High-risk tools in Pentester-MCP
332 of the 337 tools in Pentester-MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
dnscat_clientExecutednscat_client
-
execute_weevely_moduleExecuteexecute_weevely_module
-
identify_hashExecuteidentify_hash
-
john_prepareExecutejohn_prepare
-
launch_xsser_guiExecuteLaunches the graphical user interface (GTK) for XSSer.
-
objection_exploreExecuteobjection_explore
-
run_403bypasserExecuterun_403bypasser
-
run_addcomputerExecuterun_addcomputer
-
run_aircrack_actionExecuterun_aircrack_action
-
run_aixExecuterun_aix
-
run_alterxExecuterun_alterx
-
run_amassExecuterun_amass
-
run_apktoolExecuterun_apktool
-
run_arachniExecuterun_arachni
-
run_arjunExecuterun_arjun
-
run_asnmapExecuterun_asnmap
-
run_atexecExecuterun_atexec
-
run_autobloodyExecuterun_autobloody
-
run_autoreconExecuterun_autorecon
-
run_awkExecuterun_awk
-
run_bbotExecuterun_bbot
-
run_binwalkExecuterun_binwalk
-
run_bloodhoundExecuterun_bloodhound
-
run_bloodhound_automationExecuterun_bloodhound_automation
-
run_bloodyadExecuterun_bloodyad
-
run_bruteforce_luksExecuterun_bruteforce_luks
-
run_bruteshark_analysisExecuterun_bruteshark_analysis
-
run_cariddiExecuterun_cariddi
-
run_cdncheckExecuterun_cdncheck
-
run_ceroExecuterun_cero
-
run_certipyExecuterun_certipy
-
run_cewlExecuterun_cewl
-
run_changemeExecuterun_changeme
-
run_cloud_enumExecuterun_cloud_enum
-
run_cloudlistExecuterun_cloudlist
-
run_coercerExecuterun_coercer
-
run_commixExecuterun_commix
-
run_corsyExecuterun_corsy
-
run_crlfuzzExecuterun_crlfuzz
-
run_crunchExecuterun_crunch
-
run_cuppExecuterun_cupp
-
run_curlExecuterun_curl
-
run_dacleditExecuterun_dacledit
-
run_dalfoxExecuterun_dalfox
-
run_describe_ticketExecuterun_describe_ticket
-
run_digExecuterun_dig
-
run_dirbExecuterun_dirb
-
run_dirsearchExecuterun_dirsearch
-
run_dirstalkExecuterun_dirstalk
-
run_dmitryExecuterun_dmitry
-
run_dnsenumExecuterun_dnsenum
-
run_dnsreconExecuterun_dnsrecon
-
run_dnsxExecuterun_dnsx
-
run_dockerExecuterun_docker
-
run_dotdotpwnExecuterun_dotdotpwn
-
run_dpapiExecuterun_dpapi
-
run_dpl4hydraExecuterun_dpl4hydra
-
run_drupwnExecuterun_drupwn
-
run_dump_ntlm_infoExecuterun_dump_ntlm_info
-
run_emailharvesterExecuterun_emailharvester
-
run_enum4linux_ngExecuterun_enum4linux_ng
-
run_eyewitnessExecuterun_eyewitness
-
run_fatcatExecuterun_fatcat
-
run_fcrackzipExecuterun_fcrackzip
-
run_feroxbusterExecuterun_feroxbuster
-
run_ffufExecuterun_ffuf
-
run_fierceExecuterun_fierce
-
run_finalreconExecuterun_finalrecon
-
run_findExecuterun_find
-
run_find_delegationExecuterun_find_delegation
-
run_findomainExecuterun_findomain
-
run_fpingExecuterun_fping
-
run_gaiaExecuterun_gaia
-
run_gauExecuterun_gau
-
run_get_ad_computersExecuterun_get_ad_computers
-
run_get_gpppasswordExecuterun_get_gpppassword
-
run_getadusersExecuterun_getadusers
-
run_getnpusersExecuterun_getnpusers
-
run_getpacExecuterun_getpac
-
run_getstExecuterun_getst
-
