Cyber security

Vulpes/VulpOS : The Docker-Powered All-in-One Workstation For Penetration Testing And Offsec Labs

All in one Docker-based workstation with hacking tools for Pentesting and offsec Labs by maintained by @Fenrir.pro.

It is based on Alpine Linux, clutter-free, lightweight and actively used for penetration testing assessments, local training sessions, workshops and online classes on hack.courses.

Why?

We deploy on-demain online workstations and needed a hacking-oriented operating system with a small CPU/RAM/storage footprint (smaller than kali and ubuntu at least which took sometimes 20~30 minutes to setup).

Also, being able to deploy a new Linux hacking machine on a Windows workstation in less than 20 seconds is definitely enjoyable.

So here’s Vulpes (also VulpOS, still unsure about the name)!

Quick Setup

You’re On Windows?

PS> docker-compose -f docker-compose-win-novnc.yml up

You’re On A UNIX-Like System?

$> docker-compose -f docker-compose-unix-novnc.yml up

Once your build is done (which takes usually around 10 to 20 seconds) you can enjoy Vulpes in your browser locally on :

Or if you deployed vulpes on a server/remote machine :

http://YOUR_SERVER_IP:8080/?path=YOUR_SERVER_IP:6080

IMPORTANT : This default docker-compose configuration exposes three ports on your machine’s 0.0.0.0 : 8000 (noVNC web interface), 6080 (websockify) and 5900 (VNC).

Make sure you trust machines on your local network if you keep this default configuration and change the default VNC password that is CHANGEME in the docker-compose-win-novnc.yml file.

I repeat : those three services are exposed on your machine’s network interfaces by default!

Screenshots

Current Goals

Default Toolset

  • Wireshark
  • nmap
  • radare2
  • netcat
  • socat
  • john the ripper
Varshini

Tamil has a great interest in the fields of Cyber Security, OSINT, and CTF projects. Currently, he is deeply involved in researching and publishing various security tools with Kali Linux Tutorials, which is quite fascinating.

Recent Posts

Kali Linux 2024.4 Released, What’s New?

Kali Linux 2024.4, the final release of 2024, brings a wide range of updates and…

1 day ago

Lifetime-Amsi-EtwPatch : Disabling PowerShell’s AMSI And ETW Protections

This Go program applies a lifetime patch to PowerShell to disable ETW (Event Tracing for…

1 day ago

GPOHunter – Active Directory Group Policy Security Analyzer

GPOHunter is a comprehensive tool designed to analyze and identify security misconfigurations in Active Directory…

3 days ago

2024 MITRE ATT&CK Evaluation Results – Cynet Became a Leader With 100% Detection & Protection

Across small-to-medium enterprises (SMEs) and managed service providers (MSPs), the top priority for cybersecurity leaders…

6 days ago

SecHub : Streamlining Security Across Software Development Lifecycles

The free and open-source security platform SecHub, provides a central API to test software with…

1 week ago

Hawker : The Comprehensive OSINT Toolkit For Cybersecurity Professionals

Don't worry if there are any bugs in the tool, we will try to fix…

1 week ago