misc · October 19, 2025 · 4 min read
The Security Workstation
Kali broken in 30 seconds, rebuilt in 10 minutes
The code is on GitHub: rh33t/secmachine-build.
I was working on privilege escalation techniques in my VM when I typed tee /etc/passwd instead of something else. I hit Enter. The system froze. No more boot.
My files were still on disk, but without a working /etc/passwd, there was no way to access anything. I restarted the Kali installer and mentally started counting everything I’d have to redo: Ghidra with my custom settings, Neovim and its plugins, Tmux, my folder structure, my scripts, and probably fifty other small things. Three to four hours of work to get back to a functional environment.
That’s when I realized I was doing this completely backwards.
The Real Problem
Reinstalling by hand is wasted time every single time. And it happens more often than you’d think: failed snapshot, forgotten snapshot, an update that breaks a tool, a corrupted VM, or just a mistyped command like mine. On top of that, during a reinstall you also lose all the small customizations you’d added over time and never really documented.
The solution was to automate the environment and separate data from the system. The principle is simple: the VM is disposable, the work is not.
What the Playbook Does
I wrote Ansible playbooks that rebuild my entire setup from scratch. The structure is organized into roles, each handling one specific thing.
The system role handles the base config: timezone, French keyboard layout with Escape key swap, and passwordless sudo. The tools role installs the tools I actually use: Ghidra, GDB with pwntools and GEF, Binary Ninja, and everything that goes with them. The nvim and tmux roles configure my dev environment exactly the way I like it. The dotfiles role manages all my configuration files.
I also added support for Go tools like nuclei and httpx, disabled by default since I don’t always need them. The idea is to be able to enable or disable entire sections depending on the context: minimal cloud server, full workstation, or dedicated CTF machine.
To run everything:
git clone https://github.com/rh33t/secmachine-buildcd secmachine-buildmake setupTen minutes later, the environment is there.
The Tools That Save Time
Beyond security tools, it’s the custom utilities that keep me from repeating the same manual actions.
shelf is a TUI written in Go that I built to manage my CTF and box workspaces. Instead of creating folders by hand for every new challenge, I launch shelf and navigate through an interactive interface. I select the platform, category, and challenge name. Folders are created automatically and a tmux session opens directly in the right directory.
shelf # interactive modeshelf ctf # CTF mode directlyshelf box # box mode directlyThe generated structure follows a fixed convention:
~/work/training/challenges/<platform>/<category>/<challenge> # CTF~/work/training/boxes/<platform>/<box> # boxNo need to think about where to put files. I always know where to find last week’s work.
host-entry solves a problem every CTF player knows: managing /etc/hosts. Rather than editing the file by hand every time and risking breaking something, the script backs up the original, adds entries in a clearly delimited section, and makes cleanup easy once the challenge is done.
sudo host-entry add 10.10.10.10 deadcode.thm ctf.deadcode.thmsudo host-entry cleanThe Important Part: Separating the Environment from the Work
This is the real change. My work directory is mounted from the host into the VM. Notes, scripts, in-progress exploits, reports: all of that lives on the host. The VM only contains the environment.
When I create a new machine, I mount that folder, run make setup, and everything is there: notes from previous challenges, scripts, ongoing projects. The VM can be deleted, corrupted, or rebuilt. The work doesn’t disappear with it.
Day to Day
Here’s how it actually works. I boot a fresh VM, clone the repo, run make setup, and go do something else. Ten minutes later, the environment is up: terminal, tools, custom scripts, everything.
A new HTB machine drops. I run shelf box, navigate the interface, select the platform and enter the name. A tmux session opens directly in the right directory, already organized. I don’t have to think about where to put files.
At the end of a session, I shut down the VM. The next day, even if I need to rebuild, I remount the work folder, run make setup, and I’m back at the same point in a few minutes.
The full setup is on GitHub, and shelf is available separately here. What that stupid /etc/passwd mistake taught me is simple: spend the time to document your environment once, and you never pay for it by hand ten times over.