run_getuserspnsExecuterun_getuserspns
-
run_ghauriExecuterun_ghauri
-
run_gitExecuterun_git
-
run_gitleaksExecuterun_gitleaks
-
run_gobusterExecuterun_gobuster
-
run_goldenpacExecuterun_goldenpac
-
run_gospiderExecuterun_gospider
-
run_gowitnessExecuterun_gowitness
-
run_graphw00fExecuterun_graphw00f
-
run_grepExecuterun_grep
-
run_gunzipExecuterun_gunzip
-
run_hakrawlerExecuterun_hakrawler
-
run_hashcatExecuterun_hashcat
-
run_hashdeepExecuterun_hashdeep
-
run_hashidExecuterun_hashid
-
run_httpxExecuterun_httpx
-
run_hydraExecuterun_hydra
-
run_impacket_changepasswdExecuterun_impacket_changepasswd
-
run_impacket_dcomexecExecuterun_impacket_dcomexec
-
run_impacket_esentutlExecuterun_impacket_esentutl
-
run_impacket_exchangerExecuterun_impacket_exchanger
-
run_impacket_getarchExecuterun_impacket_getarch
-
run_impacket_getlapspasswordExecuterun_impacket_getlapspassword
-
run_impacket_gettgtExecuterun_impacket_gettgt
-
run_impacket_keylistattackExecuterun_impacket_keylistattack
-
run_impacket_mimikatzExecuterun_impacket_mimikatz
-
run_impacket_mssqlinstanceExecuterun_impacket_mssqlinstance
-
run_impacket_netExecuterun_impacket_net
-
run_impacket_pingExecuterun_impacket_ping
-
run_impacket_ping6Executerun_impacket_ping6
-
run_impacket_regExecuterun_impacket_reg
-
run_impacket_servicesExecuterun_impacket_services
-
run_impacket_tstoolExecuterun_impacket_tstool
-
run_jadxExecuterun_jadx
-
run_johnExecuterun_john
-
run_joomscanExecuterun_joomscan
-
run_jwt_toolExecuterun_jwt_tool
-
run_k8scanExecuterun_k8scan
-
run_katanaExecuterun_katana
-
run_kerbruteExecuterun_kerbrute
-
run_kiterunnerExecuterun_kiterunner
-
run_kubectlExecuterun_kubectl
-
run_kubernetes_taskExecuterun_kubernetes_task
-
run_lookupsidExecuterun_lookupsid
-
run_lsassyExecuterun_lsassy
-
run_machine_roleExecuterun_machine_role
-
run_mapcidrExecuterun_mapcidr
-
run_masscanExecuterun_masscan
-
run_medusaExecuterun_medusa
-
run_mqtt_checkExecuterun_mqtt_check
-
run_msfconsoleExecuterun_msfconsole
-
run_msfvenomExecuterun_msfvenom
-
run_mssqlclientExecuterun_mssqlclient
-
run_naabuExecuterun_naabu
-
run_nbtscanExecuterun_nbtscan
-
run_ndiffExecuterun_ndiff
-
run_netcat_clientExecuterun_netcat_client
-
run_netdiscover_scanExecuterun_netdiscover_scan
-
run_nikto_scanExecuterun_nikto_scan
-
run_nmapExecuterun_nmap
-
run_nmapautomatorExecuterun_nmapautomator
-
run_npingExecuterun_nping
-
run_npmExecuterun_npm
-
run_ntfs_readExecuterun_ntfs_read
-
run_nucleiExecuterun_nuclei
-
run_nxcExecuterun_nxc
-
run_onesixtyoneExecuterun_onesixtyone
-
run_openredirexExecuterun_openredirex
-
run_ownereditExecuterun_owneredit
-
run_pacuExecuterun_pacu
-
run_paramspiderExecuterun_paramspider
-
run_passdetectiveExecuterun_passdetective
-
run_phpExecuterun_php
-
run_phpsploitExecuterun_phpsploit
-
run_plumhoundExecuterun_plumhound
-
run_psexecExecuterun_psexec
-
run_pw_inspectorExecuterun_pw_inspector
-
run_pwncat_scanExecuterun_pwncat_scan
-
