NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

helpers.nix (1957B)


      1 # modules/features/pentest/helpers.nix — the small daily-use commands, taken
      2 # from IceBreaker (~/Downloads/IceBreaker-main.zip, scripts/ and home/zsh.nix)
      3 # and rewired to this toolkit's state instead of IceBreaker's ~/targets tree.
      4 #
      5 #   revshell [type] [port]   reverse shell one-liners; LHOST from htbip
      6 #   htbscan [full|udp|ports] nmap passes into $BOXDIR/recon, then htbbox ports
      7 #   hcmode [word|number]     hashcat -m lookup, read from the installed hashcat
      8 #
      9 # What was NOT taken, and why: newbox/flag/cred/settarget (htbbox and
     10 # htbtarget already do this, with box.json behind them), setproxy (it seds
     11 # proxychains.conf, which is generated by programs.proxychains in pivot.nix),
     12 # ligolo-fetch.sh (payloads.nix builds ligolo from source per arch),
     13 # install-pipx-tools.sh (python.nix pins the same tools declaratively),
     14 # tmux-htb.sh (~/.dotfiles/scripts/htb-layout.sh) and icebreaker-bench (the
     15 # dissertation's benchmark harness, not a tool).
     16 #
     17 # The scripts live in _helpers/ as plain bash so shellcheck (which
     18 # writeShellApplication runs at build time) sees them unescaped. htbip,
     19 # htbbox and sudo are deliberately NOT runtimeInputs: they come from the
     20 # system (vpn.nix, boxes.nix, the setuid wrapper), and a store copy of htbbox
     21 # would read a different $STATE than the one on PATH.
     22 { lib, ... }:
     23 {
     24   flake.nixosModules.pentest-helpers =
     25     { config, pkgs, lib, ... }:
     26     let
     27       on = config.daemon.pentest.enable;
     28 
     29       mk = name: runtimeInputs:
     30         pkgs.writeShellApplication {
     31           inherit name runtimeInputs;
     32           text = builtins.readFile ./_helpers/${name}.sh;
     33         };
     34 
     35       helpers = [
     36         (mk "revshell" (with pkgs; [ coreutils jq gum wl-clipboard glibc.bin ]))
     37         (mk "htbscan" (with pkgs; [ coreutils gnugrep nmap ]))
     38         (mk "hcmode" (with pkgs; [ gnugrep gawk hashcat ]))
     39       ];
     40     in
     41     {
     42       config = lib.mkIf on {
     43         environment.systemPackages = helpers;
     44       };
     45     };
     46 }