Skip to content
Melvin PETIT edited this page Jun 17, 2026 · 3 revisions

Bull Wiki

Bull is a Bash toolkit that creates, manages, and hardens pentest virtual machines (Kali Linux and Parrot Security) on top of Vagrant and a hypervisor (libvirt/KVM or VirtualBox). It gives you a disposable, reproducible attack box in a single command, with a VPN kill switch, encrypted storage, GPG-protected credentials, snapshots, and a reusable toolkit manager.

This wiki is the complete manual. For a quick overview, see the README.

Start here

  • Installation — set up the host, choose a provider, run on WSL2
  • Usage Guide — create, manage, connect to, and destroy VMs
  • CLI Reference — every command, alias, flag, and environment variable

Going deeper

What Bull does in one command

When you run bull create my-vm --os kali, Bull will:

  1. Detect your hypervisor (KVM if /dev/kvm exists, otherwise VirtualBox).
  2. Generate a Vagrantfile from a template with provider-specific tuning.
  3. Boot a Kali or Parrot box and provision it as root.
  4. Create your user, encrypt /home with ecryptfs, and lock the default OS accounts.
  5. Encrypt the VM password with GPG (AES256 + SHA512, 65M iterations) and store it outside the VM.
  6. Optionally install your saved toolkits.
  7. Record the VM in a local JSON inventory.

The result is a hardened, reproducible machine you can snapshot, route through a VPN with a kill switch, and destroy when you are done.

Requirements at a glance

Component Requirement
Host OS Linux (native or WSL2)
Hypervisor libvirt/KVM or VirtualBox
Vagrant 2.3+
Tools jq, gpg, ssh, sudo, openssl

See Installation for the full setup.

Clone this wiki locally