run_pywhiskerExecuterun_pywhisker
-
run_qsfuzzExecuterun_qsfuzz
-
run_qsreplaceExecuterun_qsreplace
-
run_raise_childExecuterun_raise_child
-
run_rbcdExecuterun_rbcd
-
run_rdp_checkExecuterun_rdp_check
-
run_recon_ngExecuterun_recon_ng
-
run_rpcclientExecuterun_rpcclient
-
run_rpcmapExecuterun_rpcmap
-
run_sambapipeExecuterun_sambapipe
-
run_scpExecuterun_scp
-
run_searchsploitExecuterun_searchsploit
-
run_sherlockExecuterun_sherlock
-
run_shufflednsExecuterun_shuffledns
-
run_sliver_actionExecuterun_sliver_action
-
run_smbclientExecuterun_smbclient
-
run_smbexecExecuterun_smbexec
-
run_smbmapExecuterun_smbmap
-
run_smtp_user_enumExecuterun_smtp_user_enum
-
run_smugglexExecuterun_smugglex
-
run_snmp_checkExecuterun_snmp_check
-
run_snmpwalkExecuterun_snmpwalk
-
run_spiderfootExecuterun_spiderfoot
-
run_sprayhoundExecuterun_sprayhound
-
run_sqlmapExecuterun_sqlmap
-
run_ssh_commandExecuterun_ssh_command
-
run_sslscanExecuterun_sslscan
-
run_ssrfmapExecuterun_ssrfmap
-
run_sstimapExecuterun_sstimap
-
run_subfinderExecuterun_subfinder
-
run_subjackExecuterun_subjack
-
run_tarExecuterun_tar
-
run_tcpdumpExecuterun_tcpdump
-
run_theharvesterExecuterun_theharvester
-
run_ticketerExecuterun_ticketer
-
run_tldfinderExecuterun_tldfinder
-
run_tlsxExecuterun_tlsx
-
run_trivyExecuterun_trivy
-
run_trufflehogExecuterun_trufflehog
-
run_uncoverExecuterun_uncover
-
run_urlfinderExecuterun_urlfinder
-
run_uroExecuterun_uro
-
run_username_anarchyExecuterun_username_anarchy
-
run_vulnxExecuterun_vulnx
-
run_wafw00fExecuterun_wafw00f
-
run_wapitiExecuterun_wapiti
-
run_wfuzzExecuterun_wfuzz
-
run_wgetExecuterun_wget
-
run_whatwebExecuterun_whatweb
-
run_windapsearchExecuterun_windapsearch
-
run_wmipersistExecuterun_wmipersist
-
run_wmiqueryExecuterun_wmiquery
-
run_wpExecuterun_wp
-
run_wpprobe_scanExecuterun_wpprobe_scan
-
run_wpscanExecuterun_wpscan
-
run_xsserExecuterun_xsser
-
run_xsstrikeExecuterun_xsstrike
-
run_xxexploiterExecuterun_xxexploiter
-
run_ysoserialExecuterun_ysoserial
-
run_zipExecuterun_zip
-
split_pcapExecutesplit_pcap
-
start_autopsyExecutestart_autopsy
-
start_bruteshark_liveExecutestart_bruteshark_live
-
start_caido_serviceExecutestart_caido_service
-
start_certipy_relayExecutestart_certipy_relay
-
start_chisel_clientExecutestart_chisel_client
-
start_chisel_serverExecutestart_chisel_server
-
start_commix_sessionExecutestart_commix_session
-
start_dnscat2_serverExecutestart_dnscat2_server
-
start_docker_monitorExecutestart_docker_monitor
-
start_evil_winrmExecutestart_evil_winrm
-
start_goshsExecutestart_goshs
-
start_gowitness_report_serverExecutestart_gowitness_report_server
-
start_hashcat_sessionExecutestart_hashcat_session
-
start_impacket_sniffExecutestart_impacket_sniff
-
start_interactsh_clientExecutestart_interactsh_client
-
start_interactsh_serverExecutestart_interactsh_server
-
start_jrmp_listenerExecutestart_jrmp_listener
-
start_k8scan_serverExecutestart_k8scan_server
