# f8x: one shell script that turns a bare Linux box into a security lab

> A dependency-light Bash script from WgpSec that installs development environments, pentest tooling, blue team utilities and CobaltStrike-class infrastructure through single-letter flags.

**ffffffff0x/f8x** — 红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

- Repository: https://github.com/ffffffff0x/f8x
- Website: https://f8x.wgpsec.org
- Stars: 2,164 · Forks: 290
- Language: Shell
- License: Apache-2.0
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/ffffffff0x-f8x

## A download, a chmod, and a help flag

f8x is not built and installed. It is a Bash file you fetch from either the project's own domain or the raw GitHub content, and the README gives you both, in wget and curl flavours:

```bash
wget -O f8x https://f8x.wgpsec.org/f8x
curl -o f8x https://f8x.wgpsec.org/f8x
```

Once the file is local, the documented entry point is:

```bash
bash f8x -h
```

Note that the invocation is `bash f8x` rather than `./f8x`, which keeps working even if the executable bit was lost in transit. The README goes further and recommends moving the script onto the path so you can drop the `bash` prefix:

```bash
wget -O f8x https://raw.githubusercontent.com/ffffffff0x/f8x/main/f8x && mv --force f8x /usr/local/bin/f8x && chmod +x /usr/local/bin/f8x
f8x -h
```

That single line is the whole installation story. There is no package index to register and no dependency to resolve first, because the script's stated purpose is partly to be the thing that installs dependencies. The project describes f8x as having essentially no system dependencies, with the stated goal of helping you install the dependencies you actually want. That is the design centre of the whole thing: it trades package hygiene for reach.

## Six batch flags that cover most of what a lab host needs

Where most installers give you one flag per package, f8x leads with environment-shaped flags that pull in a coherent group. The `-b` option installs a basic environment, which the README lists as gcc, make, git, vim, telnet, jq and unzip among others. `-d` installs a development environment covering python3, pip3, Go, Docker, Docker-Compose and SDKMAN. `-k` with a sub-letter from `a` through `e` installs a pentest environment, named in the README as hashcat, ffuf, OneForAll, ksubdomain and impacket among others.

The remaining three complete the red and blue split. `-s` installs a blue team environment, listed as Fail2Ban, chkrootkit, rkhunter and shellpub. `-f` installs what the README calls other tools, naming AdguardTeam, trash-cli and fzf. `-cloud` installs cloud applications, which are Terraform, Serverless Framework and wrangler. `-p` installs a proxy environment and carries its own warning that it should be used only when needed.

Then there is `-all`, described as fully automated deployment and annotated with the distributions it targets: CentOS 7 and 8, Debian 10 and 9, Ubuntu 20 and 18, and Fedora 33. That list is the most useful line in the options section, because it tells you both the supported matrix and its vintage. Fedora 33 and Ubuntu 18 are long out of support, so the compatibility claim tells you when the script's assumptions were fresh rather than how well they hold today. On a current distribution, the narrow per-tool flags are the safer path.

## The per-tool list runs long, and says so with file sizes

Past the batch flags, the option surface becomes a long catalogue, and it is more honest than most catalogues because it annotates payload sizes. The development group covers `-docker`, `-go`, `-rust`, `-nn` for npm and NodeJs, `-oraclejdk(8/11)`, `-openjdk`, `-py3(7/8/9/10)`, `-py2`, `-perl`, `-ruby`, `-code` for code-server, `-chromium` and `-phantomjs`. The blue team service group installs `-clamav`, `-suricata`, `-binwalk`, `-vol` and `-vol3` for volatility, and `-lt` for LogonTracer with a note that it has high hardware configuration requirements.

The red team infrastructure group is where the size annotations stop being decoration. `-awvs14` is marked at roughly 1.04 GB, `-cs` installs CobaltStrike 4.3 with `-cs45` selecting 4.5, `-frp` installs frp, `-msf` installs Metasploit, `-sliver` installs both the Sliver server and client with `-sliver-client` for the client alone, and `-viper` is marked at about 2.1 GB. The docker-based group follows the same convention: `-mobsf` at roughly 1.54 GB, `-arl` at about 872 MB, `-vulhub` at roughly 210 MB, `-vulfocus` at about 1.04 GB, plus `-nodejsscan` and `-TerraformGoat`.

One newer addition stands out because it points at a different interaction model. The `-worker` option installs a non-interactive security worker environment and writes a report to `/tmp/f8x-worker-report.json`, with failed installs referenced through per-capability logs under `/tmp/f8x-worker-logs/`. That matters for anyone driving f8x from automation, since a machine-readable report is what lets a controller know what landed. The README also documents an `-install <tool>` form that installs one tool by name, with nuclei as the worked example.

## Two sibling scripts cover CTF challenges and middleware

The repository holds three shell programs rather than one, and the split is by task. Alongside `f8x` there is `f8x-ctf`, which the README describes as deploying CTF environments across Web, Misc, Crypto, Pwn and IoT, and `f8x-dev`, which handles middleware and database deployment, named as apache, nginx, tomcat, Database and php. Both are fetched the same way and both have their own help flag:

```bash
bash f8x-ctf -help
bash f8x-dev -help
```

This separation is the clearest signal about how the author thinks about the problem. A CTF box, a development box and an offensive tooling box have almost nothing in common beyond needing Linux packages installed, and lumping them together would produce a single enormous flag space. Three files keep each surface readable, and it also means you can copy one script to a target without handing along the others.

There is a Windows counterpart too. The tree includes `f8x.ps1` next to the three Bash files, so PowerShell is at least attempted for hosts that do not have a shell of their own. Whether that path is as complete as the Bash ones is not something the README says, and it is worth checking with `-h` before depending on it.

