NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

assets.nix (15978B)


      1 # modules/features/pentest/_pkgs/assets.nix — prebuilt release files, as a table.
      2 #
      3 # Every entry is one download, pinned by hash, and where it lands in the
      4 # arsenal (~/pentesting, see paths.nix). payloads.nix walks this list; adding
      5 # a tool is adding an entry, nothing else.
      6 #
      7 #   { dest = "privesc/windows/potatoes/SigmaPotato.exe"; url; hash; }
      8 #       a single file, installed at `dest`
      9 #   { dest = "ad/SharpHound"; unpack = "zip"; url; hash; }
     10 #       an archive, unpacked whole into the directory `dest`
     11 #   { dest = "privesc/windows/potatoes"; unpack = "zip"; only = [ "RemotePotato0.exe" ]; url; hash; }
     12 #       only the named members, flattened into `dest`
     13 #
     14 # Keep `url = …;` and `hash = …;` on consecutive lines: pentest-update
     15 # (update.nix) finds release pins by that shape and re-points them.
     16 #
     17 # What is NOT here: anything Go that nixpkgs carries (ligolo-ng, chisel, fscan,
     18 # pspy) is cross-compiled from source in payloads.nix instead, and .NET tools
     19 # that only exist as source (Certify 2.x, SharpEfsPotato, RasmanPotato) come
     20 # from SharpCollection or are skipped. Provenance beats convenience.
     21 [
     22   ##### privesc / windows / potatoes ##########################################
     23   # SeImpersonatePrivilege -> SYSTEM. Which one works depends on the Windows
     24   # build and what is patched, so they all ship. Rough order to try on a
     25   # modern host: GodPotato, SigmaPotato, PrintSpoofer, CoercedPotato,
     26   # PrintNotifyPotato, then the rest.
     27   {
     28     dest = "privesc/windows/potatoes/GodPotato-NET2.exe";
     29     url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET2.exe";
     30     hash = "sha256-MCeiEicpVymL9NMlBTcPpj+xYtampuwJGvnXYmMXqFg=";
     31   }
     32   {
     33     dest = "privesc/windows/potatoes/GodPotato-NET35.exe";
     34     url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET35.exe";
     35     hash = "sha256-MCeiEicpVymL9NMlBTcPpj+xYtampuwJGvnXYmMXqFg=";
     36   }
     37   {
     38     dest = "privesc/windows/potatoes/GodPotato-NET4.exe";
     39     url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET4.exe";
     40     hash = "sha256-mo6dWHtXDUB08cgxexY6qNDFZu/YjylNnYW8d3Y1Kig=";
     41   }
     42   {
     43     dest = "privesc/windows/potatoes/SigmaPotato.exe";
     44     url = "https://github.com/tylerdotrar/SigmaPotato/releases/download/v1.2.6/SigmaPotato.exe";
     45     hash = "sha256-7Gimv38QSoFb0h4n5zqN+4r8soLUmXvr6ezNbIkllQY=";
     46   }
     47   {
     48     dest = "privesc/windows/potatoes/SigmaPotatoCore.exe";
     49     url = "https://github.com/tylerdotrar/SigmaPotato/releases/download/v1.2.6/SigmaPotatoCore.exe";
     50     hash = "sha256-p6G8g/lGlsLvY34Swor9X1y7j30M8iy0GSHXe2w5pyE=";
     51   }
     52   {
     53     dest = "privesc/windows/potatoes/DeadPotato-NET4.exe";
     54     url = "https://github.com/lypd0/DeadPotato/releases/download/v1.2/DeadPotato-NET4.exe";
     55     hash = "sha256-a8ihwq//pAnSlTaSZs+SKwgbjbzz2ifZiiM/u6uI2YM=";
     56   }
     57   {
     58     dest = "privesc/windows/potatoes/PrintSpoofer64.exe";
     59     url = "https://github.com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer64.exe";
     60     hash = "sha256-hST7wNc+cR5p1gxk8fG3vvNcmGcFiAZD3U1eF3eeWG0=";
     61   }
     62   {
     63     dest = "privesc/windows/potatoes/PrintSpoofer32.exe";
     64     url = "https://github.com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer32.exe";
     65     hash = "sha256-R8nv+BQkkKLDQXAaq3quvDVe7RVA7tU0qDF90eZWFLI=";
     66   }
     67   # The fork that actually publishes binaries; hackvens/CoercedPotato (the
     68   # original) is source only. "Releases" is a rolling tag, so this pin is the
     69   # 2026-07-30 build.
