mode, hypervisor, desktop, which toolkit categories |
     15 | `modules/hosts/generic/_hardware-configuration.nix` | your disks and kernel modules, generated by `nixos-generate-config` |
     16 
     17 > `modules/hosts/laptop/` is the author's own machine. It needs his secrets
     18 > and private dotfiles and **will not build for you** — ignore it.
     19 
     20 **Contents**
     21 
     22 1. [Requirements](#1-requirements)
     23 2. [Pick your path](#2-pick-your-path)
     24 3. [Path A — fresh install (bare metal or VM)](#3-path-a--fresh-install-bare-metal-or-vm)
     25 4. [Path B — you already run NixOS](#4-path-b--you-already-run-nixos)
     26 5. [Path C — just the tools (any Linux, WSL)](#5-path-c--just-the-tools-any-linux-wsl)
     27 6. [Hypervisor notes](#6-hypervisor-notes)
     28 7. [First boot](#7-first-boot)
     29 8. [Updating, rolling back, more machines](#8-updating-rolling-back-more-machines)
     30 9. [When something goes wrong](#9-when-something-goes-wrong)
     31 
     32 ---
     33 
     34 ## 1. Requirements
     35 
     36 | | Minimum | Comfortable |
     37 |---|---|---|
     38 | CPU | x86_64 or aarch64, 2 cores | 4+ cores |
     39 | RAM | 4 GB (install with `--max-jobs 1`) | 8–16 GB (BloodHound wants 4 GB on its own) |
     40 | Disk | 60 GB | 100 GB+ (old generations, wordlists, VMs) |
     41 | Network | needed for the whole install | wired or a stable Wi-Fi |
     42 
     43 The installed system is about **23 GB**, of which ~10 GB is downloaded
     44 pre-built from cache.nixos.org. Some things are compiled on your machine:
     45 the Python 3.12 AD tooling (impacket, certipy, lsassy …), the
     46 ligolo-ng/chisel/fscan/pspy agents cross-built for every OS and CPU, and a
     47 few editor plugins. Expect a first install to take **30–90 minutes**
     48 depending on CPU and bandwidth.
     49 
     50 **Architecture support.** Everything works on x86_64. On aarch64 (Apple
     51 Silicon VMs, ARM servers) BloodHound CE is switched off automatically (its
     52 pinned neo4j is x86_64-only) and the `mobile` category cannot be enabled.
     53 
     54 ---
     55 
     56 ## 2. Pick your path
     57 
     58 ```text
     59 Do you already run NixOS on this machine?
     60 ├── yes ─────────────────────────────────────────────▶ Path B
     61 └── no
     62     ├── want a full NixDaemon machine (PC or VM) ────▶ Path A
     63     └── want only the tools on your current Linux ───▶ Path C
     64 ```
     65 
     66 ---
     67 
     68 ## 3. Path A — fresh install (bare metal or VM)
     69 
     70 ### 3.1 Get the installer
     71 
     72 Download the **minimal ISO** from <https://nixos.org/download/#nixos-iso>:
     73 `x86_64` for Intel/AMD, `aarch64` for ARM (Apple Silicon with UTM/Parallels/
     74 VMware Fusion, ARM servers). Write it to a USB stick (`dd`, Ventoy, Rufus,
     75 balenaEtcher) or attach it to your VM — see [Hypervisor notes](#6-hypervisor-notes)
     76 first if you are in one.
     77 
     78 Boot it. On real hardware, **turn Secure Boot off** in the firmware setup;
     79 NixOS does not sign its bootloader by default.
     80 
     81 ### 3.2 Get online
     82 
     83 ```sh
     84 sudo -i                    # everything below runs as root
     85 ping -c1 nixos.org         # wired / VM networking: usually already up
     86 nmtui                      # Wi-Fi: pick the network, enter the password
     87 ```
     88 
     89 ### 3.3 Check how the machine booted
     90 
     91 ```sh
     92 [ -d /sys/firmware/efi ] && echo UEFI || echo BIOS
     93 lsblk                      # find your disk: /dev/nvme0n1, /dev/sda, /dev/vda …
     94 DISK=/dev/sda              # ← set this to YOUR disk. Everything on it is erased.
     95 ```
     96 
     97 ### 3.4 Partition, format, mount
     98 
     99 The labels (`nixos`, `boot`) matter: the placeholder hardware file finds the
    100 partitions by them.
    101 
    102 **UEFI** (most PCs since 2012, VMware, Hyper-V Gen 2, UTM, QEMU with OVMF):
    103 
    104 ```sh
    105 parted "$DISK" -- mklabel gpt
    106 parted "$DISK" -- mkpart ESP fat32 1MiB 1GiB
    107 parted "$DISK" -- set 1 esp on
    108 parted "$DISK" -- mkpart root ext4 1GiB 100%
    109 
    110 # partition names: /dev/sda1 /dev/sda2, but /dev/nvme0n1p1 /dev/nvme0n1p2
    111 P1=${DISK}1; P2=${DISK}2; case "$DISK" in *nvme*|*mmcblk*) P1=${DISK}p1; P2=${DISK}p2;; esac
    112 
    113 mkfs.fat -F 32 -n boot "$P1"
    114 mkfs.ext4 -L nixos "$P2"
    115 mount /dev/disk/by-label/nixos /mnt
    116 mkdir -p /mnt/boot
    117 mount -o umask=077 /dev/disk/by-label/boot /mnt/boot
    118 ```
    119 
    120 **BIOS** (old PCs; VirtualBox unless *Enable EFI* is ticked):
    121 
    122 ```sh
    123 parted "$DISK" -- mklabel msdos
    124 parted "$DISK" -- mkpart primary ext4 1MiB 100%
    125 mkfs.ext4 -L nixos "${DISK}1"
    126 mount /dev/disk/by-label/nixos /mnt
    127 ```
    128 
    129 Want swap? After install, a swap file is one line in `_hardware-configuration.nix`:
    130 `swapDevices = [ { device = "/var/lib/swapfile"; size = 8192; } ];`.
    131 Want full-disk encryption, btrfs or ZFS? Partition your way (the
    132 [NixOS manual](https://nixos.org/manual/nixos/stable/#sec-installation-manual-partitioning)
    133 has the recipes); just make sure to generate the hardware file in step 3.6.
    134 
    135 ### 3.5 Get NixDaemon
    136 
    137 Pick your user name now — it must match `user` in `_settings.nix` (step 3.6).
    138 
    139 ```sh
    140 U=operator                                     # ← your user name
    141 nix-shell -p git                               # git is not on the ISO
    142 git clone https://gitlab.com/DAEMON-404/NixDaemon.git /mnt/home/$U/NixDaemon
    143 cd /mnt/home/$U/NixDaemon
    144 ```
    145 
    146 ### 3.6 Configure
    147 
    148 ```sh
    149 nano modules/hosts/generic/_settings.nix
    150 ```
    151 
    152 Set at least `user` (same as `$U`), `system`, `boot` (and `biosDevice` for
    153 BIOS), `vm`, `desktop` and `timeZone`. Every option is explained in the file.
    154 
    155 Then generate the hardware file **into the repo**:
    156 
    157 ```sh
    158 nixos-generate-config --root /mnt --show-hardware-configuration \
    159   > modules/hosts/generic/_hardware-configuration.nix
    160 ```
    161 
    162 (Skipping this works only if you partitioned exactly as in 3.4 — the
    163 placeholder assumes those labels. Generating it is always the safer choice.)
    164 
    165 > **Flakes only see files git knows about.** Editing the two files above is
    166 > fine (they are already tracked). If you ever *add* a file, `git add` it
    167 > before building, or Nix will say it does not exist.
    168 
    169 ### 3.7 Install
    170 
    171 ```sh
    172 nixos-install --flake .#nixdaemon
    173 # low RAM (≤ 4 GB)?    nixos-install --flake .#nixdaemon --max-jobs 1 --cores 2
    174 ```
    175 
    176 It asks for a **root password** at the end. Then:
    177 
    178 ```sh
    179 reboot                     # remove the ISO / USB when the machine powers off
    180 ```
    181 
    182 Continue with [First boot](#7-first-boot).
    183 
    184 ---
    185 
    186 ## 4. Path B — you already run NixOS
    187 
    188 ```sh
    189 git clone https://gitlab.com/DAEMON-404/NixDaemon.git ~/NixDaemon
    190 cd ~/NixDaemon
    191 cp /etc/nixos/hardware-configuration.nix modules/hosts/generic/_hardware-configuration.nix
    192 nano modules/hosts/generic/_settings.nix
    193 ```
    194 
    195 In `_settings.nix`, make these **match your current system** or it may not
    196 boot:
    197 
    198 - `user` — your existing user name (your files are kept; the account is
    199   re-declared by NixDaemon, so groups and shell follow `_settings.nix`).
    200 - `boot` — `"efi"` if `/sys/firmware/efi` exists (this switches you to
    201   systemd-boot), else `"bios"` with `biosDevice` set to the disk GRUB is on now.
    202 - `hostName`, `timeZone`, `keyboard`.
    203 
    204 Build first, switch on the next boot (safest):
    205 
    206 ```sh
    207 sudo nixos-rebuild boot --flake .#nixdaemon
    208 sudo reboot
    209 ```
    210 
    211 Your old configuration stays in the boot menu as an earlier generation, so
    212 you can always go back. `/etc/nixos` is no longer used.
    213 
    214 ---
    215 
    216 ## 5. Path C — just the tools (any Linux, WSL)
    217 
    218 No NixOS needed: install Nix, then open a shell with the whole toolkit on
    219 `PATH`. Nothing is installed system-wide, and leaving the shell leaves no
    220 trace.
    221 
    222 ```sh
    223 # 1. Nix (Linux, WSL2). Determinate's installer enables flakes for you:
    224 curl -fsSL https://install.determinate.systems/nix | sh -s -- install
    225 
    226 # 2. the toolkit (x86_64-linux):
    227 nix develop gitlab:DAEMON-404/NixDaemon#pentest           # everything
    228 nix develop gitlab:DAEMON-404/NixDaemon#pentest-recon     # one category: -ad -web -crack -pivot …
    229 ```
    230 
    231 Limits: the dev shell has the **tools**, not the machine. `htbvpn`, `htbtarget`
    232 (`/etc/hosts`), the `~/pentesting` arsenal and `sudo nmap` need the NixOS
    233 install. The dev shells are x86_64-linux only (several tools exist only
    234 for x86_64); on ARM, install the generic host instead (Path A). macOS is not
    235 supported — use a VM ([UTM](https://mac.getutm.app/) + Path A).
    236 
    237 **WSL**: Path C works in WSL2. A full NixDaemon *inside* WSL is not supported
    238 (no systemd units for the VPN, no desktop); use Hyper-V or VMware instead.
    239 
    240 ---
    241 
    242 ## 6. Hypervisor notes
    243 
    244 Set `vm` in `_settings.nix` to install the matching guest tools (shared
    245 clipboard, automatic resolution, time sync). Give the VM **8 GB RAM, 4 CPUs,
    246 100 GB disk** if you can.
    247 
    248 > **The X11 desktops are off until you pick one.** `desktop` defaults to
    249 > `"niri"`. For a VM without working 3D set it to `"xfce"` (a full desktop,
    250 > Rosé Pine) or `"i3"` (a lightweight tiling window manager, Rosé Pine — the
    251 > whole VM idles around 0.9 GB). Both are newer than the Niri desktop and less
    252 > tested: expect the odd rough edge.
