NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

recon.nix (888B)


      1 # modules/features/pentest/recon.nix — finding hosts, ports and names.
      2 { lib, ... }:
      3 (import ./_sets.nix { inherit lib; }) {
      4   name = "recon";
      5   description = "port, service, host and DNS enumeration";
      6 
      7   packages = pkgs: with pkgs; [
      8     nmap masscan rustscan naabu fscan
      9     nbtscan enum4linux-ng snmpcheck onesixtyone thc-ipv6
     10     dnsrecon subfinder amass dnsx
     11     httpx katana gowitness eyewitness whatweb
     12     net-snmp # snmpwalk, snmpget: onesixtyone finds the community, this reads it
     13     sslscan testssl # `testssl.sh`
     14     arp-scan netdiscover # layer 2, once you are inside a subnet
     15   ];
     16 
     17   expectedBins = [
     18     "nmap" "masscan" "rustscan" "naabu" "fscan"
     19     "nbtscan" "enum4linux-ng" "snmp-check" "onesixtyone"
     20     "dnsrecon" "subfinder" "amass" "dnsx"
     21     "httpx" "katana" "gowitness" "whatweb"
     22     "snmpwalk" "snmpget" "sslscan" "testssl.sh" "arp-scan" "netdiscover"
     23   ];
     24 }