NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

default.nix (3117B)


      1 # modules/features/pentest/default.nix — the toolkit as one NixOS module
      2 # (self.nixosModules.pentest), assembled from the named modules it imports.
      3 #
      4 # The host imports this one name, so adding a category means editing this file
      5 # and nothing else — the same arrangement as modules/home/default.nix.
      6 #
      7 #   daemon.pentest.enable             the master switch
      8 #   daemon.pentest.<category>.enable  per category, declared by the category
      9 #                                     itself (_sets.nix)
     10 #
     11 # Default-on categories are the ones CPTS exercises; DFIR, reversing, wireless,
     12 # cloud, OSINT and mobile ship switched off (see each file's `default`).
     13 { self, ... }:
     14 {
     15   flake.nixosModules.pentest =
     16     { ... }:
     17     {
     18       imports = with self.nixosModules; [
     19         pentest-nixpkgs # the overlay the toolkit needs (see _overlay.nix)
     20         pentest-options # the master switch and the options no category owns
     21         pentest-core # ncat, socat, smbclient, kerberos, ldap; $PAYLOADS/$WORDLISTS
     22         pentest-wordlists # seclists, rockyou, searchsploit → $WORDLISTS
     23         pentest-python # one offensive python env; impacket by name
     24         pentest-recon # port, service, host and DNS enumeration
     25         pentest-ad # kerberos, LDAP, SMB, ADCS, relaying
     26         pentest-web # fuzzing, injection, scanners, proxies
     27         pentest-pivot # tunnelling and port forwarding; proxychains config
     28         pentest-crack # hashcat, john, hydra and friends
     29         pentest-shells # payloads, listeners, RDP, file transfer
     30         pentest-bloodhound # BloodHound CE + neo4j + postgresql (manual start)
     31         pentest-vpn # htbvpn: the HTB tunnel as a systemd template unit
     32         pentest-time # htb-time: conflict-aware clock skew for Kerberos
     33         pentest-htb # htbtarget/htbtime: the box you are on
     34         pentest-boxes # htbbox: the per-box tree and its writeup.md
     35         pentest-casts # htbcast: terminal recordings as raw write-up material
     36         pentest-helpers # revshell, htbscan, hcmode (from IceBreaker)
     37         pentest-payloads # the arsenal tree and payload-serve (multi-arch, cross-built)
     38         pentest-paths # ~/pentesting, the $privesc/$potatoes/$ligolo… vars, htbpaths
     39         pentest-update # pentest-update: move the _pkgs pins forward
     40         pentest-gui # burp, zap, ghidra, wireshark (desktop entries)
     41 
     42         # Off by default; one line each in configuration.nix to enable.
     43         pentest-dfir # memory, disk, log and artefact forensics
     44         pentest-reversing # disassembly, decompilation, exploit dev
     45         pentest-wireless # wifi attacks, rogue APs, packet capture
     46         pentest-radio # SDR, bluetooth, RFID/NFC (separate hardware)
     47         pentest-hardware # firmware flashing, UART/JTAG, logic, CAN
     48         pentest-c2 # havoc, villain (metasploit is in shells)
     49         pentest-database # mysql, postgres, mssql, redis, mongo clients
     50         pentest-cloud # AWS, Azure, GCP, Kubernetes
     51         pentest-osint # public-source collection
     52         pentest-social # phishing infrastructure; authorised scope only
     53         pentest-mobile # Android application testing
     54       ];
     55     };
     56 }