Updated on 2026-02-14
TLDR: Personal Kali Linux configuration (dotfiles, terminal/prompt config, browser policies/extensions and Burp/BApps settings).
Use at your own risk on a fresh Kali install pasting the following commands on the terminal:
git clone https://github.com/haxowl/kaliconfig.gitcd kaliconfigchmod 777 install.sh./install.sh⣿⣿⣿⣿⣿⣿⣿⣿⣿⣟⡟⢿⡿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⢟⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠄⠐⠛⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⠁⠄⢾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡉⡀⠄⠄⣀⠛⠛⠉⠁⠄⠄⠈⠉⠛⠛⣀⠤⠄⢀⢩⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡠⠄⠑⣿⣅⡀⠄⢐⢂⡰⡀⡀⣄⣼⣿⠊⠄⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⢁⢔⠄⠄⠛⣿⣶⣮⠛⢟⣤⣾⡿⠛⠄⡀⡢⡈⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡁⠎⣼⡇⠄⣶⣷⠉⠹⠃⠸⠏⠉⣶⣦⠄⢸⣧⢱⠈⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⡏⠄⢆⢿⣿⣄⡈⠁⣀⡼⢡⡄⢕⣀⡈⢁⣠⣿⡛⡸⠄⣹⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠈⠢⣙⡛⠻⠟⠛⠃⢸⡇⠘⠟⠻⠛⢋⣉⠜⠁⠰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠁⠄⠄⠈⠉⠋⠛⠉⠶⡘⢁⠶⠙⠙⠙⠉⠁⢀⠄⠘⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡟⠄⠄⠄⠐⡽⡰⠄⡠⡄⠄⠁⠈⣀⢠⢀⣐⣄⠻⠢⠄⠄⠠⢻⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⡏⠄⠄⠄⠄⠃⠗⡜⣿⣿⣽⡄⠰⣯⣿⣿⠢⠹⠔⠄⠄⠄⠄⢽⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⡯⢢⠂⠄⠄⠄⠄⠄⠘⢇⠉⣸⣼⣻⢇⢇⡸⠁⠄⠄⠄⠄⠄⠐⡄⣟⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣧⠄⠄⠄⠄⠄⠄⠄⠄⠄⠑⢄⢻⡟⠠⢉⠁⠄⠄⠄⠄⠄⠄⠄⢸⣾⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⡧⠤⠁⠄⠄⠄⠄⠄⠄⠄⠄⠄⠊⠁⠁⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⢻⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣷⣶⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠐⣾⣾⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣗⣠⡆⢐⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠆⢰⡐⣺⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣯⡷⠠⢰⠁⡀⠄⠄⠄⠄⠄⠄⠄⠄⡀⠄⠄⠄⡄⠈⢷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣀⣗⣶⠃⡐⠈⠂⠄⠄⠄⠄⠘⠁⢀⠈⣶⣧⡀⢷⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣾⣿⣿⣾⣶⡅⠄⠢⡄⢠⡔⠄⢿⣤⣧⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ ⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣾⣶⣿⣶⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿
This is my personal config, nothing fancy and far from perfect but it works for me and it might work for you too.
Tested on Kali 2025.4 running on VMWare Workstation 17.x
My main intention for this project is to have a ready-to-go kali VM for each new client.
Credits: thegoodhackertv ippsec pimpmykali blacklanternsecurity
About the files
README.md - usage notes and quick instructions. It instructs cloning the repo and running install.sh.
install.sh - bash script to perform the setup, full details below.
zshrc , p10k.zsh , kitty.conf , qterminal.ini , tmux.conf.local - shell prompt and shell config: full prompt setup, ZSH plugins, terminal config and tmux shortcuts.
policies.json , UserConfigCommunity.json - Firefox / BurpSuite policies: installs specific Firefox extensions and configures Firefox prefs, same for Burp.
install.sh dissection
- A Kali Linux post-install automation script
- Installs red-team toolkit
- Customizes XFCE desktop
- Configures Zsh + tmux
- Sets up Burp, Metasploit, AD tools
- Adds privilege escalation binaries
- Tweaks system settings
#!/bin/bashTells the system to run the script using Bash.
if [ "$UID" -eq 0 ]; then echo "Cannot run as root." exit 1if [ -n "$SUDO_USER" ]; then echo "Do not use sudo" exit 1If current user is root, stop execution.
If script is launched with sudo, stop execution.
The script wants to run as a normal user, and only use sudo internally.
RPATH=`pwd`Stores current working directory in variable RPATH.
Used later to copy config files from the script’s directory.
xfconf-query -c xfce4-power-manager -p /xfce4-power-manager/presentation-mode -s true --create --type boolxfconf-query -c xfce4-power-manager -p /xfce4-power-manager/show-tray-icon -s true --create --type boolEnables presentation mode.
Shows power manager tray icon.
Prevents sleep/auto-lock/screensaver.
sudo apt update -ysudo DEBIAN_FRONTEND=noninteractive apt upgrade -yUpdates package lists.
Upgrades all installed packages.
Avoids interaction during installation.
sudo apt remove -y python3-httpxRemoves python3-httpx to avoid conflict prevention.
sudo DEBIAN_FRONTEND=noninteractive apt install -y python3 python3-pip feh scrot scrub xclip xsel fastfetch wmname acpi imagemagick python3-pip lsd bpython open-vm-tools-desktop open-vm-tools pipx git python3-argcomplete netexec bat bloodhound gowitness eaphammer seclists bettercap jq kitty rlwrap font-manager cyberchef gobuster nuclei neovim golang subfinder docker.io docker-compose bloodyad certipy-ad feroxbuster oscanner redis-tools sipvicious tnscmd10g libpcap-dev sshpass sliver nishang ssh-audit dnsx airgeddon wifiphisher autorecon coercer openfortivpn libpcap-devInstalls:
Core tools: python3, pip, git, golang
Recon tools: nuclei, gobuster, subfinder, dnsx
AD tools: bloodhound, certipy-ad
Wireless tools: airgeddon, wifiphisher
Offensive tools: bettercap, sliver
Docker
Editors: neovim
Terminal tools: kitty, bat, lsd
And many more
rm -rf ~/.oh-my-zshyes | sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"git clone https://github.com/zsh-users/zsh-autosuggestions ${ZSH_CUSTOM:-~/.oh-my-zsh/custom}/plugins/zsh-autosuggestionsgit clone https://github.com/zsh-users/zsh-syntax-highlighting.git ${ZSH_CUSTOM:-~/.oh-my-zsh/custom}/plugins/zsh-syntax-highlightingrm -f ~/.zshrccp -v $RPATH/zshrc ~/.zshrcDeletes existing Oh My Zsh.
Installs fresh version automatically.
Adds shell autocompletion & syntax highlighting.
Replaces user’s .zshrc config with custom one.
rm -rf ~/.tmuxgit clone https://github.com/gpakosz/.tmux.git ~/.tmuxln -s -f ~/.tmux/.tmux.conf ~/cp -v $RPATH/tmux.conf.local ~/.tmux.conf.localInstalls popular tmux config.
Applies custom configuration.
git clone --depth=1 https://github.com/romkatv/powerlevel10k.git ${ZSH_CUSTOM:-$HOME/.oh-my-zsh/custom}/themes/powerlevel10krm -f ~/.p10k.zshcp -v $RPATH/p10k.zsh ~/.p10k.zshInstalls fancy Zsh theme.
Applies config.
sudo timedatectl set-timezone "Europe/Madrid"Changes system timezone.
mkdir /tmp/fontswget https://github.com/ryanoasis/nerd-fonts/releases/download/v3.3.0/Hack.zip -O /tmp/fonts/Hack.zipunzip /tmp/fonts/Hack.zip -d /tmp/fontssudo font-manager -i /tmp/fonts/*.ttfDownloads Hack Nerd Font:
Install via font-manager
sudo msfdb initSets up Metasploit database.
sudo git clone https://github.com/Flangvik/SharpCollection /opt/sharpcollectionsudo git clone https://github.com/dirkjanm/krbrelayx /opt/krbrelayxsudo git clone https://github.com/coffinxp/loxs.git /opt/loxssudo pip3 install -r /opt/loxs/requirements.txt --break-system-packagessudo wget https://download.sysinternals.com/files/SysinternalsSuite.zip -O /opt/SysinternalsSuite.zipsudo unzip /opt/SysinternalsSuite.zip -d /opt/SysinternalsSuitesudo rm /opt/SysinternalsSuite.zipsudo wget https://cdn.sanity.io/files/r09655ln/production/c3f3789f35a16bbf88fa6a656a2cdab2369c3b3c.zip -O /opt/pingcastle.zipsudo unzip /opt/pingcastle.zip -d /opt/pingcastlesudo rm /opt/pingcastle.zipClones tools into /opt/, including:
SharpCollection
krbrelayx
pingcastle
sysinternalssuite
sudo mkdir /opt/miscsudo wget https://github.com/peass-ng/PEASS-ng/releases/latest/download/linpeas.sh -O /opt/misc/linpeas.shsudo wget https://github.com/peass-ng/PEASS-ng/releases/latest/download/winPEAS.bat -O /opt/misc/winPEAS.batsudo wget https://github.com/peass-ng/PEASS-ng/releases/latest/download/winPEASany.exe -O /opt/misc/winPEASany.exesudo wget https://github.com/peass-ng/PEASS-ng/releases/latest/download/winPEASx64.exe -O /opt/misc/winPEASx64.exesudo wget https://github.com/itm4n/PrivescCheck/releases/latest/download/PrivescCheck.ps1 -O /opt/misc/PrivescCheck.ps1sudo