     70   {
     71     dest = "privesc/windows/potatoes/CoercedPotato_x64.exe";
     72     url = "https://github.com/Prepouce/CoercedPotato/releases/download/Releases/CoercedPotato_x64.exe";
     73     hash = "sha256-RTKJjW4xrLF6T/ihd5K7BmCzcW+ZNnsswVMHk7vh8S8=";
     74   }
     75   {
     76     dest = "privesc/windows/potatoes/CoercedPotato_x86.exe";
     77     url = "https://github.com/Prepouce/CoercedPotato/releases/download/Releases/CoercedPotato_x86.exe";
     78     hash = "sha256-RvsS0pg+hmElFZ+x9NFz6Po/yrndTtD8hHuPi8rEil8=";
     79   }
     80   {
     81     dest = "privesc/windows/potatoes/PrintNotifyPotato-NET35.exe";
     82     url = "https://github.com/BeichenDream/PrintNotifyPotato/releases/download/v1.00/PrintNotifyPotato-NET35.exe";
     83     hash = "sha256-ThRpxhpgF8ONhAxHUav90h/Zig/y1f26JtInzUSLX2Q=";
     84   }
     85   {
     86     dest = "privesc/windows/potatoes/PrintNotifyPotato-NET46.exe";
     87     url = "https://github.com/BeichenDream/PrintNotifyPotato/releases/download/v1.00/PrintNotifyPotato-NET46.exe";
     88     hash = "sha256-lbEVA43rz/Qsb+bPGonkBys+A/Ng72JGDP/Pf19L3ac=";
     89   }
     90   {
     91     dest = "privesc/windows/potatoes/PetitPotato.exe";
     92     url = "https://github.com/wh0amitz/PetitPotato/releases/download/v1.0.0/PetitPotato.exe";
     93     hash = "sha256-naQ4zylWfdL8akukJ4Vqdr7dN1DQyMLg5AOg9wnd1Gs=";
     94   }
     95   {
     96     dest = "privesc/windows/potatoes/JuicyPotato.exe";
     97     url = "https://github.com/ohpe/juicy-potato/releases/download/v0.1/JuicyPotato.exe";
     98     hash = "sha256-D1bHA+m33euQZGknusBaXG2VMIyOE7iOXU9LVyQj4DY=";
     99   }
    100   {
    101     dest = "privesc/windows/potatoes";
    102     unpack = "zip";
    103     only = [ "JuicyPotatoNG.exe" ];
    104     url = "https://github.com/antonioCoco/JuicyPotatoNG/releases/download/v1.1/JuicyPotatoNG.zip";
    105     hash = "sha256-jkVbpqLJBifMbLOLF7l022JRwex2PLg+66KIlwMapAk=";
    106   }
    107   {
    108     dest = "privesc/windows/potatoes";
    109     unpack = "zip";
    110     only = [ "RoguePotato.exe" "RogueOxidResolver.exe" ];
    111     url = "https://github.com/antonioCoco/RoguePotato/releases/download/1.0/RoguePotato.zip";
    112     hash = "sha256-YVt58TkP8RaOi81y9zPHTUsQ/nSFX5AikYiz7hTiV6U=";
    113   }
    114   {
    115     dest = "privesc/windows/potatoes";
    116     unpack = "zip";
    117     only = [ "LocalPotato.exe" ];
    118     url = "https://github.com/decoder-it/LocalPotato/releases/download/v1.1/LocalPotato.zip";
    119     hash = "sha256-PTLYdrX6oL75K6bpNb/S5C3kuD93Qp1Q12W6FhNf/kg=";
    120   }
    121   {
    122     dest = "privesc/windows/potatoes";
    123     unpack = "zip";
    124     only = [ "RemotePotato0.exe" ];
    125     url = "https://github.com/antonioCoco/RemotePotato0/releases/download/1.2/RemotePotato0.zip";
    126     hash = "sha256-8YuNplaB0ThEB+hoLot9qJvyuoGHgtsL4JxkK8CZ/8Y=";
    127   }
    128 
    129   ##### privesc / windows #####################################################
    130   # FullPowers: a LOCAL/NETWORK SERVICE shell that lost SeImpersonate gets its
    131   # default privileges back — then a potato finishes the job.
