Bull spins up a fully equipped, hardened pentest VM in one command. It wraps Vagrant and your hypervisor (libvirt/KVM or VirtualBox) to build Kali or Parrot machines that come locked down by default, VPN kill switch, encrypted home, GPG-protected credentials, snapshots and a reusable toolkit manager.
| Capability | What you get |
|---|---|
| Auto-provisioning | Kali or Parrot, ready to use out of the box |
| VPN kill switch | iptables drops all traffic if the VPN drops (OpenVPN & WireGuard) |
| Encrypted /home | user data protected with ecryptfs |
| GPG credentials | AES256 + SHA512 (65M-iteration s2k), passphrase-unlocked, never written to disk in plaintext |
| Snapshots | roll back before any risky operation |
| Toolkit manager | save Git-based tools once, install them on every new VM |
| Cross-provider | libvirt/KVM or VirtualBox, auto-detected; WSL2 supported |
# One-shot host setup (Vagrant + hypervisor, unattended)
sudo ./install.sh
# Initialize Bull and verify dependencies
sudo ./bull.sh init
# Create your first VM, then just run the menu
sudo ./bull.sh create my-vm --os kali
sudo ./bull.shFirst run takes 10-15 minutes: it downloads the Vagrant box (~2-4 GB) and installs hypervisor dependencies. After
bull inityou can callbulldirectly instead of./bull.sh.
Requirements: Linux with libvirt/KVM or VirtualBox (WSL2 via libvirt),
Vagrant 2.3+, jq, gpg, ssh, sudo. The installer can pull in the rest.
sudo bull create my-vm --os kali --ram 4096 --cpu 2
sudo bull start my-vm
sudo bull connect my-vm
sudo bull snapshot my-vm pre-exploit
sudo bull vpn my-vm ~/vpn/config.ovpn
sudo bull restore my-vm pre-exploit
sudo bull destroy my-vmEvery command and flag: CLI Reference.
The Wiki is the full manual: Installation, Usage Guide, CLI Reference, VPN & Kill Switch, Toolkit Manager, Architecture, Security Model and Troubleshooting.
In-repo: Architecture, Adding a Tool, Contributing, Security Policy.
bull.sh entry point (TUI + CLI dispatch)
install.sh unattended host setup (Vagrant + hypervisor)
lib/
core.sh colors, logging, dependency checks, GPG encryption
inventory.sh VM inventory CRUD (JSON via jq)
vagrant.sh Vagrant/libvirt VM lifecycle
vpn.sh VPN configuration + kill switch
toolkits.sh toolkit installation + persistent registry
configs/ Vagrantfile template + per-OS provisioning scripts
docs/ architecture, contributing, security, tooling guides
Bull hardens every VM it creates: GPG-encrypted credentials, ecryptfs /home,
locked default OS accounts, disabled synced folders and an iptables VPN kill
switch. These are technical measures only, they do not protect against user
error or social engineering. See the
Security Model and
SECURITY.md to report vulnerabilities.
Issues and PRs welcome. See CONTRIBUTING.md for setup, conventions and the PR checklist.