DEV Community

Raja Nagori
Raja Nagori

Posted on

Stop Rebuilding Your Pentest Lab for Every Engagements

Nightingale is a Docker pentest stack with a browser Command Center terminals, scans, VPN, VS Code, and team controls in one place.

I used to burn the first hour of an engagement on setup: install the missing package, fix the broken VPN route, sync notes from three terminals, then remember the new analyst still does not have a working lab.

That hour never shows up in the report. It still costs the client.

Nightingale flips the default. One Docker image, 200+ tools, and a web Command Center so the lab is the same whether you are on a laptop or a hosted console.

Nightingale homepage security testing at engineering speed

The pain (in one sentence)

Toolchains sprawl across hosts, environments drift, and onboarding a tester still takes longer than the first recon pass.

What you actually get

Surface Why it matters
Multi-terminal + file explorer Parallel shells in the browser; tree stays with your cwd
Security Scans / Playbooks / Schedules Queue tools, chain steps, schedule repeats, export Markdown
VPN Upload .ovpn, connect in an isolated container for HTB/THM-style labs
VS Code in-browser Edit without leaving the engagement
Users + MFA + audit Shared console without shared accountability gaps
Optional AI Command suggestions + scan explainers with your own key

Same product idea on nightingale-security.com open core under OWASP, Black Hat Arsenal track record, pull from GHCR or use the hosted dashboard.

Walk the UI (screenshots)

Sign in (or register a tenant first):

Nightingale Command Center login

Land in the console shell + explorer for the active org/engagement:

Web shell and file explorer

Submit scans without babysitting a random tmux session:

Submit your scan

Connect lab VPN without killing your console network:

VPN Management

Manage who can touch the console:

User Management and MFA

Quick start (hosted)

  1. Register: dashboard.nightingale-security.com/register
  2. Login: dashboard.nightingale-security.com/login
  3. Open Nightingale Console, pick an engagement, run a command or submit a scan.

Quick start (self-host)

docker pull ghcr.io/rajanagori/nightingale:stable
docker run -d -p 8080:8080 --name nightingale ghcr.io/rajanagori/nightingale:stable
# open http://localhost:8080
Enter fullscreen mode Exit fullscreen mode

Spin it up when the test is scheduled. Tear it down when you are done. No 24/7 lab tax.

Why this sticks for teams

Engagements are scoped (org + engagement context), so org1 and org2 do not share home dirs, scan history, or VPN configs by accident. That matters when two programs run in parallel and you cannot afford “wrong folder, wrong VPN” mistakes.

The browser VS Code tab keeps notes and scripts next to the shell. Optional AI settings let you bring your own OpenAI or Azure key for scan explainers useful when you want a first pass narrative over raw tool output, not a black-box vendor model you cannot control.

Who this is for

Pentesters and security engineers who want reproducible tooling and a browser first ops surface not another “install these 40 packages” wiki page. Also useful for lab instructors and CTF crews who need the same environment every time someone joins.

If that sounds like your workflow tax, start here: nightingale-security.com → register → open the console.

Top comments (0)