    132   {
    133     dest = "privesc/windows/FullPowers.exe";
    134     url = "https://github.com/itm4n/FullPowers/releases/download/v0.1/FullPowers.exe";
    135     hash = "sha256-5bUOkl5dv02pIjVSzGBLdF+LpI9vR/i9++ob7EdHzlA=";
    136   }
    137   {
    138     dest = "privesc/windows/PrivescCheck.ps1";
    139     url = "https://github.com/itm4n/PrivescCheck/releases/download/2026.10.07-1/PrivescCheck.ps1";
    140     hash = "sha256-P3Nz+QMfN3QLI7ZShJw23mZqEuTbyr2vizNEZcWWc2A=";
    141   }
    142 
    143   ##### creds #################################################################
    144   # LSASS without mimikatz.exe: nanodump writes a minidump (parse it at home
    145   # with pypykatz), PPLBlade gets past RunAsPPL. fortra publishes nanodump's
    146   # builds in-tree, not as releases, so these are pinned to a commit.
    147   {
    148     dest = "creds/nanodump.x64.exe";
    149     url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump.x64.exe";
    150     hash = "sha256-rZ5N3OaKNPC6MBDmYoa8OqBWBDx9ynoiwyIqJ5YUAlo=";
    151   }
    152   {
    153     dest = "creds/nanodump.x86.exe";
    154     url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump.x86.exe";
    155     hash = "sha256-6vbVCYwXv0qO6uDAI2+RqzK9yAUAogC4z0wRvjkLNHI=";
    156   }
    157   {
    158     dest = "creds/nanodump_ppl_dump.x64.exe";
    159     url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump_ppl_dump.x64.exe";
    160     hash = "sha256-0kuaua1n+DeJkgx+G9GRK212zEZ/OXBscn4PLZlYJQQ=";
    161   }
    162   {
    163     dest = "creds/nanodump_ppl_medic.x64.exe";
    164     url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump_ppl_medic.x64.exe";
    165     hash = "sha256-effVS4XKOSm4yuNKATx/mm05lkeF/2T91pLfdqfto5s=";
    166   }
    167   {
    168     dest = "creds/PPLBlade.exe";
    169     url = "https://github.com/tastypepperoni/PPLBlade/releases/download/v1.0/PPLBlade.exe";
    170     hash = "sha256-mPBnn9SSpnr5KI8u+ayPmdgICSNkxxl+ZAmYdZAiKoU=";
    171   }
    172 
    173   ##### ad ####################################################################
    174   # SharpHound for BloodHound CE. SharpCollection's SharpHound is the LEGACY
    175   # collector, whose JSON CE cannot ingest — this one replaces it in ad/.
    176   {
    177     dest = "ad/SharpHound";
    178     unpack = "zip";
    179     url = "https://github.com/SpecterOps/SharpHound/releases/download/v2.17.0/SharpHound_v2.17.0_windows_x86.zip";
    180     hash = "sha256-Ce8SOtoivgCmr02/oo+ao1eTAgX4iZE3Q3PWNGCe+wM=";
    181   }
    182   {
    183     dest = "ad";
    184     unpack = "zip";
    185     only = [ "rusthound-ce.exe" ];
    186     url = "https://github.com/g0h4n/RustHound-CE/releases/download/v2.5.23/rusthound-ce-Windows-gnu-x86_64.zip";
    187     hash = "sha256-UK7kQmP4d30n/QhcRlF+Z2LZxu6NqI07HZCuzCFMms0=";
    188   }
    189   # Certipy and bloodyAD as single Windows binaries, for when you are ON a
    190   # domain-joined host and the python versions are on your side of the tunnel.
    191   {
    192     dest = "ad/Certipy.exe";
    193     url = "https://github.com/ly4k/Certipy/releases/download/5.1.0/Certipy.exe";
    194     hash = "sha256-yFLVbvDbX5Huel8gaxLDtI28ympbhbrrAna5gWFDSJs=";
    195   }
    196   {
    197     dest = "ad/bloodyAD.exe";
    198     url = "https://github.com/CravateRouge/bloodyAD/releases/download/v2.5.5/bloodyAD.exe";
    199     hash = "sha256-V6Tn4tcaTwX5O+8ortMLYbIGAg1nDjIzyCMfGgIowr4=";
    200   }
    201   {
    202     dest = "ad/SharpSCCM.exe";
    203     url = "https://github.com/Mayyhem/SharpSCCM/releases/download/v2.0.14/SharpSCCM.exe";
    204     hash = "sha256-l6BIvLVcAQjGj4f8txOW/O6TYAh1epVz5K7NugOR8m4=";
    205   }
    206   # KrbRelayEx is a .NET (core) app: the exe needs its dll and runtimeconfig
    207   # beside it, so all three go in their own directory.