## Positioned as the host-side layer under RedC

The README places f8x inside what it calls the WgpSec Infra ecosystem, and the positioning is more informative than the feature list. In that stack, f8x is described as the host-side software provisioning layer, usable on its own or delivered remotely by RedC to cloud hosts as the execution engine behind a software store, batch tool installation and node bootstrap workflows. In the same stack, a separate redc-template repository supplies scenario and template assets, while RedC itself handles multi-cloud orchestration, lifecycle management, SSH access, plugins and AI-driven operations.

Read that as a division of labour. RedC is the controller, f8x is the per-host executor, and the templates are the content. A single Bash script is a sensible choice for the executor layer, because it runs anywhere a shell exists, needs nothing from the host, and can be shipped over SSH without an agent or a runtime to install first.

The README opens by pointing readers at RedC as a newer infrastructure-as-code deployment tool built on Terraform with a Wails GUI. That is useful context for judging f8x's direction. The shell script is not trying to become a platform; it is the piece that works when a platform hands it a host and a list of tools. Read that way, the enormous option list stops looking like scope creep and starts looking like a catalogue of what the author and the community have needed installed in practice.

## What the repository tree reveals about maintenance

The tree is small and says a lot. Alongside the scripts and the README pair, English and Simplified Chinese, there is `catalog.json`, `tool_metadata.json` by way of `generate_catalog.py`, `check_releases.py`, `f8x_version.sh`, a `CHANGELOG.md`, a `tests/` directory, a `doc/` directory, an `index.html` for the f8x.wgpsec.org landing page, and `CNAME` pointing at that domain. A version helper script and a generated tool catalogue suggest the option list is produced from structured metadata rather than maintained by hand, which is how a catalogue this size stays consistent.

The release history is the part that needs a caveat. There are three tags, 1.6.2, 1.6.1 and 1.6.0, and the newest is from 2022-09-03. The release named 1.6.2 carries an explicit note that the latest version is distributed from an EdgeOne Pages link rather than from GitHub releases, which explains the gap: the tags lag the actual distribution channel. The 1.6.2 notes are a list of additions and compatibility updates, including support for CentOS 9 Stream and Fedora 36 and a batch of new options such as `-sliver`, `-msf`, `-interactsh`, `-wpscan` and `-rg`.

Against that, the repository itself is active. The last push was on 2026-07-25, there is one open issue, and the project has 2165 stars and 290 forks. So the useful read is that this is a maintained script distributed through a website rather than through GitHub releases, and that pinning a version means fetching from the site, not checking out a tag.

## Conclusion

f8x earns its place on a lab machine or a short-lived cloud box where you want tooling now and do not want to hand-write package manager calls per distribution. The broad flag surface is also its main limitation, because the script decides how to install each tool on CentOS, Debian, Ubuntu and Fedora, and any tool it gets wrong is a tool you end up uninstalling by hand. It is Apache-2.0 licensed, the last push was on 2026-07-25, and the newest tagged release is 1.6.2 from 2022-09-03, so the repository moves while the GitHub releases list does not. Start with `bash f8x -h`, then run one narrow per-tool flag such as `-k a` on a throwaway host before trusting `-all` with anything you care about.

## FAQ

### What is the f8x tool used for?

f8x is a Bash script for provisioning Linux hosts used in security work. It installs development environments, pentest tooling, blue team utilities, red team infrastructure and docker-based targets through single-letter flags, and it can run either by hand or as the execution engine behind a larger orchestration tool.

### How do I install and run f8x on Linux?

Download the raw script with wget or curl from f8x.wgpsec.org or from GitHub raw content, then run it with bash, for example `bash f8x -h`. The README also suggests moving it to /usr/local/bin and making it executable so it can be invoked as `f8x` without the bash prefix.

### Which Linux distributions does f8x support?

The README names CentOS 7 and 8, Debian 10 and 9, Ubuntu 20 and 18 and Fedora 33 as the targets for fully automated deployment, and a later release added CentOS 9 Stream and Fedora 36. Because several of those versions are out of support, the per-tool flags are worth testing individually on a current distribution before running the all-in-one option.

### Does f8x need root or any dependencies to run?

The project states that f8x basically needs no dependencies, since its purpose is to install the dependencies you want. Installing system packages and services such as Docker, nginx or Metasploit does require elevated privileges, so the script is normally run as root or under sudo on a host you control.

### What is the difference between f8x, f8x-ctf and f8x-dev?

They are three separate shell scripts in the same repository with different jobs. f8x installs general development, pentest and infrastructure tooling, f8x-ctf deploys CTF challenge environments such as Web, Crypto, Pwn and IoT, and f8x-dev deploys middleware and databases including apache, nginx, tomcat and php.

### Is f8x actively maintained and how often is it released?

The repository is active, with the last push recorded on 2026-07-25, but the GitHub releases list is stale: the newest tag is 1.6.2 from 2022-09-03. The release notes say the current version is distributed from an EdgeOne Pages link rather than through GitHub releases, so tags are a poor way to judge freshness.

## Sources

- [ffffffff0x/f8x on GitHub](https://github.com/ffffffff0x/f8x)
- [License: Apache-2.0](https://github.com/ffffffff0x/f8x/blob/main/LICENSE)
- [Project website](https://f8x.wgpsec.org)
- [README](https://github.com/ffffffff0x/f8x/blob/main/README.md)
- [Releases](https://github.com/ffffffff0x/f8x/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ffffffff0x-f8x
