Critical-risk tools in Aapanel
26 of the 282 tools in Aapanel are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
backup_deleteDestructiveDelete a backup.
-
crontab_deleteDestructiveDelete a cron job.
-
cve_set_vuln_ignoreDestructiveIgnore a specific vulnerability permanently.
-
database_deleteDestructiveDelete a database.
-
database_delete_backupDestructiveDelete a database backup.
-
docker_image_deleteDestructiveDelete a Docker image.
-
file_deleteDestructiveDelete a file or directory on the server.
-
firewall_delete_ipDestructiveRemove an IP rule from the firewall.
-
firewall_delete_portDestructiveClose a port in the firewall.
-
ftp_deleteDestructiveDelete an FTP user.
-
harden_clear_temp_loginDestructiveClear all temporary login sessions for security.
-
plugin_uninstallDestructiveUninstall a software/plugin.
-
project_deleteDestructiveDelete a project.
-
site_deleteDestructiveDelete a website.
-
site_delete_domainDestructiveRemove a domain from a site.
-
soft_uninstallDestructiveUninstall a software component.
-
ssl_delete_certDestructiveDelete an SSL certificate from the panel.
-
system_clear_all_cacheDestructiveClear all system garbage: mail logs, temp files, install cache, wwwlogs.
-
system_clear_all_logsDestructiveClose/clear all website logs on the server.
-
system_clear_cacheDestructiveClear system cache to free up memory.
-
system_clear_old_sessionsDestructiveDelete old panel sessions to free up resources.
-
system_clear_panel_logsDestructiveClear aaPanel error logs.
-
system_clear_site_logsDestructiveClear access/error logs for a specific site.
-
tamper_remove_file_denyDestructiveRemove tamper protection from a file/directory.
-
task_removeDestructiveRemove/cancel a background task.
-
waf_delete_ruleDestructiveDelete a WAF rule by ID.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.