# k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

Repository: https://github.com/k8gege/K8tools
Canonical: https://ross.abutalabs.com/products/k8tools
Homepage: http://k8gege.org
Language: PowerShell
License: MIT
License Family: permissive
Topics: exploit, 0day, poc, getshell, pentest, hacking, scanner, privilege-escalation, bypass, crack, netscan, brute-force, password, database, exp, lpe, rce
Last push: 2025-01-25T06:32:52+00:00

## Health v2 (maintenance only)
Score: 34/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 3, release rhythm 35, longevity 100
- inputs: {"age_days": 2748, "days_push": 585, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6203, forks 2053 (observed 2026-08-28T04:09:39.890919+00:00)

## What it is
K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege escalation, exploit delivery, password cracking, scanning, and evasion. It aggregates exploits for common web applications (Struts2, Weblogic, Tomcat, JBoss, etc.) along with shellcode, payloads, and post-exploitation utilities.

## Use cases
- find exploits for struts2 weblogic tomcat getshell
- privilege escalation tools for windows internal network pentest
- brute force and password cracking during authorized pentest
- scan internal network for live hosts and vulnerable services
- bypass UAC and evade antivirus during red team engagement
- collect poc and 0day exploits for vulnerability testing

## When to choose
- you are doing authorized penetration testing or red team work and want a broad toolkit of exploits and post-exploitation utilities
- you need quick access to privilege escalation, password cracking, and web getshell exploits in one download
- you want a Windows-centric offensive toolkit usable from cmd or webshell

## When to avoid
- you need a single well-maintained tool with documentation rather than a mixed bag of binaries and scripts
- you require guaranteed clean, audited code - the collection includes modified binaries of unclear provenance
- your use is defensive-only and you just want vulnerability scanning without offensive capabilities

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, vulnerability-scanning, security, networking
- domain: penetration-testing, security, developer-tools
- platform: windows, cli, python
- tags: exploit-collection, privilege-escalation, password-cracking, webshell, 0day, pentest-toolkit, offensive-security, red-team, command-line, linux

## Member repositories
- k8gege/K8tools (main) score 34

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:39.890919+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:47:19.565226+00:00, confidence not recorded.
  - readme: https://github.com/k8gege/K8tools (fetched 2026-08-28T04:09:39.890919+00:00, sha e42c88a3884e)
  - homepage: http://k8gege.org (fetched 2026-08-29T08:43:47.931253+00:00, sha 3fa56da5edeb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
