High-risk tools in Defense
14 of the 31 tools in Defense are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
app_hardenExecuteApp hardening: audit running apps, recommendations, firewall rules, systemd sandboxing
-
container_isolationExecuteContainer isolation: AppArmor, SELinux, namespaces, seccomp, rootless setup
-
cryptoExecuteCrypto: TLS/SSL audit, GPG, LUKS, file hashing, certificate lifecycle
-
ebpfExecuteeBPF/Falco: list eBPF programs, Falco status, deploy rules, read events
-
firewallExecuteFirewall: iptables, UFW, nftables, persistence, policy audit
-
harden_kernelExecuteKernel hardening: sysctl, kernel security, bootloader, memory protections
-
honeypot_manageExecuteDeception: canary tokens, honeyport listeners, trigger detection, canary management
-
incident_responseExecuteIncident response: volatile data, IOC scan, timeline, forensics (memory/disk/network/evidence/custody)
-
malwareExecuteMalware: ClamAV scan/update, YARA rules, suspicious files, webshells, quarantine
-
sudo_sessionExecuteSudo: elevate privileges, check/drop/extend session, preflight tool checks
-
vuln_manageExecuteVulnerabilities: nmap scan, nikto web scan, tracking, risk prioritization, remediation plans
-
waf_manageExecuteWAF: ModSecurity audit, rule management, rate limiting, OWASP CRS, blocked request analysis
-
wireless_securityExecuteWireless: Bluetooth audit, WiFi assessment, rogue AP detection, disable unused interfaces
-
zero_trustExecuteZero-trust: WireGuard VPN, peer management, mTLS certificates, microsegmentation
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.