Ross ROSS = Recommend OSS · open-source software intelligence for agents

k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) observed · 2026-08-28

github.com/k8gege/K8tools · homepage · PowerShell · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

34/100

  • Activity 3
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2748
  • days_rel: n/a
  • days_push: 585
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

6203 stars · 2053 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege escalation, exploit delivery, password cracking, scanning, and evasion. It aggregates exploits for common web applications (Struts2, Weblogic, Tomcat, JBoss, etc.) along with shellcode, payloads, and post-exploitation utilities.

Use cases

  • find exploits for struts2 weblogic tomcat getshell
  • privilege escalation tools for windows internal network pentest
  • brute force and password cracking during authorized pentest
  • scan internal network for live hosts and vulnerable services
  • bypass UAC and evade antivirus during red team engagement
  • collect poc and 0day exploits for vulnerability testing

When to choose

  • you are doing authorized penetration testing or red team work and want a broad toolkit of exploits and post-exploitation utilities
  • you need quick access to privilege escalation, password cracking, and web getshell exploits in one download
  • you want a Windows-centric offensive toolkit usable from cmd or webshell

When to avoid

  • you need a single well-maintained tool with documentation rather than a mixed bag of binaries and scripts
  • you require guaranteed clean, audited code - the collection includes modified binaries of unclear provenance
  • your use is defensive-only and you just want vulnerability scanning without offensive capabilities

Facets

cli-tool · maturity active

penetration-testing vulnerability-scanning security networking penetration-testing security developer-tools windows cli python exploit-collection privilege-escalation password-cracking webshell 0day pentest-toolkit offensive-security red-team command-line linux

2 sources

Member repositories

RepositoryRoleHealth v2
k8gege/K8toolsmain34

For agents

markdown · JSON · MCP: product_card(name="k8gege/K8tools")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem