Repository navigation
Home
Bull is a Bash toolkit that creates, manages, and hardens pentest virtual machines (Kali Linux and Parrot Security) on top of Vagrant and a hypervisor (libvirt/KVM or VirtualBox). It gives you a disposable, reproducible attack box in a single command, with a VPN kill switch, encrypted storage, GPG-protected credentials, snapshots, and a reusable toolkit manager.
This wiki is the complete manual. For a quick overview, see the README.
- Installation — set up the host, choose a provider, run on WSL2
- Usage Guide — create, manage, connect to, and destroy VMs
- CLI Reference — every command, alias, flag, and environment variable
- VPN and Kill Switch — lock all traffic to the tunnel
- Toolkit Manager — save your tools once, deploy them on every VM
- How It Works — the full lifecycle at the level of functions, files, and artifacts
- Architecture — how Bull is structured and why
- Security Model — what Bull protects, and what it does not
- Troubleshooting — common errors and how to fix them
When you run bull create my-vm --os kali, Bull will:
- Detect your hypervisor (KVM if
/dev/kvmexists, otherwise VirtualBox). - Generate a Vagrantfile from a template with provider-specific tuning.
- Boot a Kali or Parrot box and provision it as root.
- Create your user, encrypt
/homewith ecryptfs, and lock the default OS accounts. - Encrypt the VM password with GPG (AES256 + SHA512, 65M iterations) and store it outside the VM.
- Optionally install your saved toolkits.
- Record the VM in a local JSON inventory.
The result is a hardened, reproducible machine you can snapshot, route through a VPN with a kill switch, and destroy when you are done.
| Component | Requirement |
|---|---|
| Host OS | Linux (native or WSL2) |
| Hypervisor | libvirt/KVM or VirtualBox |
| Vagrant | 2.3+ |
| Tools |
jq, gpg, ssh, sudo, openssl
|
See Installation for the full setup.
Bull · MIT License · Technical hardening only — see the Security Model.
Getting started
Features
Internals
Help