assets.nix (15978B)
1 # modules/features/pentest/_pkgs/assets.nix — prebuilt release files, as a table. 2 # 3 # Every entry is one download, pinned by hash, and where it lands in the 4 # arsenal (~/pentesting, see paths.nix). payloads.nix walks this list; adding 5 # a tool is adding an entry, nothing else. 6 # 7 # { dest = "privesc/windows/potatoes/SigmaPotato.exe"; url; hash; } 8 # a single file, installed at `dest` 9 # { dest = "ad/SharpHound"; unpack = "zip"; url; hash; } 10 # an archive, unpacked whole into the directory `dest` 11 # { dest = "privesc/windows/potatoes"; unpack = "zip"; only = [ "RemotePotato0.exe" ]; url; hash; } 12 # only the named members, flattened into `dest` 13 # 14 # Keep `url = …;` and `hash = …;` on consecutive lines: pentest-update 15 # (update.nix) finds release pins by that shape and re-points them. 16 # 17 # What is NOT here: anything Go that nixpkgs carries (ligolo-ng, chisel, fscan, 18 # pspy) is cross-compiled from source in payloads.nix instead, and .NET tools 19 # that only exist as source (Certify 2.x, SharpEfsPotato, RasmanPotato) come 20 # from SharpCollection or are skipped. Provenance beats convenience. 21 [ 22 ##### privesc / windows / potatoes ########################################## 23 # SeImpersonatePrivilege -> SYSTEM. Which one works depends on the Windows 24 # build and what is patched, so they all ship. Rough order to try on a 25 # modern host: GodPotato, SigmaPotato, PrintSpoofer, CoercedPotato, 26 # PrintNotifyPotato, then the rest. 27 { 28 dest = "privesc/windows/potatoes/GodPotato-NET2.exe"; 29 url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET2.exe"; 30 hash = "sha256-MCeiEicpVymL9NMlBTcPpj+xYtampuwJGvnXYmMXqFg="; 31 } 32 { 33 dest = "privesc/windows/potatoes/GodPotato-NET35.exe"; 34 url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET35.exe"; 35 hash = "sha256-MCeiEicpVymL9NMlBTcPpj+xYtampuwJGvnXYmMXqFg="; 36 } 37 { 38 dest = "privesc/windows/potatoes/GodPotato-NET4.exe"; 39 url = "https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET4.exe"; 40 hash = "sha256-mo6dWHtXDUB08cgxexY6qNDFZu/YjylNnYW8d3Y1Kig="; 41 } 42 { 43 dest = "privesc/windows/potatoes/SigmaPotato.exe"; 44 url = "https://github.com/tylerdotrar/SigmaPotato/releases/download/v1.2.6/SigmaPotato.exe"; 45 hash = "sha256-7Gimv38QSoFb0h4n5zqN+4r8soLUmXvr6ezNbIkllQY="; 46 } 47 { 48 dest = "privesc/windows/potatoes/SigmaPotatoCore.exe"; 49 url = "https://github.com/tylerdotrar/SigmaPotato/releases/download/v1.2.6/SigmaPotatoCore.exe"; 50 hash = "sha256-p6G8g/lGlsLvY34Swor9X1y7j30M8iy0GSHXe2w5pyE="; 51 } 52 { 53 dest = "privesc/windows/potatoes/DeadPotato-NET4.exe"; 54 url = "https://github.com/lypd0/DeadPotato/releases/download/v1.2/DeadPotato-NET4.exe"; 55 hash = "sha256-a8ihwq//pAnSlTaSZs+SKwgbjbzz2ifZiiM/u6uI2YM="; 56 } 57 { 58 dest = "privesc/windows/potatoes/PrintSpoofer64.exe"; 59 url = "https://github.com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer64.exe"; 60 hash = "sha256-hST7wNc+cR5p1gxk8fG3vvNcmGcFiAZD3U1eF3eeWG0="; 61 } 62 { 63 dest = "privesc/windows/potatoes/PrintSpoofer32.exe"; 64 url = "https://github.com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer32.exe"; 65 hash = "sha256-R8nv+BQkkKLDQXAaq3quvDVe7RVA7tU0qDF90eZWFLI="; 66 } 67 # The fork that actually publishes binaries; hackvens/CoercedPotato (the 68 # original) is source only. "Releases" is a rolling tag, so this pin is the 69 # 2026-07-30 build. 