-
start_karmasmbExecutestart_karmasmb
-
start_kubectl_port_forwardExecutestart_kubectl_port_forward
-
start_kubernetes_persistenceExecutestart_kubernetes_persistence
-
start_ligolo_proxyExecutestart_ligolo_proxy
-
start_mimikatz_interactive_sessionExecutestart_mimikatz_interactive_session
-
start_mitm6Executestart_mitm6
-
start_msf_handlerExecutestart_msf_handler
-
start_ncat_listenerExecutestart_ncat_listener
-
start_netcat_listenerExecutestart_netcat_listener
-
start_netdiscover_monitorExecutestart_netdiscover_monitor
-
start_ntlmrelayxExecutestart_ntlmrelayx
-
start_php_serverExecutestart_php_server
-
start_phpsploit_sessionExecuteEstablishes a persistent, interactive connection to a pre-deployed PHP backdoor.
-
start_proxifyExecutestart_proxify
-
start_psexec_shellExecutestart_psexec_shell
-
start_pwncat_sessionExecutestart_pwncat_session
-
start_recon_ng_interactiveExecutestart_recon_ng_interactive
-
start_responderExecutestart_responder
-
start_smb_serverExecutestart_smb_server
-
start_snifferExecutestart_sniffer
-
start_spiderfoot_webExecutestart_spiderfoot_web
-
start_sqlmap_os_shellExecutestart_sqlmap_os_shell
-
start_ssh_tunnelExecutestart_ssh_tunnel
-
start_sshuttleExecutestart_sshuttle
-
start_ssrfmap_handlerExecutestart_ssrfmap_handler
-
start_sstimap_interactiveExecutestart_sstimap_interactive
-
start_tcpdump_captureExecutestart_tcpdump_capture
-
start_trivy_serverExecutestart_trivy_server
-
start_weevely_sessionExecutestart_weevely_session
-
start_wireless_listenerExecutestart_wireless_listener
-
start_wp_shellExecuteOpen an interactive PHP shell (REPL) within the context of the WordPress environment.
-
start_xfreerdpExecutestart_xfreerdp
-
stop_autopsyExecuteTerminate a running Autopsy forensic server process using its PID.
-
stop_bruteshark_liveExecuteTerminates a background Bruteshark live capture process.
-
stop_caido_serviceExecuteTerminates a running Caido service process using its PID.
-
stop_certipy_relayExecuteTerminate a background Certipy relay process.
-
stop_chisel_processExecuteTerminates a background Chisel server or client process using its PID.
-
stop_commix_sessionExecuteTerminates a background Commix session (pseudo-shell or reverse shell handler)
-
stop_dnscatExecuteTerminates a background dnscat process.
-
stop_dnscat2_serverExecuteTerminates a background dnscat2-server process using its Process ID (PID).
-
stop_docker_monitorExecuteStop a background Docker monitoring process using its PID.
-
stop_evil_winrmExecuteTerminates a running evil-winrm background session.
-
stop_fping_monitorExecuteTerminates a long-running fping monitor process.
-
stop_goshsExecuteTerminates a background goshs server process using its PID.
-
stop_gowitness_report_serverExecuteTerminates a gowitness report server process.
-
stop_hashcat_sessionExecuteTerminates a background hashcat session.
-
stop_impacket_sniffExecuteTerminates a background impacket-sniff process.
