NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

boxes.nix (2258B)


      1 # modules/features/pentest/boxes.nix — one directory and one box.json per box.
      2 #
      3 #   htbbox new Sauna 10.10.10.175 windows easy     positional, any order
      4 #   htbbox new Sauna 10.10.10.175 win easy sauna.htb dc01.sauna.htb
      5 #   htbbox new                                     prompt for everything (gum)
      6 #   htbbox use <box> | ls | info | path | json     switch and look around
      7 #   htbbox set | host | cred | flag | note | ports record what you find
      8 #
      9 # The CLI itself is _htbbox.py (stdlib python, its docstring is the manual).
     10 # It used to be ~200 lines of bash in this file plus a separate renderer; one
     11 # python file is easier to read, test and extend than either.
     12 #
     13 # The layout is the CPTS vocabulary, not the HTB website's:
     14 #
     15 #   box.json     the manifest: ip, os, difficulty, hostnames, domain, status,
     16 #                flags, creds, ports, notes. Every other tool reads it.
     17 #   writeup.md   the post, rendered once from the vault's Templater template
     18 #   recon/ enum/ creds/ loot/ exploit/ serve/ casts/
     19 #
     20 # `serve/` rather than `payloads/`: the global arsenal is ~/pentesting
     21 # ($PAYLOADS, paths.nix), and a per-box `payloads/` would read as the same thing.
     22 #
     23 # `new` and `use` write $STATE/box and call htbtarget, so $BOX, $BOXDIR,
     24 # $TARGET and /etc/hosts all follow the box in every terminal (htb.nix).
     25 { lib, ... }:
     26 {
     27   flake.nixosModules.pentest-boxes =
     28     { config, pkgs, lib, ... }:
     29     let
     30       on = config.daemon.pentest.enable;
     31 
     32       htbbox = pkgs.runCommand "htbbox"
     33         {
     34           nativeBuildInputs = [ pkgs.makeWrapper pkgs.python3 ];
     35           meta.mainProgram = "htbbox";
     36         }
     37         ''
     38           install -Dm0644 ${./_htbbox.py} $out/libexec/htbbox.py
     39           # A syntax error should fail the build, not the first `htbbox new`.
     40           python3 -m py_compile $out/libexec/htbbox.py
     41           rm -rf $out/libexec/__pycache__
     42           makeWrapper ${pkgs.python3}/bin/python3 $out/bin/htbbox \
     43             --add-flags "-I $out/libexec/htbbox.py" \
     44             --prefix PATH : ${lib.makeBinPath [ pkgs.gum ]}
     45           install -Dm0644 ${./_completions/_htbbox} $out/share/zsh/site-functions/_htbbox
     46         '';
     47     in
     48     {
     49       config = lib.mkIf on {
     50         environment.systemPackages = [ htbbox ];
     51       };
     52     };
     53 }