wget https://github.com/DominicBreuker/pspy/releases/download/v1.2.1/pspy32 -O /opt/misc/pspy32sudo wget https://github.com/DominicBreuker/pspy/releases/download/v1.2.1/pspy32 -O /opt/misc/pspy64sudo wget https://raw.githubusercontent.com/gladiatx0r/Powerless/refs/heads/master/Powerless.bat -O /opt/misc/Powerless.batsudo wget https://raw.githubusercontent.com/The-Z-Labs/linux-exploit-suggester/refs/heads/master/linux-exploit-suggester.sh -O /opt/misc/linux-exploit-suggester.shsudo git clone https://github.com/carlospolop/cloudpeass /opt/cloudpeasssudo wget https://github.com/ohpe/juicy-potato/releases/download/v0.1/JuicyPotato.exe -O /opt/misc/JuicyPotato.exesudo wget https://raw.githubusercontent.com/topotam/PetitPotam/refs/heads/main/PetitPotam.py -O /opt/misc/PetitPotam.pysudo wget https://github.com/topotam/PetitPotam/raw/refs/heads/main/PetitPotam.exe -O /opt/misc/PetitPotam.exesudo wget https://raw.githubusercontent.com/maaaaz/nmaptocsv/refs/heads/master/nmaptocsv.py -O /opt/misc/nmaptocsv.py12 collapsed lines
sudo wget https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET4.exe -O /opt/misc/GodPotato-NET4.exesudo wget https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET35.exe -O /opt/misc/GodPotato-NET35.exesudo wget https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET2.exe -O /opt/misc/GodPotato-NET2.exesudo wget https://github.com/jpillora/chisel/releases/download/v1.11.3/chisel_1.11.3_linux_amd64.gz -O /opt/misc/chisel_1.11.3_linux_amd64.gzsudo wget https://github.com/jpillora/chisel/releases/download/v1.11.3/chisel_1.11.3_windows_amd64.gz -O /opt/misc/chisel_1.11.3_windows_amd64.gzsudo gunzip /opt/misc/chisel_1.11.3_linux_amd64.gzsudo gunzip /opt/misc/chisel_1.11.3_windows_amd64.gzsudo chmod 777 /opt/misc/chisel_1.11.3_linux_amd64sudo mv /opt/misc/chisel_1.11.3_windows_amd64 /opt/misc/chisel.exesudo wget https://raw.githubusercontent.com/jakehildreth/Locksmith/refs/heads/main/Invoke-Locksmith.ps1 -O /opt/misc/Invoke-Locksmith.ps1sudo wget https://github.com/ropnop/kerbrute/releases/download/v1.0.3/kerbrute_linux_amd64 -O /opt/misc/kerbrutesudo chmod 777 /opt/misc/kerbruteCreates /opt/misc and downloads:
linpeas
winPEAS
PrivescCheck
pspy
PetitPotam
JuicyPotato
GodPotato
chisel
kerbrute
nmaptocsv
Locksmith
These are red-team / pentest utilities.
go install github.com/projectdiscovery/naabuInstalls port scanner.
sudo wget -O code-latest.deb 'https://code.visualstudio.com/sha/download?build=stable&os=linux-deb-x64'sudo DEBIAN_FRONTEND=noninteractive apt install -y ./code-latest.debsudo rm code-latest.debInstall VSCode.
nucleisudo nucleiInitialize Nuclei Templates
ssh-keygen -t rsa -f ~/.ssh/id_rsa -P ""Creates SSH keypair with empty passphrase.
sudo mkdir /usr/local/lib/BurpSuitesudo wget https://repo1.maven.org/maven2/org/jruby/jruby-complete/9.4.9.0/jruby-complete-9.4.9.0.jar -O /usr/local/lib/BurpSuite/jruby-complete.jarsudo wget https://repo1.maven.org/maven2/org/python/jython-standalone/2.7.4/jython-standalone-2.7.4.jar -O /usr/local/lib/BurpSuite/jython-standalone.jarsudo chmod 0644 /usr/local/lib/BurpSuite/jruby-complete.jarsudo chmod 0644 /usr/local/lib/BurpSuite/jython-standalone.jar/bin/bash -c "timeout 45 /usr/lib/jvm/java-21-openjdk-amd64/bin/java -Djava.awt.headless=true -jar /usr/share/burpsuite/burpsuite.jar < <(echo y) &"sleep 30curl http://localhost:8080/cert -o /tmp/cacert.dersudo cp -v /tmp/cacert.der /usr/local/share/ca-certificates/BurpSuiteCA.dersudo chmod 0644 /usr/local/share/ca-certificates/BurpSuiteCA.dersudo rm /tmp/cacert.dersudo cp -v $RPATH/UserConfigCommunity.json ~/.BurpSuite/UserConfigCommunity.jsonCreates /usr/local/lib/BurpSuite
Downloads:
jruby
jython
Generates Burp CA certificate:
Launches Burp headless
Extracts cert
Installs into system CA store
Copies custom Burp config.
