NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

osint.nix (2122B)


      1 # modules/features/pentest/osint.nix — open-source collection.
      2 # Off by default. `daemon.pentest.osint.enable = true;`
      3 #
      4 # Passive by intent: nothing here touches the target's infrastructure, it asks
      5 # third parties what they already know. That is also the caveat — most of these
      6 # want an API key to be useful (shodan, censys, hunter.io, haveibeenpwned), and
      7 # a key is a secret, so it belongs in secrets/secrets.yaml and not in a config
      8 # file here. `recon-ng`'s keystore and `sn0int`'s are per-user state.
      9 #
     10 # Active DNS and host enumeration is recon.nix, not this.
     11 { lib, ... }:
     12 (import ./_sets.nix { inherit lib; }) {
     13   name = "osint";
     14   description = "people, domain, account and metadata collection from public sources";
     15   default = false;
     16 
     17   packages = pkgs: with pkgs; [
     18     # Frameworks
     19     theharvester # `theHarvester`
     20     recon-ng # recon-ng, recon-cli
     21     sn0int # package-manager model, its own script registry
     22 
     23     # Accounts and people
     24     sherlock
     25     maigret
     26     holehe # which sites an email is registered on
     27     socialscan
     28     h8mail # breach-corpus lookups
     29 
     30     # Domains and names
     31     dnstwist # typosquats and homoglyphs of a domain
     32     fierce
     33 
     34     # What a target has already published
     35     assetfinder
     36     waybackurls # URLs the Wayback Machine has for a host
     37     gau # the same idea, more sources
     38     photon # crawler that keeps the interesting strings
     39 
     40     # Their code and their files
     41     gitleaks # secrets in a git history
     42     trufflehog # the same, plus verification of live keys
     43     exifprobe # exifprobe, exifgrep — metadata out of published documents
     44   ];
     45 
     46   expectedBins = [
     47     "theHarvester" "recon-ng" "recon-cli" "sn0int"
     48     "sherlock" "maigret" "holehe" "socialscan" "h8mail"
     49     "dnstwist" "fierce"
     50     "assetfinder" "waybackurls" "gau" "photon"
     51     "gitleaks" "trufflehog" "exifprobe" "exifgrep"
     52   ];
     53 
     54   # The python ones, actually run: a tool that installs and then dies on a
     55   # missing module passes `command -v` and fails you mid-engagement. This is
     56   # how `masky` was caught (see _overlay.nix).
     57   smokeBins = [ "dnstwist" "photon" "h8mail" "socialscan" "fierce" ];
     58 }