High-risk tools in Nyxstrike
175 of the 221 tools in Nyxstrike are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
advanced_payload_generationExecuteadvanced_payload_generation
-
ai_generate_attack_suiteExecuteGenerate comprehensive attack suite with multiple payload types.
-
ai_generate_payloadExecuteai_generate_payload
-
ai_reconnaissance_workflowExecuteai_reconnaissance_workflow
-
ai_test_payloadExecuteai_test_payload
-
ai_vulnerability_assessmentExecuteai_vulnerability_assessment
-
airbase_ngExecuteairbase_ng
-
aircrack_ngExecuteaircrack_ng
-
aircrack_ng_analysisExecuteaircrack_ng_analysis
-
airdecap_ngExecuteairdecap_ng
-
aireplay_ngExecuteaireplay_ng
-
airmon_ngExecuteairmon_ng
-
airodump_ngExecuteairodump_ng
-
amass_scanExecuteExecute Amass for subdomain enumeration with enhanced logging.
-
analyze_sessionExecuteanalyze_session
-
anew_data_processingExecuteanew_data_processing
-
angr_symbolic_executionExecuteangr_symbolic_execution
-
api_fuzzerExecuteapi_fuzzer
-
api_schema_analyzerExecuteapi_schema_analyzer
-
arjun_parameter_discoveryExecutearjun_parameter_discovery
-
arjun_scanExecutearjun_scan
-
arp_scan_discoveryExecutearp_scan_discovery
-
autopsy_analysisExecuteLaunch the Autopsy digital forensics web server and provide access instructions.
-
autorecon_comprehensiveExecuteautorecon_comprehensive
-
autorecon_scanExecuteautorecon_scan
-
bbot_scanExecutebbot_scan
-
bettercap_wifiExecutebettercap_wifi
-
binwalk_analyzeExecutebinwalk_analyze
-
breachsql_scanExecutebreachsql_scan
-
browser_agent_inspectExecutebrowser_agent_inspect
-
bugbounty_authentication_bypass_testingExecutebugbounty_authentication_bypass_testing
-
bugbounty_business_logic_testingExecutebugbounty_business_logic_testing
-
bugbounty_comprehensive_assessmentExecutebugbounty_comprehensive_assessment
-
bugbounty_file_upload_testingExecuteCreate file upload vulnerability testing workflow with bypass techniques.
-
bugbounty_reconnaissance_workflowExecutebugbounty_reconnaissance_workflow
-
bugbounty_vulnerability_huntingExecutebugbounty_vulnerability_hunting
-
burpsuite_alternative_scanExecuteburpsuite_alternative_scan
-
burpsuite_scanExecuteburpsuite_scan
-
checkov_iac_scanExecutecheckov_iac_scan
-
clair_vulnerability_scanExecuteclair_vulnerability_scan
-
classify_taskExecuteclassify_task
-
cloudmapper_analysisExecutecloudmapper_analysis
-
commixExecutecommix
-
comprehensive_api_auditExecutecomprehensive_api_audit
-
correlate_threat_intelligenceExecutecorrelate_threat_intelligence
-
create_attack_chain_aiExecutecreate_attack_chain_ai
-
dalfox_xss_scanExecutedalfox_xss_scan
-
dirb_scanExecuteExecute Dirb for directory brute forcing with enhanced logging.
-
dirsearch_scanExecutedirsearch_scan
-
discover_attack_chainsExecutediscover_attack_chains
-
dnsenum_scanExecutednsenum_scan
-
docker_bench_security_scanExecutedocker_bench_security_scan
-
dotdotpwn_scanExecutedotdotpwn_scan
-
eaphammerExecuteeaphammer
-
enum4linux_ng_advancedExecuteenum4linux_ng_advanced
-
enum4linux_scanExecuteExecute Enum4linux for SMB enumeration with enhanced logging.
-
execute_commandExecuteExecute an arbitrary command on the API server with enhanced logging.
-
execute_python_scriptExecuteexecute_python_script
-
exploit_dbExecuteexploit_db
-
falco_runtime_monitoringExecutefalco_runtime_monitoring
-
feroxbuster_scanExecuteferoxbuster_scan
-
ffuf_scanExecuteffuf_scan
-
fierce_scanExecuteExecute fierce for DNS reconnaissance with enhanced logging.
-
follow_up_sessionExecutefollow_up_session
-
foremost_carvingExecuteforemost_carving
-
gau_discoveryExecutegau_discovery
-
gdb_analyzeExecutegdb_analyze
-
gdb_peda_debugExecutegdb_peda_debug
-
generate_exploit_from_cveExecutegenerate_exploit_from_cve
-
generate_payloadExecutegenerate_payload
-
ghidra_analysisExecuteghidra_analysis
-
gobuster_scanExecutegobuster_scan
-
gospider_crawlExecutegospider_crawl
-
graphql_scannerExecutegraphql_scanner
-
hakrawler_crawlExecutehakrawler_crawl
-
handover_sessionExecutehandover_session
-
hashcat_crackExecutehashcat_crack
-
hashpump_attackExecutehashpump_attack
-
hcxdumptoolExecutehcxdumptool
-
hcxpcapngtoolExecutehcxpcapngtool
-
http_framework_testExecutehttp_framework_test
-
http_intruderExecuteSimple Intruder (sniper) fuzzing. Iterates payloads over each param individually.
-
http_repeaterExecuteSend a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data.
-
http_set_rulesExecuteSet match/replace rules used to rewrite parts of URL/query/headers/body before sending.
