High-risk tools in Claude C2
35 of the 94 tools in Claude C2 are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
amsi_bypassExecuteBypass AMSI. Auto-selects client.
-
bypassuacExecuteUAC bypass. Auto-selects client.
-
defender_excludeExecuteAdd Defender exclusion. Auto-selects client.
-
etw_patchExecutePatch ETW logging. Auto-selects client.
-
execute_assemblyExecuteLoad and execute .NET assembly in memory. Auto-selects client if only one connected.
-
firewall_ruleExecuteManage firewall rule. Auto-selects client.
-
generate_payloadExecuteGenerate customized payload with specific options
-
get_payloadExecuteGet agent payload/implant for a specific platform
-
getsystemExecuteGet SYSTEM privileges. Auto-selects client.
-
injectExecuteInject shellcode. Auto-selects client.
-
keylog_startExecuteStart keylogger. Auto-selects client.
-
keylog_stopExecuteStop keylogger. Auto-selects client.
-
mcp_add_toolExecuteAdd a new MCP tool dynamically (adds to tools list and handler)
-
mcp_append_codeExecuteAppend code to MCP server file
-
mcp_restartExecuteRestart the MCP server to apply code changes
-
mimikatzExecuteRun Mimikatz command. Auto-selects client.
-
persist_registryExecuteRegistry run key persistence. Auto-selects client.
-
persist_schtaskExecuteScheduled task persistence. Auto-selects client.
-
persist_serviceExecuteInstall as Windows service. Auto-selects client.
-
persist_startupExecuteAdd to startup folder. Auto-selects client.
-
persist_wmiExecuteWMI event subscription persistence. Auto-selects client.
-
portscanExecutePort scan target. Auto-selects client.
-
powershellExecuteExecute PowerShell command on Windows client. Auto-selects client if only one connected.
-
privesc_checkExecuteCheck privesc vectors. Auto-selects client.
-
psexecExecutePsExec remote execution. Auto-selects client.
-
runasExecuteRun as different user. Auto-selects client.
-
send_remote_commandExecuteSend a command to a remote client
-
server_shellExecuteExecute any shell command on C2 server (bash, no sandbox, full permissions). Use sudo for privileged ops.
-
shellExecuteExecute shell command on remote client (cmd.exe on Windows, /bin/sh on Linux). If only one client connected, client_id is auto-selected.
-
spawnExecuteSpawn process. Auto-selects client.
-
ssh_execExecuteSSH remote execution. Auto-selects client.
-
webcamExecuteCapture webcam photo. Auto-selects client.
-
winrmExecuteWinRM remote execution. Auto-selects client.
-
wmiexecExecuteWMI remote execution. Auto-selects client.
-
zipExecuteCompress to zip. Auto-selects client.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.