sudo cp -v $RPATH/policies.json /usr/share/firefox-esr/distribution/policies.jsonInstalls Burp certificate into Firefox.
Installs extensions.
mkdir ~/.config/kittycp -v $RPATH/kitty.conf ~/.config/kitty/kitty.confcp -v $RPATH/qterminal.ini ~/.config/qterminal.org/qterminal.iniTerminal Config
kitty.conf
qterminal.ini
mkdir ~/tmuxlogsecho "tmux pipe-pane -o 'cat >>~/tmuxlogs/tmux.#H.#S.#I.#P_%Y.%m.%d_%H.%M.%S.log'" >> ~/tmux_start_logging.shchmod 777 ~/tmux_start_logging.shLogs all tmux sessions automatically.
xfconf-query -c xfce4-panel -p /plugins/plugin-5/items -t string -a -s 'kali-burpsuite.desktop' --createxfconf-query -c xfce4-panel -p /plugins/plugin-6/items -t string -a -s 'xfce-text-editor.desktop' --createxfconf-query -c xfce4-panel -p /plugins/plugin-7/items -t string -a -s 'firefox-esr.desktop' --createxfce4-panel --add=launcherxfconf-query -c xfce4-panel -p /plugins/plugin-23/items -t string -a -s 'code.desktop' --createxfce4-panel --add=launcherxfconf-query -c xfce4-panel -p /plugins/plugin-24/items -t string -a -s 'kitty.desktop' --createxfconf-query -c xfce4-panel -p /panels/panel-1/plugin-ids -a -t int -s 1 -t int -s 2 -t int -s 3 -t int -s 4 -t int -s 5 -t int -s 6 -t int -s 7 -t int -s 23 -t int -s 24 -t int -s 8 -t int -s 9 -t int -s 10 -t int -s 11 -t int -s 12 -t int -s 13 -t int -s 14 -t int -s 15 -t int -s 16 -t int -s 17 -t int -s 18 -t int -s 19 -t int -s 20 -t int -s 21 -t int -s 22xfconf-query -c xfce4-panel -p /plugins/plugin-19/digital-layout -t int -s 1xfconf-query -c xfce4-panel -p /plugins/plugin-1/favorites -a -n -t string -s 'kitty.desktop' -t string -s 'firefox-esr.desktop' -t string -s 'code.desktop' -t string -s 'kali-burpsuite.desktop' -t string -s 'xfce-text-editor.desktop' -t string -s 'xfce4-terminal-emulator.desktop' -t string -s 'root-terminal.desktop' -t string -s 'xfce4-file-manager.desktop' -t string -s 'exploit-database.desktop' -t string -s 'vulnhub.desktop'xfconf-query -c thunar -p /last-show-hidden -t bool -s true --createxfconf-query -c xfce4-panel -p /plugins/plugin-11/show-labels -t bool -s true --createxfconf-query -c xfce4-panel -p /plugins/plugin-11/grouping -t bool -s false --createUses xfconf-query to:
Add launchers:
Burp
Firefox
VSCode
Kitty
Reorder panel
Set clock layout
Add favorites to menu
Show hidden files
Adjust window button behavior
sudo cp -v $RPATH/idorfuzz.txt /usr/share/seclists/idorfuzz.txtAdds custom wordlist to SecLists.
sudo wget https://github.com/bol-van/zapret/releases/download/v72.9/zapret-v72.9.zipsudo unzip zapret-v72.9.zipsudo mv zapret-v72.9 /opt/zapretDownloads zapret DPI Bypass.
sudo updatedbUpdate locate Database
sudo runuser -u postgres -- psql -c 'ALTER DATABASE postgres REFRESH COLLATION VERSION; ALTER DATABASE template1 REFRESH COLLATION VERSION;'Fix PostgreSQL Collation.
Fixes locale mismatch issues.
sudo rm -rf ~/githubsudo rm -rf $RPATHCleanup
Deletes:
~/github
Entire directory where script was run
echo -e "\n[+] Input new ROOT password!\n"sudo passwd rootecho -e "\n[+] Input new KALI password!\n"sudo passwd kaliPrompts user to:
Set root password
Set kali password