    208   {
    209     dest = "ad/KrbRelayEx/KrbRelayEx.exe";
    210     url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.exe";
    211     hash = "sha256-WE7Q21zEDIbx7XTWkc+av9JXgPze/gmdNLqej+/XNLw=";
    212   }
    213   {
    214     dest = "ad/KrbRelayEx/KrbRelayEx.dll";
    215     url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.dll";
    216     hash = "sha256-Qx4O65q3mQGoN3jF81oUciBh+DUu18qa/3AXFxlVpn8=";
    217   }
    218   {
    219     dest = "ad/KrbRelayEx/KrbRelayEx.runtimeconfig.json";
    220     url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.runtimeconfig.json";
    221     hash = "sha256-KDKc8I9lBec4BrF1WLGHwC8MHFFv5H6/t6AT0IKqowY=";
    222   }
    223   {
    224     dest = "ad";
    225     unpack = "zip";
    226     only = [ "Inveigh.exe" "Inveigh.exe.config" ];
    227     url = "https://github.com/Kevin-Robertson/Inveigh/releases/download/v2.0.12/Inveigh-net4.6.2-v2.0.12.zip";
    228     hash = "sha256-Txz0+3mOZF9KJ7jqycN+AQGVLcSYE7ueTzB5/wgqrS4=";
    229   }
    230   # ropnop's kerbrute (Go). Not the nixpkgs `kerbrute`, which is Tarlogic's
    231   # python tool of the same name. Prebuilt: the module predates go.sum
    232   # discipline and does not build cleanly from source any more.
    233   {
    234     dest = "ad/kerbrute/kerbrute-linux-amd64";
    235     url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_linux_amd64";
    236     hash = "sha256-cQqdJlPIvTaJ5FF3jaudrsDeTEx1+QB4jM8j7yVLEio=";
    237   }
    238   {
    239     dest = "ad/kerbrute/kerbrute-linux-386";
    240     url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_linux_386";
    241     hash = "sha256-P3vR6d4Ufi6aiYq2WsyTLP/WvqhAA9imUt+lLkwajK0=";
    242   }
    243   {
    244     dest = "ad/kerbrute/kerbrute-darwin-amd64";
    245     url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_darwin_amd64";
    246     hash = "sha256-Gf7ASh528ct8IQlUqNEeYTydN2KaA2x41WK/Q4rpYoA=";
    247   }
    248   {
    249     dest = "ad/kerbrute/kerbrute-windows-amd64.exe";
    250     url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_windows_amd64.exe";
    251     hash = "sha256-0YqoS3vw796ca12yo4qx7JSExZxShMC9CA9Rl7+TiLA=";
    252   }
    253   {
    254     dest = "ad/kerbrute/kerbrute-windows-386.exe";
    255     url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_windows_386.exe";
    256     hash = "sha256-WqA168M1nuhRfZlWnIiB/Lf0irfpovEB9+fsI+Y2x5s=";
    257   }
    258 
    259   ##### shells ################################################################
    260   {
    261     dest = "shells";
    262     unpack = "zip";
    263     only = [ "RunasCs.exe" "RunasCs_net2.exe" ];
    264     url = "https://github.com/antonioCoco/RunasCs/releases/download/v1.5/RunasCs.zip";
    265     hash = "sha256-iPgmCWvh7RvjLdRdwjgRid98XzSce4CO24cuaL5Kk1A=";
    266   }
    267   # No releases or tags upstream; pinned to a commit.
