Pass Tomb

A pass extension that helps you keep the whole tree of passwords encrypted inside a Tomb.

Cybersecurity & Ethical HackingShellGPL-3.0

Abstract

Pass Tomb is an open-source Cybersecurity & Ethical Hacking project. A pass extension that helps you keep the whole tree of passwords encrypted inside a Tomb. Due to the structure of pass, file- and directory names are not encrypted in the password store. pass-tomb provides a convenient solution to put your password store in a [Tomb][github-tomb] and then keep your password tree encrypted when you are not using it. It is built using Shell. The complete source code is publicly available on GitHub under the GNU General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Due to the structure of pass, file- and directory names are not encrypted in the password store. pass-tomb provides a convenient solution to put your password store in a [Tomb][github-tomb] and then keep your password tree encrypted when you are not using it.

It uses the same GPG key to encrypt passwords and tomb, therefore you don't need to manage more key or secret. Moreover, you can ask pass-tomb to automatically close your store after a given time.

[![][workflow]][action] [![][gitlab]][gitlab-link] [![][coverage]][coverage-link] [![][quality]][quality-link] [![ ][release]][release-link]

2. Objective

A pass extension that helps you keep the whole tree of passwords encrypted inside a Tomb.

This project demonstrates how Shell can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Shell

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Linux / macOS terminal or WSL on Windows
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/roddhjav/pass-tomb.git
cd pass-tomb
  1. pass 1.7.0 or greater.
  2. tomb 2.4 or greater.
  3. A systemd based Linux distribution is required to use the timer feature.
yay -S pass-tomb  # or your preferred AUR install method
apt install pass-extension-tomb
guix install pass-tomb
nix-env -iA nixos.passExtensions.pass-tomb

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by roddhjav and published on GitHub under the GNU General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship