Sign inSign up

enfilade0x/nevalyx

By enfilade0x

•Updated 3 months ago

Nevalyx: A high‑performance, x86‑64‑v3 optimized pentesting container built on CachyOS

Image
Security
0

2.0K

enfilade0x/nevalyx repository overview


⁠What is this?

A container with pentesting tools compiled from source with -march=x86-64-v3 and Full/Fat LTO. Built for my own use and shared in case others find it helpful.

  • Base: CachyOS (Arch derivative)
  • Runtime: Podman or Distrobox (With Podman as backend)
  • GitHub Repository: Enfilade0x/Nevalyx⁠ for the Dockerfile, issues, and full documentation.

⁠Before you start

Caution

This image requires **x86-64-v3** (AVX2 + BMI2 + FMA). That's Intel Haswell (2013) or AMD Excavator (2015) and newer. Older CPUs will hit illegal instruction crashes. No fallback.

Check:

grep -o 'avx2\|bmi2\|fma' /proc/cpuinfo | sort -u

All three must show up. If not, stop here.


⁠Usage

Pull the image directly from Docker Hub:

podman pull docker.io/enfilade0x/nevalyx:latest

Distrobox handles home directory mounting, X11/Wayland GUI forwarding, and audio automatically.

export DBX_CONTAINER_MANAGER=podman

distrobox create \
  --name nevalyx \
  --image docker.io/enfilade0x/nevalyx:latest \
  --nvidia \ # (Optional: Include if using an NVIDIA GPU for Hashcat)
  --additional-flags "--cap-add=NET_RAW --cap-add=NET_ADMIN --network=host"

distrobox enter nevalyx
⁠Podman (standalone)

If you prefer pure Podman without Distrobox's host integration:

# Create and enter the container for the first time
podman run -it --name nevalyx \
  --cap-add=NET_RAW --cap-add=NET_ADMIN \
  --network=host \
  --device nvidia.com/gpu=all \ # (Optional: For NVIDIA GPU passthrough)
  -v /tmp/.X11-unix:/tmp/.X11-unix:ro -e DISPLAY=$DISPLAY \ # (Optional: For GUI tools)
  docker.io/enfilade0x/nevalyx:latest

# To re-enter it later (keeps your shell history and updates):
podman start -ai nevalyx

Warning

**Docker is highly discouraged.** While this is a fully compliant image and `docker run` will work perfectly fine, running a root-level daemon listening on a local socket 24/7 is terrible OPSEC for a pentesting environment. Please use Podman.

For contributions, tool requests, or to build the image locally, please visit the GitHub Repository⁠.

Tag summary

Content type

Image

Digest

sha256:33ab5234b…

Size

11.5 GB

Last updated

3 months ago

docker pull enfilade0x/nevalyx