-
httpx_probeExecutehttpx_probe
-
hurl_requestExecutehurl_request
-
hydra_attackExecutehydra_attack
-
impacket_ad_enumExecuteimpacket_ad_enum
-
impacket_get_specExecuteimpacket_get_spec
-
impacket_remote_execExecuteimpacket_remote_exec
-
impacket_runExecuteimpacket_run
-
install_python_packageExecuteInstall a Python package in a virtual environment on the API server.
-
intelligent_smart_scanExecuteintelligent_smart_scan
-
interactsh_clientExecuteinteractsh_client
-
jaeles_vulnerability_scanExecutejaeles_vulnerability_scan
-
john_crackExecutejohn_crack
-
joomscan_analyzeExecuteExecute Joomscan for Joomla vulnerability scanning with enhanced logging.
-
katana_crawlExecutekatana_crawl
-
kube_bench_cisExecutekube_bench_cis
-
kube_hunter_scanExecutekube_hunter_scan
-
masscan_high_speedExecutemasscan_high_speed
-
massdns_scanExecutemassdns_scan
-
mdk4Executemdk4
-
medusa_attackExecutemedusa_attack
-
metasploit_runExecutemetasploit_run
-
msfvenom_generateExecutemsfvenom_generate
-
mysql_queryExecutemysql_query
-
nbtscan_netbiosExecutenbtscan_netbios
-
netexec_scanExecutenetexec_scan
-
nikto_scanExecuteExecute Nikto web vulnerability scanner with enhanced logging.
-
nmap_advanced_scanExecutenmap_advanced_scan
-
nmap_scanExecutenmap_scan
-
nuclei_scanExecutenuclei_scan
-
nyxstrike_h2csmugglerExecutenyxstrike_h2csmuggler
-
nyxstrike_net_pingExecutenyxstrike_net_ping
-
objdump_analyzeExecuteobjdump_analyze
-
one_gadget_searchExecuteone_gadget_search
-
ophcrack_crackExecuteophcrack_crack
-
optimize_tool_parameters_aiExecuteoptimize_tool_parameters_ai
-
pacu_exploitationExecutepacu_exploitation
-
paramspider_discoveryExecuteparamspider_discovery
-
paramspider_miningExecuteparamspider_mining
-
parseroExecuteExecute Parsero for Robots.txt analysis with enhanced logging.
-
patator_attackExecutepatator_attack
-
pause_processExecutePause a specific running process.
-
phaseaccess_scanExecutephaseaccess_scan
-
postgresql_queryExecutepostgresql_query
-
preview_attack_chain_aiExecutepreview_attack_chain_ai
-
prowler_scanExecuteprowler_scan
-
pwninit_setupExecutepwninit_setup
-
pwntools_exploitExecutepwntools_exploit
-
qsreplace_parameter_replacementExecuteqsreplace_parameter_replacement
-
radare2_analyzeExecuteradare2_analyze
-
research_zero_day_opportunitiesExecuteresearch_zero_day_opportunities
-
responder_credential_harvestExecuteresponder_credential_harvest
-
resume_processExecuteResume a paused process.
-
ropgadget_searchExecuteropgadget_search
-
ropper_gadget_searchExecuteropper_gadget_search
-
rpcclient_enumerationExecuterpcclient_enumeration
-
run_toolExecuterun_tool
-
rustscan_fast_scanExecuterustscan_fast_scan
-
schemathesisExecuteschemathesis
-
scout_suite_assessmentExecutescout_suite_assessment
-
select_optimal_tools_aiExecuteselect_optimal_tools_ai
-
sherlockExecuteExecute Sherlock for username investigation across social networks.
-
shuffledns_scanExecuteshuffledns_scan
-
smbmap_scanExecutesmbmap_scan
-
spiderfootExecuteExecute SpiderFoot for OSINT automation with enhanced logging.
-
sqlite_queryExecutesqlite_query
-
sqlmap_scanExecuteExecute SQLMap for SQL injection testing with enhanced logging.
-
sshExecutessh
-
steghide_analysisExecutesteghide_analysis
-
stingxss_scanExecutestingxss_scan
-
subfinder_scanExecutesubfinder_scan
-
telnetExecutetelnet
-
terrascan_iac_scanExecuteterrascan_iac_scan
-
test_error_recoveryExecutetest_error_recovery
-
testssl_analyzeExecutetestssl_analyze
-
theharvester_scanExecutetheharvester_scan
-
threat_hunting_assistantExecutethreat_hunting_assistant
-
trivy_scanExecutetrivy_scan
-
uro_url_filteringExecuteuro_url_filtering
-
vaultrip_sweepExecutevaultrip_sweep
-
volatility_analyzeExecutevolatility_analyze
-
volatility3_analyzeExecutevolatility3_analyze
-
vulnxExecutevulnx
-
wafw00f_scanExecuteExecute wafw00f to identify and fingerprint WAF products with enhanced logging.
-
wfuzz_scanExecutewfuzz_scan
-
whatweb_analyzeExecuteExecute WhatWeb for web technology fingerprinting with enhanced logging.
-
wifite2Executewifite2
-
wordlist_find_bestExecutewordlist_find_best
-
wpscan_analyzeExecuteExecute WPScan for WordPress vulnerability scanning with enhanced logging.
-
x8_parameter_discoveryExecutex8_parameter_discovery
-
xsser_scanExecuteExecute XSSer for XSS vulnerability testing with enhanced logging.
-
zap_scanExecutezap_scan
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.