    268   {
    269     dest = "shells/nc64.exe";
    270     url = "https://raw.githubusercontent.com/int0x33/nc.exe/fa87aa42c460d34966efb998a1788efca6db11a7/nc64.exe";
    271     hash = "sha256-Plk3n1hevwvstrTgbQ+7+AbeKKS7JW6De0VV8bQkVXE=";
    272   }
    273   {
    274     dest = "shells/nc.exe";
    275     url = "https://raw.githubusercontent.com/int0x33/nc.exe/fa87aa42c460d34966efb998a1788efca6db11a7/nc.exe";
    276     hash = "sha256-6PvsJdtPnZW16PQcylGksyvoZ0pN6npFtveusi28ONs=";
    277   }
    278 
    279   ##### pivoting ##############################################################
    280   {
    281     dest = "pivoting/plink-x64.exe";
    282     url = "https://the.earth.li/~sgtatham/putty/0.85/w64/plink.exe";
    283     hash = "sha256-lp82h51XFqoamBH0OmplEOjwg3Lb65aVuBC5x3bznHU=";
    284   }
    285   {
    286     dest = "pivoting/plink-x86.exe";
    287     url = "https://the.earth.li/~sgtatham/putty/0.85/w32/plink.exe";
    288     hash = "sha256-x76EzEJWWtTefnfpnwph86jewXx31f8a+tedAFr1TJM=";
    289   }
    290 
    291   ##### recon #################################################################
    292   # 7.92 is the last nmap that nmap.org ships as a portable zip; everything
    293   # newer is an NSIS installer only. Runs unprivileged for -sT/-sV without
    294   # npcap; the bundled npcap installer is there if you are admin.
    295   {
    296     dest = "recon/nmap/windows";
    297     unpack = "zip";
    298     url = "https://nmap.org/dist/nmap-7.92-win32.zip";
    299     hash = "sha256-tUxU1LR4ytGVZ6UEx8a3Iw39gKzYgdwukBWmKKPvpx4=";
    300   }
    301 
    302   # Static nmap for the target itself — ernw's musl static-pie builds, one per
    303   # arch. The tarball has no top-level dir: nmap/ncat/nping sit beside a data/
    304   # dir, and nmap needs `NMAPDIR=<dir>/data`. Unpacked into its own arch dir so
    305   # the four data/ copies don't collide.
    306   {
    307     dest = "recon/nmap/linux-amd64";
    308     unpack = "tar";
    309     url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-x86_64-portable.tar.gz";
    310     hash = "sha256-uVVdnAJvlFjJVWT6Gh/0KMu/ho/1poubSAszUy673nE=";
    311   }
    312   {
    313     dest = "recon/nmap/linux-x86";
    314     unpack = "tar";
    315     url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-x86-portable.tar.gz";
    316     hash = "sha256-nBKaHgaAP4lw7WtfRU5SiI165TXT1G3GjO5TA8ZpRqI=";
    317   }
    318   {
    319     dest = "recon/nmap/linux-arm64";
    320     unpack = "tar";
    321     url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-aarch64-portable.tar.gz";
    322     hash = "sha256-8haqFI4Rg3Az4+73D+BiktHmgV5ZkEghisxMc4llbuI=";
    323   }
    324   {
    325     dest = "recon/nmap/linux-armhf";
    326     unpack = "tar";
    327     url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-armhf-portable.tar.gz";
    328     hash = "sha256-uJsSvCKKAOwlASnPHmok6vl5aSDt5suFoTAbJMZJCyQ=";
    329   }
    330 
    331   ##### pivoting / socat (static, per arch) ###################################
    332   # ernw's static socat — the Windows builds need cygwin1.dll, these do not.
    333   {
    334     dest = "pivoting/socat/socat-linux-amd64";
    335     url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-x86_64";
    336     hash = "sha256-Gf0oS41I/v8qFcw3vZugcCI9pXXk6EYjrqS4j27+tZc=";
    337   }
    338   {
    339     dest = "pivoting/socat/socat-linux-x86";
    340     url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-x86";
    341     hash = "sha256-mBFvSL9wT8saQOtrhPZOIostY+bt82p1IEUu0L2Ua18=";
    342   }
    343   {
    344     dest = "pivoting/socat/socat-linux-arm64";
    345     url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-aarch64";
    346     hash = "sha256-dY8CPZonrjt/X2M+9BvtZbgSrw3Ya0r+3jeSXkBd3D0=";
    347   }
    348   {
    349     dest = "pivoting/socat/socat-linux-armhf";
    350     url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-armhf";
    351     hash = "sha256-kgH9gK3143Hy7QZdInkw6M19pnMc/cl0FycxYUDdFGQ=";
    352   }
    353 ]