Nevalyx: A high‑performance, x86‑64‑v3 optimized pentesting container built on CachyOS
2.0K
A container with pentesting tools compiled from source with -march=x86-64-v3 and Full/Fat LTO. Built for my own use and shared in case others find it helpful.
Caution
This image requires **x86-64-v3** (AVX2 + BMI2 + FMA). That's Intel Haswell (2013) or AMD Excavator (2015) and newer. Older CPUs will hit illegal instruction crashes. No fallback.
Check:
grep -o 'avx2\|bmi2\|fma' /proc/cpuinfo | sort -u
All three must show up. If not, stop here.
Pull the image directly from Docker Hub:
podman pull docker.io/enfilade0x/nevalyx:latest
Distrobox handles home directory mounting, X11/Wayland GUI forwarding, and audio automatically.
export DBX_CONTAINER_MANAGER=podman
distrobox create \
--name nevalyx \
--image docker.io/enfilade0x/nevalyx:latest \
--nvidia \ # (Optional: Include if using an NVIDIA GPU for Hashcat)
--additional-flags "--cap-add=NET_RAW --cap-add=NET_ADMIN --network=host"
distrobox enter nevalyx
If you prefer pure Podman without Distrobox's host integration:
# Create and enter the container for the first time
podman run -it --name nevalyx \
--cap-add=NET_RAW --cap-add=NET_ADMIN \
--network=host \
--device nvidia.com/gpu=all \ # (Optional: For NVIDIA GPU passthrough)
-v /tmp/.X11-unix:/tmp/.X11-unix:ro -e DISPLAY=$DISPLAY \ # (Optional: For GUI tools)
docker.io/enfilade0x/nevalyx:latest
# To re-enter it later (keeps your shell history and updates):
podman start -ai nevalyx
Warning
**Docker is highly discouraged.** While this is a fully compliant image and `docker run` will work perfectly fine, running a root-level daemon listening on a local socket 24/7 is terrible OPSEC for a pentesting environment. Please use Podman.
For contributions, tool requests, or to build the image locally, please visit the GitHub Repository.
Content type
Image
Digest
sha256:33ab5234b…
Size
11.5 GB
Last updated
3 months ago
docker pull enfilade0x/nevalyx