NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

gui.nix (1936B)


      1 # modules/features/pentest/gui.nix — the windowed tools, with desktop entries
      2 # so they appear in the launcher the way Kali's menu does.
      3 #
      4 # Kept separate from the headless categories: enabling `web` should not drag in
      5 # a JDK, and a remote session should be able to skip this entirely.
      6 #
      7 # programs.wireshark is set here at mkDefault (1000) and in wireless.nix at a
      8 # weaker 1500, so this one wins when both categories are on and either alone
      9 # still gets the dumpcap capability wrapper. They may NOT both be mkDefault:
     10 # types.package merges with mergeEqualOption, and `==` on two derivations is
     11 # false even for one store path, so equal priorities are a hard conflict.
     12 # See the longer note in wireless.nix.
     13 { lib, ... }:
     14 (import ./_sets.nix { inherit lib; }) {
     15   name = "gui";
     16   description = "burp, zap, ghidra, wireshark, autopsy and other windowed tools";
     17 
     18   packages = pkgs: with pkgs; [
     19     burpsuite # unfree; allowed by nixpkgs.nix and by the host
     20     zap
     21     ghidra
     22     cutter
     23     autopsy
     24     sqlitebrowser
     25     wireshark
     26   ];
     27 
     28   expectedBins = [
     29     "burpsuite" "zap" "ghidra" "cutter" "autopsy" "sqlitebrowser" "wireshark"
     30   ];
     31 
     32   # Every tool above must actually ship a .desktop file, or it will not appear
     33   # in the launcher and the point of this category is lost.
     34   checkScript = { pkgs, lib }: ''
     35     for p in ${pkgs.burpsuite} ${pkgs.zap} ${pkgs.ghidra} ${pkgs.cutter} ${pkgs.wireshark} ${pkgs.sqlitebrowser}; do
     36       if ! ls "$p"/share/applications/*.desktop >/dev/null 2>&1; then
     37         echo "pentest-gui: $p ships no share/applications/*.desktop entry" >&2
     38         exit 1
     39       fi
     40     done
     41   '';
     42 
     43   extraConfig = { pkgs, lib, ... }: {
     44     # The package alone cannot capture: this creates the `wireshark` group and
     45     # the setcap dumpcap wrapper. Without it you need full root to sniff.
     46     programs.wireshark = {
     47       enable = lib.mkDefault true;
     48       package = lib.mkDefault pkgs.wireshark;
     49     };
     50   };
     51 }