NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

_settings.nix (3817B)


      1 # modules/hosts/generic/_settings.nix — THE file to edit when you install
      2 # NixDaemon on your own machine. Everything machine-specific about the generic
      3 # host is here; nothing else in the repo needs to change.
      4 #
      5 # After editing:
      6 #   sudo nixos-rebuild switch --flake .#nixdaemon      (or: nh os switch -H nixdaemon)
      7 #
      8 # See docs/install.md for the full walk-through (bare metal, VMware,
      9 # VirtualBox, QEMU/KVM, UTM on Apple Silicon, Hyper-V, an existing NixOS).
     10 {
     11   # Your login name. A home directory /home/<user> is created for it.
     12   user = "operator";
     13 
     14   # First-login password. CHANGE IT straight away with `passwd`, or set
     15   # `initialPassword = null;` and use `sudo passwd <user>` from the installer.
     16   initialPassword = "nixdaemon";
     17 
     18   hostName = "nixdaemon";
     19 
     20   # "x86_64-linux" for Intel/AMD, "aarch64-linux" for ARM (Apple Silicon VMs,
     21   # Raspberry Pi 4/5 with UEFI firmware, Ampere, Snapdragon).
     22   system = "x86_64-linux";
     23 
     24   timeZone = "UTC"; # `timedatectl list-timezones`, e.g. "Europe/London"
     25   locale = "en_US.UTF-8";
     26   keyboard = "us"; # X/Wayland layout: "gb", "de", "fr", …
     27 
     28   # How the machine boots. Look at the installer: if /sys/firmware/efi exists
     29   # it booted UEFI — use "efi". Otherwise "bios" and name the disk GRUB goes
     30   # on. VirtualBox defaults to BIOS unless "Enable EFI" is ticked.
     31   boot = "efi"; # "efi" | "bios"
     32   biosDevice = "/dev/sda"; # only read when boot = "bios"
     33 
     34   # Guest tools for the hypervisor you run in (clipboard, resolution, time).
     35   #   "none" | "vmware" | "virtualbox" | "qemu" (KVM, virt-manager, Proxmox, UTM) | "hyperv"
     36   vm = "none";
     37 
     38   # "niri"  Niri (scrolling Wayland compositor) + Noctalia shell, Rosé Pine.
     39   #         The default. Needs working 3D: bare metal, QEMU virtio-gpu with
     40   #         GL, VMware with 3D acceleration on. Super+Return opens a terminal.
     41   #
     42   # The two below are switched OFF until you choose one here. They are X11,
     43   # so they run in every VM (VirtualBox, Hyper-V, Proxmox, VMware without 3D):
     44   # "xfce"  XFCE in Rosé Pine: panel, menu, file manager — a full desktop.
     45   # "i3"    i3 tiling window manager in Rosé Pine: the lightweight one (a
     46   #         whole i3 VM idles around 0.9 GB). Super+Return terminal, Super+d menu.
     47   # They are newer than the Niri desktop and less tested: expect the odd rough
     48   # edge (theming in some apps, resize in some hypervisors). Report what breaks.
     49   #
     50   # "none"  no desktop: console + SSH only.
     51   desktop = "niri";
     52 
     53   # Host folders shared into the VM. VMware: mounted at /mnt/hgfs/<name>.
     54   # VirtualBox: your user joins vboxsf and shares appear at /media/sf_<name>.
     55   # Turn the sharing on in the hypervisor's VM settings as well.
     56   sharedFolders = false;
     57 
     58   # Accept SSH logins (password auth stays off; put your public key below).
     59   ssh = false;
     60   sshKeys = [ ]; # [ "ssh-ed25519 AAAA… you@laptop" ]
     61 
     62   # The offensive toolkit. The CPTS core (recon, AD, web, pivot, crack,
     63   # shells, BloodHound, payloads, wordlists, GUI tools) is on by default;
     64   # these extra categories are off. Flip any to true. (On aarch64 BloodHound
     65   # is switched off automatically: its pinned neo4j is x86_64-only.)
     66   pentest = {
     67     dfir = false; # volatility, sleuthkit, yara, stego
     68     reversing = false; # radare2, rizin, gdb+gef, pwntools, ROPgadget
     69     wireless = false; # aircrack-ng, wifite, kismet (needs a monitor-mode card)
     70     radio = false; # SDR, bluetooth, RFID (needs the hardware)
     71     hardware = false; # flashrom, openocd, sigrok, can-utils
     72     c2 = false; # havoc, villain
     73     database = false; # mysql, mssql, redis, mongo clients
     74     cloud = false; # aws, az, gcloud, kubectl, pacu
     75     osint = false; # theharvester, recon-ng, sn0int
     76     social = false; # gophish, setoolkit — authorised scope only
     77     mobile = false; # apktool, jadx, frida, adb (x86_64 only)
     78   };
     79 }