High-risk tools in Ikuai
13 of the 229 tools in Ikuai are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
enable_sshExecute启用/禁用 SSH 服务
-
enable_telnetExecute启用/禁用 Telnet 服务
-
iperf_testExecute执行 iPerf 吞吐测试
-
kick_pppoe_userExecute踢下线指定用户
-
ping_testExecute执行 Ping 测试
-
restart_apExecute重启指定 AP
-
scan_surrounding_channelsExecute扫描周边信道
-
speed_testExecute执行线路测速
-
start_firmware_upgradeExecute开始固件升级 ⚠️⚠️ 路由器会重启断网!
-
toggle_pppoe_serverExecute启用/禁用 PPPoE 服务端
-
tracerouteExecute执行 Traceroute 路由追踪
-
upgrade_ap_firmwareExecute升级 AP 固件 ⚠️ AP 会重启
-
wake_on_lanExecute发送网络唤醒包 (Wake-on-LAN)
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.