Critical-risk tools in Appaloft
44 of the 358 tools in Appaloft are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
account_deleteDestructiveRun account.delete through the Appaloft application operation catalog. Shared with HTTP/API.
-
account_sessions_revokeDestructiveRun account.sessions.revoke through the Appaloft application operation catalog. Shared with HTTP/API.
-
audit_events_archives_pruneDestructiveRun audit-events.archives.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
audit_events_pruneDestructiveRun audit-events.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
certificates_deleteDestructiveRun certificates.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
certificates_revokeDestructiveRun certificates.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
connections_revokeDestructiveRun connections.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
control_plane_portability_artifacts_deleteDestructiveRun control-plane-portability.artifacts.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
credentials_delete_sshDestructiveRun credentials.delete-ssh through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
dependency_resources_deleteDestructiveRun dependency-resources.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
deployments_archiveDestructiveRun deployments.archive through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
deployments_pruneDestructiveRun deployments.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
domain_bindings_deleteDestructiveRun domain-bindings.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
domain_events_pruneDestructiveRun domain-events.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
operator_work_pruneDestructiveRun operator-work.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
organizations_deleteDestructiveRun organizations.delete through the Appaloft application operation catalog. Shared with HTTP/API.
-
organizations_remove_memberDestructiveRun organizations.remove-member through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
preview_environments_deleteDestructiveRun preview-environments.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
projects_deleteDestructiveRun projects.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
provider_job_logs_pruneDestructiveRun provider-job-logs.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_archiveDestructiveRun resources.archive through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_deleteDestructiveRun resources.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_detach_storageDestructiveRun resources.detach-storage through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_runtime_control_attempts_pruneDestructiveRun resources.runtime-control-attempts.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_runtime_log_archives_pruneDestructiveRun resources.runtime-log-archives.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
resources_secrets_deleteDestructiveRun resources.secrets.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_credentials_revokeDestructiveRun sandbox-credentials.revoke through the Appaloft application operation catalog. Shared with HTTP/API.
-
sandbox_files_removeDestructiveRun sandbox-files.remove through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_ports_revokeDestructiveRun sandbox-ports.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_snapshots_deleteDestructiveRun sandbox-snapshots.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandbox_templates_deleteDestructiveRun sandbox-templates.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_candidate_previews_deleteDestructiveRun sandboxes.candidate-previews.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_source_artifacts_deleteDestructiveRun sandboxes.source-artifacts.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
sandboxes_terminateDestructiveRun sandboxes.terminate through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
scheduled_tasks_deleteDestructiveRun scheduled-tasks.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
servers_capacity_pruneDestructiveRun servers.capacity.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
servers_deactivateDestructiveRun servers.deactivate through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
servers_deleteDestructiveRun servers.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
source_events_pruneDestructiveRun source-events.prune through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
source_links_deleteDestructiveRun source-links.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
storage_volumes_deleteDestructiveRun storage-volumes.delete through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
storage_volumes_prune_backupsDestructiveRun storage-volumes.prune-backups through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
tunnels_revokeDestructiveRun tunnels.revoke through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
-
organizations_transfer_ownerFinancialRun organizations.transfer-owner through the Appaloft application operation catalog. Shared with CLI and HTTP/API.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.