NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

core.nix (1908B)


      1 # modules/features/pentest/core.nix — what every category assumes: the
      2 # primitives for talking to a target and the two paths the rest of the toolkit
      3 # hangs off.
      4 #
      5 # On whenever any category is on, so $PAYLOADS and $WORDLISTS always resolve.
      6 # Their values here are placeholders; wordlists.nix and payloads.nix override
      7 # them with lib.mkForce.
      8 #
      9 # `ncat` is not a top-level attribute — it ships inside nmap, which is why nmap
     10 # appears here as well as in recon.nix (Nix dedupes the closure).
     11 { lib, ... }:
     12 (import ./_sets.nix { inherit lib; }) {
     13   name = "core";
     14   description = "pentest primitives: ncat, socat, smbclient, kerberos, ldap";
     15 
     16   packages = pkgs: [
     17     pkgs.nmap # ncat: the reverse-shell workhorse (--ssl, -e)
     18     pkgs.socat
     19     pkgs.samba # smbclient, net
     20     pkgs.krb5 # kinit, klist — CPTS AD boxes live on these
     21     pkgs.openldap # ldapsearch
     22     pkgs.sshpass
     23     pkgs.rlwrap # line editing in a dumb reverse shell
     24     pkgs.jq
     25     # The dotfiles' engagement database (~/.dotfiles/config/database.zsh:
     26     # `htb-list`, `htb-newbox`, `creds`, `findings`, `flags`, `note`) shells
     27     # out to sqlite3 nineteen times and to `column` from util-linux. Without
     28     # sqlite3 every one of those fails with "_pdb_init: command not found".
     29     pkgs.sqlite
     30     pkgs.dnsutils # dig, nslookup
     31     pkgs.iputils
     32     pkgs.util-linux
     33   ];
     34 
     35   expectedBins = [
     36     "ncat"
     37     "socat"
     38     "smbclient"
     39     "kinit"
     40     "ldapsearch"
     41     "sshpass"
     42     "rlwrap"
     43     "dig"
     44     "sqlite3"
     45     "column" # util-linux; the dotfiles' DB views need it
     46   ];
     47 
     48   extraConfig = { lib, ... }: {
     49     # Placeholders: wordlists.nix (Task 2) and payloads.nix (Task 12) take these
     50     # over with lib.mkForce.
     51     environment.sessionVariables = {
     52       PAYLOADS = lib.mkDefault "/run/current-system/sw/share/pentest/payloads";
     53       WORDLISTS = lib.mkDefault "/run/current-system/sw/share/pentest/wordlists";
     54     };
     55   };
     56 }