High-risk tools in Kali MCP Server
17 of the 19 tools in Kali MCP Server are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
kali_exploit_msfvenom_generateExecuteGenerate custom payloads for Metasploit Framework. Msfvenom is a payload generator and encoder combining msfpayload and msfencode. **WARNING:** Only use generated payloads for...
-
kali_network_masscan_scanExecuteHigh-speed port scanner capable of scanning the entire internet in minutes. Use with caution and proper authorization.
-
kali_network_netdiscover_scanExecuteARP reconnaissance tool for discovering hosts on a local network. Supports active and passive modes.
-
kali_network_nmap_discoverExecuteDiscover live hosts on a network using Nmap. Supports ping, ARP, TCP, UDP, and ICMP discovery methods.
-
kali_network_nmap_scanExecutePerform network port scanning using Nmap. Nmap (Network Mapper) is a powerful network scanner for discovering hosts, services, and potential vulnerabilities. **Capabilities:**...
-
kali_network_tcpdump_captureExecuteCapture network packets for analysis. Supports BPF filters and can save to PCAP files.
-
kali_network_tshark_captureExecuteWireshark CLI for packet capture and analysis with advanced filtering and multiple output formats.
-
kali_password_hashcat_crackExecuteAdvanced password recovery tool using GPU acceleration. Supports 300+ hash types.
-
kali_password_hydra_bruteExecuteFast network login brute-forcer supporting many protocols. Hydra is a parallelized login cracker which supports numerous protocols. **Supported Services:** - SSH, FTP, HTTP(S)...
-
kali_password_john_crackExecuteJohn the Ripper password cracker supporting many hash formats and attack modes.
-
kali_web_ffuf_fuzzExecuteFast web fuzzer for discovering hidden files, directories, and parameters. URL must contain FUZZ keyword.
-
kali_web_gobuster_dirExecuteEnumerate directories and files on web servers using wordlists. Gobuster is a fast directory/file brute-forcing tool written in Go. **Features:** - Fast multi-threaded scannin...
-
kali_web_gobuster_dnsExecuteEnumerate subdomains using DNS brute-forcing with wordlists.
-
kali_web_nikto_scanExecuteComprehensive web server scanner for vulnerabilities, misconfigurations, and security issues.
-
kali_web_nuclei_scanExecuteTemplate-based vulnerability scanner with extensive CVE coverage and custom templates support.
-
kali_web_sqlmap_testExecuteAutomated SQL injection testing and exploitation. SQLMap automates the detection and exploitation of SQL injection vulnerabilities. **WARNING:** Only use on systems you have a...
-
kali_web_wpscan_scanExecuteWordPress security scanner for finding vulnerabilities in WordPress sites, themes, and plugins.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.