Pendora is a modular installation framework that transforms a standard Fedora Linux install into a penetration testing and security assessment VM — bringing Kali's toolset, workflows, and aesthetics to Fedora's modern Wayland, RPM/DNF, and systemd ecosystem.
$ git clone https://github.com/sec-moose/pendora && cd pendora && ./install.sh --basic▊// architecture
Tooling, services, and configuration are organized into dedicated tiers — each a plain list you can read, edit, and extend.
pkg-lists/
109 packages verified against official Fedora repos — base compilers, networking, sniffers, web discovery, reversing, and forensics.
pipx-lists/
Offensive Python utilities in isolated environments, safe from system library conflicts.
upstreams/
Vendor installers, git clones, and Docker containers for enterprise suites.
zsh/
Interactive Zsh with autosuggestions, syntax highlighting, completions, and pentesting aliases.
// install
All three modes are tested and verified on Fedora Workstation VMs. Installing Sway never removes GNOME — pick your session at the GDM login screen.
./install.sh --basic (-b)Keeps your default Fedora GNOME desktop intact while deploying all pentest CLI tools (00–60), Pipx tools, Docker container suites, Zsh, Neovim, and Alacritty. Zero desktop changes.
./install.sh --sway (-W)Lightweight Sway tiling compositor with the Noctalia shell, Hack Nerd Font, focus-based window opacity, and SPICE host/guest clipboard sharing. 100% native Fedora RPMs — zero COPR repos. Switch between GNOME and Sway at the login screen.
./install.sh --all (-a)Single-pass end-to-end deployment of everything in Basic plus the full Sway desktop stack (70-sway.list, dotfiles, screensharing portal services).
// preview
Keep Fedora's GNOME with --basic, or deploy the dynamic Sway tiling desktop with --sway — both tested and verified on QEMU/KVM.
// about
Pendora is a modular installation framework and configuration template that transforms a standard Fedora Linux installation into a penetration testing and security assessment virtual machine — bringing the toolset, workflows, and aesthetics of Kali Linux to Fedora's modern ecosystem (Wayland, RPM/DNF, systemd).
Everything is organized into four plain-text, human-editable tiers:
Native Fedora RPMs (pkg-lists/) — 109 packages verified against official Fedora repos: compilers, networking, sniffers, web discovery, reversing, and forensics.
Pipx-isolated Python tools (pipx-lists/) — netexec, impacket, certipy-ad, sqlmap, responder, and more, safe from system library conflicts.
Upstreams & containers (upstreams/) — Metasploit, Burp Suite, SecLists, OWASP ZAP, RustScan, Portainer, SysReptor, and BloodHound CE.
Shell & look-and-feel (zsh/) — Kali-style Zsh prompt, autosuggestions, syntax highlighting, and pentesting aliases.
A single script, install.sh, deploys everything with three tested and verified modes: --basic (keeps GNOME, deploys all CLI tooling), --sway (adds the Sway tiling desktop with the Noctalia shell, Hack Nerd Font, and focus-based opacity — 100% native RPMs, zero COPR), and --all (everything in one pass). GNOME and Sway can be switched freely at the GDM login screen.
Containerized suites land ready on localhost: SysReptor reporting :8000, BloodHound CE :8080, and Portainer :7999 (work in progress). Target environment is a QEMU/KVM VM (baseline 4 vCPU / 4 GB / 25 GB; recommended 8 vCPU / 8 GB / 35–50 GB; ~11 GB install footprint).
Status: Beta — all three install modes verified on Fedora Workstation VMs, with continuous testing underway. Parts of the project were developed with AI assistance; some upstream modules execute vendor scripts directly — inspect all scripts before running, and use entirely at your own risk.
// dashboards
localhost:7999work in progresslocalhost:8000localhost:8080Pendora is provided "as is" without warranty of any kind. Some upstream modules fetch and execute vendor installation scripts directly — inspect all scripts before running them. Parts of this project were developed with AI assistance. Intended for authorized security testing and lab environments only.
// roadmap
Synced live from TODO.md in the repo — updates on GitHub show up here on their own, no republish needed.
## Bugfixes & Active Investigations
Portainer CE Deployment
upstreams/install-upstreams.sh).Sway VM Display Auto-Rescaling
## Tooling & Upstream Additions
ADWS Domain Dump (r4cken fork)
pipx).Nuclei
Coercer
Programming Language Libraries
## Desktop Environment & UX Polish
Rofi Theme Customization
$mod+Shift+space).Noctalia Widgets & Bar Polish
tun0/wg0, IP address widget, system resource monitors).## Framework & Installer Improvements
Minimal vs. Full Installation Profiles
Self-Check / Verification Subcommand
./install.sh --verify to test if all tools, services, and symlinks are installed and responsive.Modular Uninstall / Cleanup
./install.sh --clean or module removal option to safely un-stow configurations and purge unused cache files.Air-Gapped / Offline Deployment
$ pendora roadmap --todo | 12 open tasks · synced from TODO.md · 2026-10-04▊
// faq
The things people ask before running an unknown install script on a fresh VM.
?What exactly is Pendora?
A modular installation framework and configuration template that turns a standard Fedora Linux install into a full penetration testing and security assessment VM — Kali's toolset and workflows, running natively on Fedora's RPM/DNF, Wayland, and systemd ecosystem.
?Why was Pendora developed?
Honestly? I wanted a familiar environment. Kali is great, but I enjoy Fedora far more — and since my host runs Fedora with Hyprland, I wanted that same feeling in my pentest VM. Manually reinstalling every package after a fresh setup, with no snapshots or backups to fall back on, was exactly the problem Pendora solves. I also wanted to give something back to the open-source community — and somewhere around that point, the idea of Pendora was born.
?Who is Pendora made for?
Penetration testers and red teamers who want a complete assessment VM in minutes; students and CTF players learning on professional tooling in an isolated QEMU/KVM sandbox; Fedora users who want Kali's toolset without leaving DNF, Wayland, and systemd behind; and homelab or blue-team folks who need the networking packages plus SysReptor and BloodHound CE on localhost.
?Do I need to wipe my Fedora install or dual-boot?
No. Pendora runs as a single script, ./install.sh, on top of an existing Fedora installation. Everything is organized into plain-text lists you can read and edit before running anything. It's built and tested for a QEMU/KVM VM — snapshot your VM and you can always roll back.
?Will installing Sway remove my GNOME desktop?
Never. Installing Sway adds a second session — GNOME stays exactly where it is. Switch between the two at the GDM login screen, any time.
?Which install mode should I pick?
--basic if you want to keep your GNOME desktop and just get the tooling (recommended). --sway if you want the lightweight Sway tiling desktop with the Noctalia shell. --all if you want everything in a single pass.
?What are the system requirements?
Baseline: 4 vCPU, 4 GB RAM, 25 GB disk. Recommended: 8 vCPU, 8 GB RAM, 35–50 GB. The install footprint is roughly 11 GB, and the target environment is a QEMU/KVM virtual machine.
?What do I get running out of the box?
109 native Fedora RPMs, Pipx-isolated Python tools (netexec, impacket, certipy-ad, sqlmap, responder…), containerized suites — SysReptor on :8000, BloodHound CE on :8080, Portainer on :7999 (work in progress) — plus a Kali-style Zsh shell with pentesting aliases.
?Can I add my own tools?
Yes — that's the point. The four tiers are plain-text lists under pkg-lists/, pipx-lists/, upstreams/, and zsh/. Edit them directly, or use the suggest-tool form on the tools page to open a pre-filled GitHub issue.
?Is it production-ready?
It's in beta: all three install modes are verified on Fedora Workstation VMs with continuous testing underway. Parts of the project were developed with AI assistance, and some upstream modules execute vendor scripts directly — inspect everything before running, and use entirely at your own risk.
$ pendora faq --list | 10 entries · more in the README▊