pwnbox A hardened NixOS box for hacking. Declared once, themed by the wallpaper.

PWNBOX

NixOS for hacking,
reversing, AD
and networking

A ready-to-go NixOS + home-manager box. Reproducible, portable and built for privacy: nothing is downloaded at runtime, nothing is written to disk that does not need to be, and every colour on screen comes from the wallpaper.

tool categories26
bar styles10
sessionsHyprland · GNOME
logs on disk0
$ ./install.sh switch

On the box it is ALT S. Here, 1 to 8 previews a palette, Space cycles.

by ×

The box

pwnbox at work: Neovim solve script, gdb disassembly, kitty
at work Neovim on the left, gdb on the right, kitty underneath. Berkeley Mono at 9, Manrope for the bar. The palette is pywal's read of a sand-coloured wallpaper.
pwnbox, Monochrome theme
monochrome The built-in default before any wallpaper is picked. No colour, so the layout has to carry itself.
pwnbox, crimson palette
crimson Same checksec, same gef session. Red petals behind the panes, red registers inside them.
pwnbox, neon pink palette
neon The loud one. Pywal pulls the pink out of the grid and hands it to kitty, rofi, the bar and gef in one pass.
pwnbox, frost palette
frost Cold blue on navy. The Hyprland border colour is generated from the same 16 colours.
pwnbox, ember palette
ember Amber on charcoal. Blur, transparency and corner radius are all set from the same menu.
pwnbox, dune palette
dune Sand and sepia, the quiet daytime palette.
pwnbox, street palette
street A side street at dusk. Teal-black behind the panes, the bar as islands on top.

Ten bars

The bar, notifications, calendar, power menu and OSD are Quickshell. ALT S → Style switches the layout live; each style's geometry is defined once in BarStyles.js so the calendar always opens against the real bar, even the bottom dock.

Sun 04 Oct 21:15
cpu 21%mem 18%net 301Kvol 40%

One palette, every app

Pywal reads 16 colours out of the wallpaper. Templates turn them into each app's format. Three apps refresh while they are running: no quit, no CTRL R.

wallpaper

pywal · 16 colours

Discord (Equibop) themed by pwnbox
discord · live Equibop watches quickCss.css and hot-applies it. Server list folded into folders, system font everywhere.
Spotify themed by pwnbox through Spicetify
spotify · live Spicetify on a writable copy of the store package. Inputs, menus, modals and buttons themed, artwork gradients flattened, every scrollbar removed.

Or pin it

A custom theme is a folder with a theme.conf and a wallpaper. Fixed palette, fixed image. Only name, background and foreground are required; everything else falls back to Monochrome.

dotfiles/themes/My-theme/theme.conf
name = My theme
wallpaper = wallpaper.png

background = #101014
foreground = #e6e6e6

Rebuild with upd, then ALT S → Custom. The thumbnail card is the wallpaper with the theme name below it.

Toolset

26 pentest categories, all enabled by default, each one a Nix option. Turn any of them off with a single line in hosts/<host>/default.nix.

nix pwnbox.packages.toolset.<category>.enable = false;

Daily driver

Zero trace

No logs. journald is volatile, /var/log is a RAM disk.

No swap partition. zram only, so nothing in memory ever touches a disk.

RAM-backed /tmp and /var/tmp. No hibernation. No core dumps.

Hardened kernel, strict sysctls, AppArmor, locked modules. sudo-rs, wheel only, root locked.

No SSH, no Avahi, no printing, no geolocation. Firewall on.

Shell history goes to /dev/null.

Installed by default

Signal · SimpleX · Element · Dino · qTox · AyuGram · Tor Browser · Mullvad VPN · tor + torsocks · KeePassXC

Keys

ALT for apps and workspaces, SUPER for windows. The full list is in the docs.

Install

One command on an existing NixOS machine.

The installer detects your user, host name, time zone and hardware, creates hosts/<host>/ from the template, then runs nixos-rebuild with the flake. Boot an older generation from the boot menu if a build ever breaks.

$ ./install.sh switch
updrebuild and activate
updateupdate all flake inputs, then rebuild
./install.sh testactivate for this boot only
./install.sh buildbuild, do not activate

Grab the files

The whole flake as a zip. Unzip it, cd pwnbox, run ./install.sh switch on any NixOS machine and you land on this desktop.

lite30MB

pwnbox-flake-lite.zip

Everything needed to build the box. The wallpaper library is left out: bring your own images, the four custom themes keep theirs.

  • flake.nix, hosts, modules
  • 26 tool categories
  • every dotfile: hypr, kitty, rofi, nvim, zed, ranger
  • Quickshell bar, 10 styles
  • pwnbox-theme engine + pywal templates
  • 4 custom themes with wallpapers
225 filesdownload
full273MB

pwnbox-flake.zip

The same flake plus the full wallpaper library, so ALT S → Pywal has fifty images to pick from on day one.

  • everything in lite
  • the wallpaper library, dotfiles/gnome/wallpapers/
275 filesdownload
verify$ curl -LO https://pwnbox.one/download/pwnbox-flake-lite.zip
$ curl -LO https://pwnbox.one/download/pwnbox-flake-lite.zip.sha256
$ sha256sum -c pwnbox-flake-lite.zip.sha256
lite
df185c0b14861cf2741ef3cb90f5c9a42b7e53b4fd43a4ca74023510b515023a
full
5746d0d2f6dd8e15e940b64268ea6df4863dfec143a3e898fc1036a2f3980e37

Berkeley Mono is a paid font and is not in either archive. The box falls back to the next monospace in the list until you drop your own copy into dotfiles/gnome/fonts/.

Documentation

The manual.

Getting started, desktop, keybinds, themes, fonts, apps, packages, privacy, architecture, troubleshooting, development. Eleven pages, every option and every file path.

read the docs →