    253 
    254 | Hypervisor | `vm =` | Firmware → `boot =` | Graphics → `desktop =` |
    255 |---|---|---|---|
    256 | **VMware** Workstation / Fusion (x86) | `"vmware"` | set *UEFI* in VM options → `"efi"` | enable *Accelerate 3D graphics* → `"niri"` |
    257 | **VMware Fusion** on Apple Silicon | `"vmware"` | UEFI → `"efi"`, `system = "aarch64-linux"` | 3D on → `"niri"`, else `"xfce"` |
    258 | **VirtualBox** | `"virtualbox"` | default is BIOS → `"bios"` (`biosDevice = "/dev/sda"`); or tick *Enable EFI* → `"efi"` | VirtualBox's 3D is unreliable → `"xfce"` or `"i3"` |
    259 | **QEMU / KVM / virt-manager** | `"qemu"` | OVMF (UEFI) → `"efi"`, SeaBIOS → `"bios"` | *Virtio* video with *3D acceleration* + Spice *OpenGL* → `"niri"`; otherwise `"xfce"` |
    260 | **Proxmox** | `"qemu"` | OVMF → `"efi"` | no host GPU → `"xfce"` / `"i3"`, or `"none"` + SSH |
    261 | **UTM** (Apple Silicon) | `"qemu"` | UEFI → `"efi"`, `system = "aarch64-linux"` | *virtio-gpu-gl-pci* → `"niri"`, else `"xfce"` |
    262 | **Parallels** (Apple Silicon) | `"none"` | UEFI → `"efi"`, `system = "aarch64-linux"` | `"xfce"` |
    263 | **Hyper-V** | `"hyperv"` | Generation 2, **Secure Boot off** → `"efi"` | no 3D → `"xfce"` / `"i3"` |
    264 | **Cloud / headless server** | `"qemu"` or `"none"` | provider's default | `"none"`, `ssh = true` + your key |
    265 
    266 **Niri needs working 3D.** If you log in and get a black screen or are
    267 thrown back to the greeter, the VM has no usable OpenGL: switch to
    268 `desktop = "xfce"` or `"i3"` (see [§9](#9-when-something-goes-wrong)).
    269 
    270 **Shared folders**: set `sharedFolders = true;` and enable sharing in the
    271 hypervisor too. VMware mounts them at `/mnt/hgfs/<name>` (on first access);
    272 VirtualBox puts them at `/media/sf_<name>` and adds your user to `vboxsf`.
    273 Under XFCE and i3, VMware's clipboard and auto-resize come from
    274 open-vm-tools; on Niri (Wayland) the clipboard is not shared.
    275 
    276 **Disk device names differ**: VirtIO disks are `/dev/vda`, SATA/SCSI are
    277 `/dev/sda`, NVMe is `/dev/nvme0n1`. Check with `lsblk` before partitioning,
    278 and use the right one for `biosDevice`.
    279 
    280 ---
    281 
    282 ## 7. First boot
    283 
    284 1. Log in as your `user` with the `initialPassword` from `_settings.nix`
    285    (default `nixdaemon`), then **change it at once**:
    286 
    287    ```sh
    288    passwd
    289    ```
    290 
    291 2. Fix ownership of the checkout (it was cloned as root in Path A):
    292 
    293    ```sh
    294    sudo chown -R "$USER":users ~/NixDaemon
    295    ```
    296 
    297 3. Find your way around:
    298 
    299    ```sh
    300    pentest-cheat              # the toolkit card: htb workflow, recon, AD, pivot, crack, web …
    301    niri-cheat                 # the desktop's keys (Super+Return terminal, Super+Space launcher)
    302    htbpaths                   # the ~/pentesting arsenal and its $variables
    303    ```
    304 
    305 4. HTB / lab VPN: put your `.ovpn` file(s) in `~/.config/htb/vpn/`, then
    306    `htbup` (or `htbvpn up <name>`). `htbip` prints your tunnel address.
