High-risk tools in NmapMCP
14 of the 15 tools in NmapMCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
arp_discoveryExecutePerform ARP discovery on the specified target with optional custom arguments.
-
disable_dns_resolutionExecutedisable_dns_resolution
-
dns_brute_forceExecutePerform DNS brute-force to discover subdomains of the specified target.
-
fin_scanExecutePerform a FIN scan on the specified target with optional custom arguments.
-
idle_scanExecutePerform an idle scan on the specified target with optional custom arguments.
-
no_portscanExecutePerform host discovery without port scanning on the specified target with optional custom arguments.
-
os_detectionExecutePerform OS detection on the specified target with optional custom arguments.
-
ping_scanExecutePerform a ping scan on the specified target with optional custom arguments.
-
portscan_onlyExecutePerform a port scan only on the specified target with optional custom arguments.
-
scan_top_portsExecuteScan the top ports of the specified target with optional custom arguments.
-
syn_scanExecutePerform a SYN scan on the specified target with optional custom arguments.
-
tcp_scanExecutePerform a TCP connect scan on the specified target with optional custom arguments.
-
udp_scanExecutePerform a UDP scan on the specified target with optional custom arguments.
-
version_detectionExecuteDetect service versions on the specified target with optional custom arguments.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.