Pendora is a modular installation framework that transforms a standard Fedora Linux install into a penetration testing and security assessment VM — bringing Kali's toolset, workflows, and aesthetics to Fedora's modern Wayland, RPM/DNF, and systemd ecosystem.
$ git clone https://github.com/sec-moose/pendora && cd pendora && ./install.sh --basic▊// architecture
Tooling, services, and configuration are organized into dedicated tiers — each a plain list you can read, edit, and extend.
pkg-lists/
109 packages verified against official Fedora repos — base compilers, networking, sniffers, web discovery, reversing, and forensics.
pipx-lists/
Offensive Python utilities in isolated environments, safe from system library conflicts.
upstreams/
Vendor installers, git clones, and Docker containers for enterprise suites.
zsh/
Interactive Zsh with autosuggestions, syntax highlighting, completions, and pentesting aliases.
// install
All three modes are tested and verified on Fedora Workstation VMs. Installing Sway never removes GNOME — pick your session at the GDM login screen.
./install.sh --basic (-b)Keeps your default Fedora GNOME desktop intact while deploying all pentest CLI tools (00–60), Pipx tools, Docker container suites, Zsh, Neovim, and Alacritty. Zero desktop changes.
./install.sh --sway (-W)Lightweight Sway tiling compositor with the Noctalia shell, Hack Nerd Font, focus-based window opacity, and SPICE host/guest clipboard sharing. 100% native Fedora RPMs — zero COPR repos. Switch between GNOME and Sway at the login screen.
./install.sh --all (-a)Single-pass end-to-end deployment of everything in Basic plus the full Sway desktop stack (70-sway.list, dotfiles, screensharing portal services).
// preview
Keep Fedora's GNOME with --basic, or deploy the dynamic Sway tiling desktop with --sway — both tested and verified on QEMU/KVM.
// dashboards
localhost:7999work in progresslocalhost:8000localhost:8080Pendora is provided "as is" without warranty of any kind. Some upstream modules fetch and execute vendor installation scripts directly — inspect all scripts before running them. Parts of this project were developed with AI assistance. Intended for authorized security testing and lab environments only.