Critical-risk tools in Truenas
46 of the 279 tools in Truenas are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
acme_dns_authenticator_deleteDestructiveDelete an ACME DNS authenticator by its ID.
-
alertservice_deleteDestructiveDelete an alert notification service by its ID. Use alertservice_list to find the ID.
-
api_key_deleteDestructiveDelete an API key by its numeric ID. Use api_key_list to find the ID. This immediately revokes access for anyone using that key.
-
app_deleteDestructiveDelete/uninstall an app. This is a DESTRUCTIVE operation. The
-
bootenv_deleteDestructiveDelete a boot environment. This is a DESTRUCTIVE operation — the
-
certificate_deleteDestructiveDelete a certificate by its ID. This is a DESTRUCTIVE operation — the
-
cloud_backup_deleteDestructiveDelete a cloud backup task (destructive — requires confirm)
-
cloudsync_credentials_deleteDestructiveDelete a cloud sync credential
-
cloudsync_deleteDestructiveDelete a cloud sync task (destructive — requires confirm)
-
cronjob_deleteDestructiveDelete a cron job
-
dataset_deleteDestructiveDelete a dataset (destructive — requires confirm)
-
disk_wipeDestructiveWipe a disk, destroying all data on it. This is a DESTRUCTIVE operation — the
-
group_deleteDestructiveDelete a group. This is a DESTRUCTIVE operation — the
-
initshutdown_deleteDestructiveDelete an init/shutdown script
-
iscsi_extent_deleteDestructiveDelete an iSCSI extent (LUN)
-
iscsi_initiator_deleteDestructiveDelete an iSCSI initiator group
-
iscsi_portal_deleteDestructiveDelete an iSCSI portal
-
iscsi_target_deleteDestructiveDelete an iSCSI target
-
iscsi_targetextent_deleteDestructiveDelete an iSCSI target-to-extent mapping
-
keychaincredential_deleteDestructiveDelete an SSH credential or keypair
-
network_interface_deleteDestructiveDelete a network interface. This is a DESTRUCTIVE operation — the
-
network_static_route_deleteDestructiveDelete a static route by its numeric ID. Use network_static_route_list to find the ID.
-
nfs_share_deleteDestructiveDelete an NFS share/export
-
privilege_deleteDestructiveDelete a privilege/role by its ID. Use privilege_list to find the ID.
-
replication_deleteDestructiveDelete a replication task (destructive — requires confirm)
-
rsync_task_deleteDestructiveDelete an rsync task
-
smb_share_deleteDestructiveDelete an SMB share
-
system_ntp_server_deleteDestructiveDelete an NTP server by its ID. Use system_ntp_servers first to find the ID.
-
tunable_deleteDestructiveDelete a tunable by its ID. Use tunable_list to find the ID.
-
user_deleteDestructiveDelete a user account. This is a DESTRUCTIVE operation — the
-
vm_deleteDestructiveDelete a virtual machine. This is a DESTRUCTIVE operation. The
-
vm_device_deleteDestructiveDelete a VM device by its ID. Optionally delete the associated zvol or raw file.
-
system_shutdownDestructiveShut down the TrueNAS system. This is a DESTRUCTIVE operation — the system will power off and require physical or IPMI intervention to restart. The
-
app_rollbackDestructiveRollback an app to a previous version. This is a DESTRUCTIVE operation. The
-
cloud_backup_abortDestructiveAbort a running cloud backup task
-
directory_services_leaveDestructiveLeave the current Active Directory or LDAP domain. This is a DESTRUCTIVE operation —
-
network_rollback_changesDestructiveRollback all pending (uncommitted) network interface changes, restoring the previous network configuration.
-
snapshot_deleteDestructiveDelete a ZFS snapshot (destructive — requires confirm)
-
snapshot_rollbackDestructiveRollback a dataset to a snapshot (destructive — requires confirm)
-
snapshot_task_deleteDestructiveDelete a periodic snapshot task
-
system_rebootDestructiveReboot the TrueNAS system. This is a DESTRUCTIVE operation — all running services will be interrupted. The
-
boot_attach_diskDestructiveAttach a disk to the boot pool to create or extend a mirror. This is a DESTRUCTIVE operation that will erase the target disk. The
-
boot_detach_diskDestructiveDetach a disk from the boot pool mirror. This is a DESTRUCTIVE operation — the
-
pool_exportDestructiveExport (disconnect) a pool (destructive — requires confirm)
-
pool_replace_diskDestructiveReplace a disk in a pool (destructive — requires confirm)
-
update_applyDestructiveApply previously downloaded system updates. This is a DESTRUCTIVE operation that may reboot the system. The
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.