Nightingale is a Docker pentest stack with a browser Command Center terminals, scans, VPN, VS Code, and team controls in one place.
I used to burn the first hour of an engagement on setup: install the missing package, fix the broken VPN route, sync notes from three terminals, then remember the new analyst still does not have a working lab.
That hour never shows up in the report. It still costs the client.
Nightingale flips the default. One Docker image, 200+ tools, and a web Command Center so the lab is the same whether you are on a laptop or a hosted console.
The pain (in one sentence)
Toolchains sprawl across hosts, environments drift, and onboarding a tester still takes longer than the first recon pass.
What you actually get
| Surface | Why it matters |
|---|---|
| Multi-terminal + file explorer | Parallel shells in the browser; tree stays with your cwd |
| Security Scans / Playbooks / Schedules | Queue tools, chain steps, schedule repeats, export Markdown |
| VPN | Upload .ovpn, connect in an isolated container for HTB/THM-style labs |
| VS Code in-browser | Edit without leaving the engagement |
| Users + MFA + audit | Shared console without shared accountability gaps |
| Optional AI | Command suggestions + scan explainers with your own key |
Same product idea on nightingale-security.com open core under OWASP, Black Hat Arsenal track record, pull from GHCR or use the hosted dashboard.
Walk the UI (screenshots)
Sign in (or register a tenant first):
Land in the console shell + explorer for the active org/engagement:
Submit scans without babysitting a random tmux session:
Connect lab VPN without killing your console network:
Manage who can touch the console:
Quick start (hosted)
- Register: dashboard.nightingale-security.com/register
- Login: dashboard.nightingale-security.com/login
- Open Nightingale Console, pick an engagement, run a command or submit a scan.
Quick start (self-host)
docker pull ghcr.io/rajanagori/nightingale:stable
docker run -d -p 8080:8080 --name nightingale ghcr.io/rajanagori/nightingale:stable
# open http://localhost:8080
Spin it up when the test is scheduled. Tear it down when you are done. No 24/7 lab tax.
Why this sticks for teams
Engagements are scoped (org + engagement context), so org1 and org2 do not share home dirs, scan history, or VPN configs by accident. That matters when two programs run in parallel and you cannot afford “wrong folder, wrong VPN” mistakes.
The browser VS Code tab keeps notes and scripts next to the shell. Optional AI settings let you bring your own OpenAI or Azure key for scan explainers useful when you want a first pass narrative over raw tool output, not a black-box vendor model you cannot control.
Who this is for
Pentesters and security engineers who want reproducible tooling and a browser first ops surface not another “install these 40 packages” wiki page. Also useful for lab instructors and CTF crews who need the same environment every time someone joins.
If that sounds like your workflow tax, start here: nightingale-security.com → register → open the console.






Top comments (0)