PWNBOX
NixOS for hacking,
reversing, AD
and networking
A ready-to-go NixOS + home-manager box. Reproducible, portable and built for privacy: nothing is downloaded at runtime, nothing is written to disk that does not need to be, and every colour on screen comes from the wallpaper.
$ ./install.sh switch
On the box it is ALT S. Here, 1 to 8 previews a palette, Space cycles.
The box
One palette, every app
Pywal reads 16 colours out of the wallpaper. Templates turn them into each app's format. Three apps refresh while they are running: no quit, no CTRL R.
wallpaper
pywal · 16 colours
quickCss.css and hot-applies it. Server list folded into folders, system font everywhere.
Or pin it
A custom theme is a folder with a theme.conf and a wallpaper. Fixed palette, fixed image. Only name, background and foreground are required; everything else falls back to Monochrome.
dotfiles/themes/My-theme/theme.conf
name = My theme
wallpaper = wallpaper.png
background = #101014
foreground = #e6e6e6
Rebuild with upd, then ALT S → Custom. The thumbnail card is the wallpaper with the theme name below it.
Toolset
26 pentest categories, all enabled by default, each one a Nix option. Turn any of them off with a single line in hosts/<host>/default.nix.
nix pwnbox.packages.toolset.<category>.enable = false;
Daily driver
Zero trace
No logs. journald is volatile, /var/log is a RAM disk.
No swap partition. zram only, so nothing in memory ever touches a disk.
RAM-backed /tmp and /var/tmp. No hibernation. No core dumps.
Hardened kernel, strict sysctls, AppArmor, locked modules. sudo-rs, wheel only, root locked.
No SSH, no Avahi, no printing, no geolocation. Firewall on.
Shell history goes to /dev/null.
Installed by default
Signal · SimpleX · Element · Dino · qTox · AyuGram · Tor Browser · Mullvad VPN · tor + torsocks · KeePassXC
Keys
ALT for apps and workspaces, SUPER for windows. The full list is in the docs.
Install
One command on an existing NixOS machine.
The installer detects your user, host name, time zone and hardware, creates hosts/<host>/ from the template, then runs nixos-rebuild with the flake. Boot an older generation from the boot menu if a build ever breaks.
$ ./install.sh switch
updrebuild and activateupdateupdate all flake inputs, then rebuild./install.sh testactivate for this boot only./install.sh buildbuild, do not activateGrab the files
The whole flake as a zip. Unzip it, cd pwnbox, run ./install.sh switch on any NixOS machine and you land on this desktop.
pwnbox-flake-lite.zip
Everything needed to build the box. The wallpaper library is left out: bring your own images, the four custom themes keep theirs.
- flake.nix, hosts, modules
- 26 tool categories
- every dotfile: hypr, kitty, rofi, nvim, zed, ranger
- Quickshell bar, 10 styles
- pwnbox-theme engine + pywal templates
- 4 custom themes with wallpapers
pwnbox-flake.zip
The same flake plus the full wallpaper library, so ALT S → Pywal has fifty images to pick from on day one.
- everything in lite
- the wallpaper library,
dotfiles/gnome/wallpapers/
verify$ curl -LO https://pwnbox.one/download/pwnbox-flake-lite.zip $ curl -LO https://pwnbox.one/download/pwnbox-flake-lite.zip.sha256 $ sha256sum -c pwnbox-flake-lite.zip.sha256
- lite
df185c0b14861cf2741ef3cb90f5c9a42b7e53b4fd43a4ca74023510b515023a- full
5746d0d2f6dd8e15e940b64268ea6df4863dfec143a3e898fc1036a2f3980e37
Berkeley Mono is a paid font and is not in either archive. The box falls back to the next monospace in the list until you drop your own copy into dotfiles/gnome/fonts/.
Documentation
The manual.
Getting started, desktop, keybinds, themes, fonts, apps, packages, privacy, architecture, troubleshooting, development. Eleven pages, every option and every file path.