High-risk tools in Aapanel
28 of the 282 tools in Aapanel are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
abnormal_check_allExecuteRun all abnormal detection checks at once (MySQL, PHP, CPU, memory, disk).
-
crontab_startExecuteExecute a cron job immediately.
-
deployment_installExecuteInstall a deployment package to a site.
-
docker_container_restartExecuteRestart a Docker container.
-
docker_container_startExecuteStart a Docker container.
-
docker_container_stopExecuteStop a Docker container.
-
harden_disable_ssh_passwordExecuteDisable SSH password authentication (enforce key-only auth for hardening).
-
harden_set_ssh_key_authExecuteSet up SSH key-based authentication for hardening.
-
network_scan_portsExecuteScan ports on a target host from the aaPanel server.
-
panel_sync_timeExecuteSync server time with NTP.
-
panel_updateExecuteUpdate aaPanel to the latest version.
-
plugin_installExecuteInstall a software/plugin.
-
project_startExecuteStart a project.
-
project_stopExecuteStop a project.
-
security_baseline_repairExecuteRepair a specific security baseline issue.
-
security_baseline_scanExecuteRun security baseline scan (SSH, system config, permissions audit).
-
site_startExecuteStart a website.
-
site_stopExecuteStop a website.
-
soft_installExecuteInstall a software component (nginx, apache, mysql, php, redis, etc.).
-
system_release_memoryExecuteRelease/flush system memory (RAM cleanup). Runs sync and memory release script.
-
system_restart_panelExecuteRestart the aaPanel service.
-
system_restart_serverExecuteRestart the server. Use with caution!
-
system_service_adminExecuteStart, stop, or restart a service (nginx, apache, mysql, etc.).
-
terminal_execute_commandExecuteterminal_execute_command
-
terminal_install_bridgeExecuteterminal_install_bridge
-
virus_scan_safe_detectExecuteRun system-level safe detection (file integrity, suspicious files, permission audit).
-
virus_scan_siteExecuteStart a virus/malware scan on a website (checks for web shells, malicious code, trojans).
-
virus_scan_webExecuteRun web vulnerability scanning on a site (uses panel/scanning module).
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.