Cyber security

Vulpes/VulpOS : The Docker-Powered All-in-One Workstation For Penetration Testing And Offsec Labs

All in one Docker-based workstation with hacking tools for Pentesting and offsec Labs by maintained by @Fenrir.pro.

It is based on Alpine Linux, clutter-free, lightweight and actively used for penetration testing assessments, local training sessions, workshops and online classes on hack.courses.

Why?

We deploy on-demain online workstations and needed a hacking-oriented operating system with a small CPU/RAM/storage footprint (smaller than kali and ubuntu at least which took sometimes 20~30 minutes to setup).

Also, being able to deploy a new Linux hacking machine on a Windows workstation in less than 20 seconds is definitely enjoyable.

So here’s Vulpes (also VulpOS, still unsure about the name)!

Quick Setup

You’re On Windows?

PS> docker-compose -f docker-compose-win-novnc.yml up

You’re On A UNIX-Like System?

$> docker-compose -f docker-compose-unix-novnc.yml up

Once your build is done (which takes usually around 10 to 20 seconds) you can enjoy Vulpes in your browser locally on :

Or if you deployed vulpes on a server/remote machine :

http://YOUR_SERVER_IP:8080/?path=YOUR_SERVER_IP:6080

IMPORTANT : This default docker-compose configuration exposes three ports on your machine’s 0.0.0.0 : 8000 (noVNC web interface), 6080 (websockify) and 5900 (VNC).

Make sure you trust machines on your local network if you keep this default configuration and change the default VNC password that is CHANGEME in the docker-compose-win-novnc.yml file.

I repeat : those three services are exposed on your machine’s network interfaces by default!

Screenshots

Current Goals

Default Toolset

  • Wireshark
  • nmap
  • radare2
  • netcat
  • socat
  • john the ripper
Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

Playwright-MCP : A Powerful Tool For Browser Automation

Playwright-MCP (Model Context Protocol) is a cutting-edge tool designed to bridge the gap between AI…

3 weeks ago

JBDev : A Tool For Jailbreak And TrollStore Development

JBDev is a specialized development tool designed to streamline the creation and debugging of jailbreak…

3 weeks ago

Kereva LLM Code Scanner : A Revolutionary Tool For Python Applications Using LLMs

The Kereva LLM Code Scanner is an innovative static analysis tool tailored for Python applications…

3 weeks ago

Nuclei-Templates-Labs : A Hands-On Security Testing Playground

Nuclei-Templates-Labs is a dynamic and comprehensive repository designed for security researchers, learners, and organizations to…

3 weeks ago

SSH-Stealer : The Stealthy Threat Of Advanced Credential Theft

SSH-Stealer and RunAs-Stealer are malicious tools designed to stealthily harvest SSH credentials, enabling attackers to…

3 weeks ago

ollvm-unflattener : A Tool For Reversing Control Flow Flattening In OLLVM

Control flow flattening is a common obfuscation technique used by OLLVM (Obfuscator-LLVM) to transform executable…

3 weeks ago