    307 
    308 5. Start a box:
    309 
    310    ```sh
    311    htbbox new Sauna 10.10.10.175 windows easy     # directory, box.json, $TARGET, /etc/hosts
    312    htbscan full                                    # nmap → recon/, ports into box.json
    313    revshell bash                                   # a reverse shell for your tunnel IP
    314    ```
    315 
    316 ---
    317 
    318 ## 8. Updating, rolling back, more machines
    319 
    320 ```sh
    321 cd ~/NixDaemon
    322 nh os switch -H nixdaemon              # rebuild after editing _settings.nix (shows a diff, asks for sudo)
    323 nix flake update && nh os switch -H nixdaemon     # update every input (nixpkgs etc.)
    324 git pull && nh os switch -H nixdaemon             # take upstream NixDaemon changes
    325 ```
    326 
    327 If you kept `hostName = "nixdaemon"`, plain `nh os switch` works without `-H`.
    328 The plain-Nix equivalent of all of these is
    329 `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon`.
    330 
    331 **Rolling back**: every rebuild is a new generation. Pick an older one in the
    332 boot menu, or `sudo nixos-rebuild switch --rollback`.
    333 
    334 **More than one machine** from one checkout: in your fork, add a file such as
    335 `modules/hosts/mine.nix`:
    336 
    337 ```nix
    338 { self, ... }:
    339 {
    340   flake.nixosConfigurations.vm = self.lib.mkHost (
    341     import ./generic/_settings.nix // {
    342       hostName = "vm";
    343       vm = "qemu";
    344       hardware = ./_vm-hardware.nix;   # that machine's nixos-generate-config output
    345     }
    346   );
    347 }
    348 ```
    349 
    350 then `git add` both files and install it with `--flake .#vm`.
    351 
    352 ---
    353 
    354 ## 9. When something goes wrong
    355 
    356 | Symptom | Fix |
    357 |---|---|
    358 | `error: … does not provide attribute … nixdaemon` or "path does not exist" | A new file is not tracked: `git add -A`, build again. |
    359 | `Failed assertions: _settings.nix: …` | A value in `_settings.nix` is misspelled; the message names it. |
    360 | Black screen / back at the greeter after choosing Niri | No 3D in the VM. Set `desktop = "xfce"` (or `"i3"`), then from a text console (Ctrl+Alt+F2) run `sudo nixos-rebuild switch --flake ~/NixDaemon#nixdaemon`. |
    361 | Machine does not boot after install | Wrong `boot` mode, or BIOS `biosDevice` pointing at the wrong disk. Boot the ISO, mount (3.4), fix `_settings.nix`, run `nixos-install` again. |
    362 | `No space left on device` during install | The disk is too small (60 GB minimum), or the target is not mounted at `/mnt`. |
    363 | Install killed / machine freezes while building | Out of RAM: `--max-jobs 1 --cores 2`, or give the VM more memory. |
    364 | `hash mismatch` fetching a payload | Upstream replaced a release file. Run `pentest-update` (re-pins), or turn that category off for now. |
    365 | Clock-skew errors from Kerberos tools | `htbtime` syncs your clock to the target's DC (and restores it after). |
    366 | You want the previous system back | Choose an older generation in the boot menu, or `sudo nixos-rebuild switch --rollback`. |
    367 
    368 **Ask Claude.** NixDaemon installs a Claude Code skill at
    369 `~/.claude/skills/nixdaemon` (source: [skills/nixdaemon/SKILL.md](../skills/nixdaemon/SKILL.md)):
    370 run `claude` and describe the problem — it knows which file to edit, the
    371 traps above and where the logs are. It shows changes before making them and
    372 leaves `sudo` to you.
    373 
    374 Still stuck? `nix flake check` runs every category's smoke test and the VM
    375 tests, and usually names the broken piece.