-
stop_interactshExecuteTerminates a running interactsh-client or interactsh-server process.
-
stop_jrmp_listenerExecuteTerminates a background JRMP listener process.
-
stop_k8scan_serverExecuteTerminates a background k8scan server process.
-
stop_karmasmbExecuteTerminates a background impacket-karmaSMB server process.
-
stop_kubectl_processExecuteTerminates a background kubectl process (like a port-forwarder) using its PID.
-
stop_kubernetes_persistenceExecuteTerminate a background Kubernetes process (log stream or exec) using its PID.
-
stop_ligolo_proxyExecuteTerminates a running ligolo-proxy process.
-
stop_mimikatz_sessionExecuteTerminate a background Mimikatz session.
-
stop_mitm6ExecuteTerminates a running mitm6 process using its Process ID (PID).
-
stop_msf_handlerExecuteTerminates a background Metasploit handler process.
-
stop_ncat_listenerExecuteTerminates a background Ncat listener process.
-
stop_netcat_listenerExecuteTerminates a background Netcat listener process using its PID.
-
stop_netdiscover_monitorExecuteTerminates a background netdiscover monitoring process.
-
stop_ntfs_shellExecuteTerminates a background impacket-ntfs-read interactive exploration process.
-
stop_ntlmrelayxExecuteTerminates a background ntlmrelayx process.
-
stop_objection_sessionExecuteTerminates a backgrounded objection exploration session.
-
stop_php_serverExecuteTerminate a background PHP development server using its Process ID (PID).
-
stop_phpsploit_sessionExecuteTerminates a background phpsploit session using its Process ID (PID).
-
stop_proxifyExecuteTerminates a running proxify background process.
-
stop_psexec_shellExecuteTerminates a background PSExec shell session.
-
stop_pwncat_sessionExecuteTerminates a background pwncat session using its Process ID (PID).
-
stop_recon_ng_interactiveExecuteTerminates a background recon-ng session using its PID.
-
stop_responderExecuteTerminates a running Responder background process.
-
stop_smb_processExecuteTerminates a background impacket-smbclient process.
-
stop_smb_serverExecuteTerminate a running Impacket SMB server process.
-
stop_snifferExecuteTerminates a background sniffing process using its Process ID (PID).
-
stop_spiderfoot_webExecuteTerminates a background SpiderFoot web server process.
-
stop_sqlmap_os_shellExecuteTerminates a background sqlmap os-shell process.
-
stop_ssh_tunnelExecuteTerminates a background SSH tunnel or process.
-
stop_sshuttleExecuteTerminate a background sshuttle process.
-
stop_ssrfmap_handlerExecuteTerminate a background ssrfmap handler process.
-
stop_sstimap_interactiveExecuteTerminates a background sstimap session using its PID.
-
stop_tcpdump_captureExecuteTerminates a background tcpdump capture session using its Process ID (PID).
-
stop_trivy_serverExecuteTerminate a background Trivy server process.
-
stop_weevely_sessionExecuteTerminates a background Weevely session.
-
stop_wget_processExecuteTerminates a background wget process using its PID.
-
stop_wireless_listenerExecuteTerminates a background wireless process using its PID.
-
stop_wp_shellExecuteTerminates a background wp shell process by PID.
-
stop_xfreerdpExecuteTerminates a running XFreeRDP session by its Process ID (PID).
-
stop_xsser_guiExecuteTerminates a background XSSer GUI process using its PID.
-
monitor_fpingExecuteStarts a continuous, long-running fping monitor against a target host.
-
generate_weevely_agentExecutegenerate_weevely_agent
-
manage_brewExecutemanage_brew
-
manage_dirb_dictionariesExecutemanage_dirb_dictionaries
-
manage_mountsExecutemanage_mounts
-
manage_sliver_daemonExecutemanage_sliver_daemon
-
manage_wpprobeExecutemanage_wpprobe
-
objection_patchExecuteobjection_patch
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.