70 { 71 dest = "privesc/windows/potatoes/CoercedPotato_x64.exe"; 72 url = "https://github.com/Prepouce/CoercedPotato/releases/download/Releases/CoercedPotato_x64.exe"; 73 hash = "sha256-RTKJjW4xrLF6T/ihd5K7BmCzcW+ZNnsswVMHk7vh8S8="; 74 } 75 { 76 dest = "privesc/windows/potatoes/CoercedPotato_x86.exe"; 77 url = "https://github.com/Prepouce/CoercedPotato/releases/download/Releases/CoercedPotato_x86.exe"; 78 hash = "sha256-RvsS0pg+hmElFZ+x9NFz6Po/yrndTtD8hHuPi8rEil8="; 79 } 80 { 81 dest = "privesc/windows/potatoes/PrintNotifyPotato-NET35.exe"; 82 url = "https://github.com/BeichenDream/PrintNotifyPotato/releases/download/v1.00/PrintNotifyPotato-NET35.exe"; 83 hash = "sha256-ThRpxhpgF8ONhAxHUav90h/Zig/y1f26JtInzUSLX2Q="; 84 } 85 { 86 dest = "privesc/windows/potatoes/PrintNotifyPotato-NET46.exe"; 87 url = "https://github.com/BeichenDream/PrintNotifyPotato/releases/download/v1.00/PrintNotifyPotato-NET46.exe"; 88 hash = "sha256-lbEVA43rz/Qsb+bPGonkBys+A/Ng72JGDP/Pf19L3ac="; 89 } 90 { 91 dest = "privesc/windows/potatoes/PetitPotato.exe"; 92 url = "https://github.com/wh0amitz/PetitPotato/releases/download/v1.0.0/PetitPotato.exe"; 93 hash = "sha256-naQ4zylWfdL8akukJ4Vqdr7dN1DQyMLg5AOg9wnd1Gs="; 94 } 95 { 96 dest = "privesc/windows/potatoes/JuicyPotato.exe"; 97 url = "https://github.com/ohpe/juicy-potato/releases/download/v0.1/JuicyPotato.exe"; 98 hash = "sha256-D1bHA+m33euQZGknusBaXG2VMIyOE7iOXU9LVyQj4DY="; 99 } 100 { 101 dest = "privesc/windows/potatoes"; 102 unpack = "zip"; 103 only = [ "JuicyPotatoNG.exe" ]; 104 url = "https://github.com/antonioCoco/JuicyPotatoNG/releases/download/v1.1/JuicyPotatoNG.zip"; 105 hash = "sha256-jkVbpqLJBifMbLOLF7l022JRwex2PLg+66KIlwMapAk="; 106 } 107 { 108 dest = "privesc/windows/potatoes"; 109 unpack = "zip"; 110 only = [ "RoguePotato.exe" "RogueOxidResolver.exe" ]; 111 url = "https://github.com/antonioCoco/RoguePotato/releases/download/1.0/RoguePotato.zip"; 112 hash = "sha256-YVt58TkP8RaOi81y9zPHTUsQ/nSFX5AikYiz7hTiV6U="; 113 } 114 { 115 dest = "privesc/windows/potatoes"; 116 unpack = "zip"; 117 only = [ "LocalPotato.exe" ]; 118 url = "https://github.com/decoder-it/LocalPotato/releases/download/v1.1/LocalPotato.zip"; 119 hash = "sha256-PTLYdrX6oL75K6bpNb/S5C3kuD93Qp1Q12W6FhNf/kg="; 120 } 121 { 122 dest = "privesc/windows/potatoes"; 123 unpack = "zip"; 124 only = [ "RemotePotato0.exe" ]; 125 url = "https://github.com/antonioCoco/RemotePotato0/releases/download/1.2/RemotePotato0.zip"; 126 hash = "sha256-8YuNplaB0ThEB+hoLot9qJvyuoGHgtsL4JxkK8CZ/8Y="; 127 } 128 129 ##### privesc / windows ##################################################### 130 # FullPowers: a LOCAL/NETWORK SERVICE shell that lost SeImpersonate gets its 131 # default privileges back — then a potato finishes the job. 132 { 133 dest = "privesc/windows/FullPowers.exe"; 134 url = "https://github.com/itm4n/FullPowers/releases/download/v0.1/FullPowers.exe"; 135 hash = "sha256-5bUOkl5dv02pIjVSzGBLdF+LpI9vR/i9++ob7EdHzlA="; 136 } 137 { 138 dest = "privesc/windows/PrivescCheck.ps1"; 139 url = "https://github.com/itm4n/PrivescCheck/releases/download/2026.10.07-1/PrivescCheck.ps1"; 140 hash = "sha256-P3Nz+QMfN3QLI7ZShJw23mZqEuTbyr2vizNEZcWWc2A="; 141 } 142 143 ##### creds ################################################################# 144 # LSASS without mimikatz.exe: nanodump writes a minidump (parse it at home 145 # with pypykatz), PPLBlade gets past RunAsPPL. fortra publishes nanodump's 146 # builds in-tree, not as releases, so these are pinned to a commit. 147 { 148 dest = "creds/nanodump.x64.exe"; 149 url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump.x64.exe"; 150 hash = "sha256-rZ5N3OaKNPC6MBDmYoa8OqBWBDx9ynoiwyIqJ5YUAlo="; 151 } 152 { 153 dest = "creds/nanodump.x86.exe"; 154 url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump.x86.exe"; 155 hash = "sha256-6vbVCYwXv0qO6uDAI2+RqzK9yAUAogC4z0wRvjkLNHI="; 156 } 157 { 158 dest = "creds/nanodump_ppl_dump.x64.exe"; 159 url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump_ppl_dump.x64.exe"; 160 hash = "sha256-0kuaua1n+DeJkgx+G9GRK212zEZ/OXBscn4PLZlYJQQ="; 161 } 162 { 163 dest = "creds/nanodump_ppl_medic.x64.exe"; 164 url = "https://github.com/fortra/nanodump/raw/450d5b23aeba5e0f8f6e5fc826a08997b2237be9/dist/nanodump_ppl_medic.x64.exe"; 165 hash = "sha256-effVS4XKOSm4yuNKATx/mm05lkeF/2T91pLfdqfto5s="; 166 } 167 { 168 dest = "creds/PPLBlade.exe"; 169 url = "https://github.com/tastypepperoni/PPLBlade/releases/download/v1.0/PPLBlade.exe"; 170 hash = "sha256-mPBnn9SSpnr5KI8u+ayPmdgICSNkxxl+ZAmYdZAiKoU="; 171 } 172 173 ##### ad #################################################################### 174 # SharpHound for BloodHound CE. SharpCollection's SharpHound is the LEGACY 175 # collector, whose JSON CE cannot ingest — this one replaces it in ad/. 176 { 177 dest = "ad/SharpHound"; 178 unpack = "zip"; 179 url = "https://github.com/SpecterOps/SharpHound/releases/download/v2.17.0/SharpHound_v2.17.0_windows_x86.zip"; 180 hash = "sha256-Ce8SOtoivgCmr02/oo+ao1eTAgX4iZE3Q3PWNGCe+wM="; 181 } 182 { 183 dest = "ad"; 184 unpack = "zip"; 185 only = [ "rusthound-ce.exe" ]; 186 url = "https://github.com/g0h4n/RustHound-CE/releases/download/v2.5.23/rusthound-ce-Windows-gnu-x86_64.zip"; 187 hash = "sha256-UK7kQmP4d30n/QhcRlF+Z2LZxu6NqI07HZCuzCFMms0="; 188 } 189 # Certipy and bloodyAD as single Windows binaries, for when you are ON a 190 # domain-joined host and the python versions are on your side of the tunnel. 191 { 192 dest = "ad/Certipy.exe"; 193 url = "https://github.com/ly4k/Certipy/releases/download/5.1.0/Certipy.exe"; 194 hash = "sha256-yFLVbvDbX5Huel8gaxLDtI28ympbhbrrAna5gWFDSJs="; 195 } 196 { 197 dest = "ad/bloodyAD.exe"; 198 url = "https://github.com/CravateRouge/bloodyAD/releases/download/v2.5.5/bloodyAD.exe"; 199 hash = "sha256-V6Tn4tcaTwX5O+8ortMLYbIGAg1nDjIzyCMfGgIowr4="; 200 } 201 { 202 dest = "ad/SharpSCCM.exe"; 203 url = "https://github.com/Mayyhem/SharpSCCM/releases/download/v2.0.14/SharpSCCM.exe"; 204 hash = "sha256-l6BIvLVcAQjGj4f8txOW/O6TYAh1epVz5K7NugOR8m4="; 205 } 206 # KrbRelayEx is a .NET (core) app: the exe needs its dll and runtimeconfig 207 # beside it, so all three go in their own directory. 208 { 209 dest = "ad/KrbRelayEx/KrbRelayEx.exe"; 210 url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.exe"; 211 hash = "sha256-WE7Q21zEDIbx7XTWkc+av9JXgPze/gmdNLqej+/XNLw="; 212 } 213 { 214 dest = "ad/KrbRelayEx/KrbRelayEx.dll"; 215 url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.dll"; 216 hash = "sha256-Qx4O65q3mQGoN3jF81oUciBh+DUu18qa/3AXFxlVpn8="; 217 } 218 { 219 dest = "ad/KrbRelayEx/KrbRelayEx.runtimeconfig.json"; 220 url = "https://github.com/decoder-it/KrbRelayEx/releases/download/v1.2/KrbRelayEx.runtimeconfig.json"; 221 hash = "sha256-KDKc8I9lBec4BrF1WLGHwC8MHFFv5H6/t6AT0IKqowY="; 222 } 223 { 224 dest = "ad"; 225 unpack = "zip"; 226 only = [ "Inveigh.exe" "Inveigh.exe.config" ]; 227 url = "https://github.com/Kevin-Robertson/Inveigh/releases/download/v2.0.12/Inveigh-net4.6.2-v2.0.12.zip"; 228 hash = "sha256-Txz0+3mOZF9KJ7jqycN+AQGVLcSYE7ueTzB5/wgqrS4="; 229 } 230 # ropnop's kerbrute (Go). Not the nixpkgs `kerbrute`, which is Tarlogic's 231 # python tool of the same name. Prebuilt: the module predates go.sum 232 # discipline and does not build cleanly from source any more. 233 { 234 dest = "ad/kerbrute/kerbrute-linux-amd64"; 235 url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_linux_amd64"; 236 hash = "sha256-cQqdJlPIvTaJ5FF3jaudrsDeTEx1+QB4jM8j7yVLEio="; 237 } 238 { 239 dest = "ad/kerbrute/kerbrute-linux-386"; 240 url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_linux_386"; 241 hash = "sha256-P3vR6d4Ufi6aiYq2WsyTLP/WvqhAA9imUt+lLkwajK0="; 242 } 243 { 244 dest = "ad/kerbrute/kerbrute-darwin-amd64"; 245 url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_darwin_amd64"; 246 hash = "sha256-Gf7ASh528ct8IQlUqNEeYTydN2KaA2x41WK/Q4rpYoA="; 247 } 248 { 249 dest = "ad/kerbrute/kerbrute-windows-amd64.exe"; 250 url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_windows_amd64.exe"; 251 hash = "sha256-0YqoS3vw796ca12yo4qx7JSExZxShMC9CA9Rl7+TiLA="; 252 } 253 { 254 dest = "ad/kerbrute/kerbrute-windows-386.exe"; 255 url = "https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_windows_386.exe"; 256 hash = "sha256-WqA168M1nuhRfZlWnIiB/Lf0irfpovEB9+fsI+Y2x5s="; 257 } 258 259 ##### shells ################################################################ 260 { 261 dest = "shells"; 262 unpack = "zip"; 263 only = [ "RunasCs.exe" "RunasCs_net2.exe" ]; 264 url = "https://github.com/antonioCoco/RunasCs/releases/download/v1.5/RunasCs.zip"; 265 hash = "sha256-iPgmCWvh7RvjLdRdwjgRid98XzSce4CO24cuaL5Kk1A="; 266 } 267 # No releases or tags upstream; pinned to a commit. 268 { 269 dest = "shells/nc64.exe"; 270 url = "https://raw.githubusercontent.com/int0x33/nc.exe/fa87aa42c460d34966efb998a1788efca6db11a7/nc64.exe"; 271 hash = "sha256-Plk3n1hevwvstrTgbQ+7+AbeKKS7JW6De0VV8bQkVXE="; 272 } 273 { 274 dest = "shells/nc.exe"; 275 url = "https://raw.githubusercontent.com/int0x33/nc.exe/fa87aa42c460d34966efb998a1788efca6db11a7/nc.exe"; 276 hash = "sha256-6PvsJdtPnZW16PQcylGksyvoZ0pN6npFtveusi28ONs="; 277 } 278 279 ##### pivoting ############################################################## 280 { 281 dest = "pivoting/plink-x64.exe"; 282 url = "https://the.earth.li/~sgtatham/putty/0.85/w64/plink.exe"; 283 hash = "sha256-lp82h51XFqoamBH0OmplEOjwg3Lb65aVuBC5x3bznHU="; 284 } 285 { 286 dest = "pivoting/plink-x86.exe"; 287 url = "https://the.earth.li/~sgtatham/putty/0.85/w32/plink.exe"; 288 hash = "sha256-x76EzEJWWtTefnfpnwph86jewXx31f8a+tedAFr1TJM="; 289 } 290 291 ##### recon ################################################################# 292 # 7.92 is the last nmap that nmap.org ships as a portable zip; everything 293 # newer is an NSIS installer only. Runs unprivileged for -sT/-sV without 294 # npcap; the bundled npcap installer is there if you are admin. 295 { 296 dest = "recon/nmap/windows"; 297 unpack = "zip"; 298 url = "https://nmap.org/dist/nmap-7.92-win32.zip"; 299 hash = "sha256-tUxU1LR4ytGVZ6UEx8a3Iw39gKzYgdwukBWmKKPvpx4="; 300 } 301 302 # Static nmap for the target itself — ernw's musl static-pie builds, one per 303 # arch. The tarball has no top-level dir: nmap/ncat/nping sit beside a data/ 304 # dir, and nmap needs `NMAPDIR=<dir>/data`. Unpacked into its own arch dir so 305 # the four data/ copies don't collide. 306 { 307 dest = "recon/nmap/linux-amd64"; 308 unpack = "tar"; 309 url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-x86_64-portable.tar.gz"; 310 hash = "sha256-uVVdnAJvlFjJVWT6Gh/0KMu/ho/1poubSAszUy673nE="; 311 } 312 { 313 dest = "recon/nmap/linux-x86"; 314 unpack = "tar"; 315 url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-x86-portable.tar.gz"; 316 hash = "sha256-nBKaHgaAP4lw7WtfRU5SiI165TXT1G3GjO5TA8ZpRqI="; 317 } 318 { 319 dest = "recon/nmap/linux-arm64"; 320 unpack = "tar"; 321 url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-aarch64-portable.tar.gz"; 322 hash = "sha256-8haqFI4Rg3Az4+73D+BiktHmgV5ZkEghisxMc4llbuI="; 323 } 324 { 325 dest = "recon/nmap/linux-armhf"; 326 unpack = "tar"; 327 url = "https://github.com/ernw/static-toolbox/releases/download/nmap-v7.94SVN/nmap-7.94SVN-armhf-portable.tar.gz"; 328 hash = "sha256-uJsSvCKKAOwlASnPHmok6vl5aSDt5suFoTAbJMZJCyQ="; 329 } 330 331 ##### pivoting / socat (static, per arch) ################################### 332 # ernw's static socat — the Windows builds need cygwin1.dll, these do not. 333 { 334 dest = "pivoting/socat/socat-linux-amd64"; 335 url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-x86_64"; 336 hash = "sha256-Gf0oS41I/v8qFcw3vZugcCI9pXXk6EYjrqS4j27+tZc="; 337 } 338 { 339 dest = "pivoting/socat/socat-linux-x86"; 340 url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-x86"; 341 hash = "sha256-mBFvSL9wT8saQOtrhPZOIostY+bt82p1IEUu0L2Ua18="; 342 } 343 { 344 dest = "pivoting/socat/socat-linux-arm64"; 345 url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-aarch64"; 346 hash = "sha256-dY8CPZonrjt/X2M+9BvtZbgSrw3Ya0r+3jeSXkBd3D0="; 347 } 348 { 349 dest = "pivoting/socat/socat-linux-armhf"; 350 url = "https://github.com/ernw/static-toolbox/releases/download/socat-v1.7.4.4/socat-1.7.4.4-armhf"; 351 hash = "sha256-kgH9gK3143Hy7QZdInkw6M19pnMc/cl0FycxYUDdFGQ="; 352 } 353 ]