High-risk tools in Pengstrike
107 of the 163 tools in Pengstrike are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
advanced_payload_generationExecuteadvanced_payload_generation
-
ai_generate_attack_suiteExecuteGenerate comprehensive attack suite with multiple payload types.
-
ai_generate_payloadExecuteai_generate_payload
-
ai_reconnaissance_workflowExecuteai_reconnaissance_workflow
-
ai_test_payloadExecuteai_test_payload
-
ai_vulnerability_assessmentExecuteai_vulnerability_assessment
-
amass_scanExecuteExecute Amass for subdomain enumeration with enhanced logging.
-
angr_symbolic_executionExecuteangr_symbolic_execution
-
api_fuzzerExecuteapi_fuzzer
-
arjun_parameter_discoveryExecutearjun_parameter_discovery
-
arp_scan_discoveryExecutearp_scan_discovery
-
autorecon_comprehensiveExecuteautorecon_comprehensive
-
autorecon_scanExecuteautorecon_scan
-
binwalk_analyzeExecutebinwalk_analyze
-
browser_agent_inspectExecutebrowser_agent_inspect
-
bugbounty_authentication_bypass_testingExecutebugbounty_authentication_bypass_testing
-
bugbounty_business_logic_testingExecutebugbounty_business_logic_testing
-
bugbounty_comprehensive_assessmentExecutebugbounty_comprehensive_assessment
-
bugbounty_file_upload_testingExecuteCreate file upload vulnerability testing workflow with bypass techniques.
-
bugbounty_reconnaissance_workflowExecutebugbounty_reconnaissance_workflow
-
burpsuite_alternative_scanExecuteburpsuite_alternative_scan
-
burpsuite_scanExecuteburpsuite_scan
-
checkov_iac_scanExecutecheckov_iac_scan
-
clair_vulnerability_scanExecuteclair_vulnerability_scan
-
comprehensive_api_auditExecutecomprehensive_api_audit
-
create_attack_chain_aiExecutecreate_attack_chain_ai
-
dalfox_xss_scanExecutedalfox_xss_scan
-
dirb_scanExecuteExecute Dirb for directory brute forcing with enhanced logging.
-
dirsearch_scanExecutedirsearch_scan
-
discover_attack_chainsExecutediscover_attack_chains
-
dnsenum_scanExecutednsenum_scan
-
docker_bench_security_scanExecutedocker_bench_security_scan
-
dotdotpwn_scanExecutedotdotpwn_scan
-
enum4linux_ng_advancedExecuteenum4linux_ng_advanced
-
enum4linux_scanExecuteExecute Enum4linux for SMB enumeration with enhanced logging.
-
execute_commandExecuteExecute an arbitrary command on the PengStrike AI server with enhanced logging.
-
execute_python_scriptExecuteexecute_python_script
-
falco_runtime_monitoringExecutefalco_runtime_monitoring
-
feroxbuster_scanExecuteferoxbuster_scan
-
ffuf_scanExecuteffuf_scan
-
fierce_scanExecuteExecute fierce for DNS reconnaissance with enhanced logging.
-
foremost_carvingExecuteforemost_carving
-
gdb_analyzeExecutegdb_analyze
-
gdb_peda_debugExecutegdb_peda_debug
-
generate_exploit_from_cveExecutegenerate_exploit_from_cve
-
generate_payloadExecutegenerate_payload
-
ghidra_analysisExecuteghidra_analysis
-
gobuster_scanExecutegobuster_scan
-
graphql_scannerExecutegraphql_scanner
-
hakrawler_crawlExecutehakrawler_crawl
-
hashcat_crackExecutehashcat_crack
-
hashpump_attackExecutehashpump_attack
-
http_framework_testExecutehttp_framework_test
-
http_intruderExecuteSimple Intruder (sniper) fuzzing. Iterates payloads over each param individually.
-
http_repeaterExecuteSend a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data.
-
httpx_probeExecutehttpx_probe
-
hydra_attackExecutehydra_attack
-
intelligent_smart_scanExecuteintelligent_smart_scan
-
jaeles_vulnerability_scanExecutejaeles_vulnerability_scan
-
john_crackExecutejohn_crack
-
katana_crawlExecutekatana_crawl
-
kube_bench_cisExecutekube_bench_cis
-
kube_hunter_scanExecutekube_hunter_scan
-
masscan_high_speedExecutemasscan_high_speed
-
metasploit_runExecuteExecute a Metasploit module with enhanced logging.
-
msfvenom_generateExecutemsfvenom_generate
-
nbtscan_netbiosExecutenbtscan_netbios
-
netexec_scanExecutenetexec_scan
-
nikto_scanExecuteExecute Nikto web vulnerability scanner with enhanced logging.
-
nmap_advanced_scanExecutenmap_advanced_scan
-
nmap_scanExecutenmap_scan
-
nuclei_scanExecutenuclei_scan
-
objdump_analyzeExecuteobjdump_analyze
-
one_gadget_searchExecuteone_gadget_search
-
optimize_tool_parameters_aiExecuteoptimize_tool_parameters_ai
-
pacu_exploitationExecutepacu_exploitation
-
paramspider_discoveryExecuteparamspider_discovery
-
pause_processExecutePause a specific running process.
-
prowler_scanExecuteprowler_scan
-
pwninit_setupExecutepwninit_setup
-
pwntools_exploitExecutepwntools_exploit
-
qsreplace_parameter_replacementExecuteqsreplace_parameter_replacement
-
radare2_analyzeExecuteradare2_analyze
-
research_zero_day_opportunitiesExecuteresearch_zero_day_opportunities
-
responder_credential_harvestExecuteresponder_credential_harvest
-
resume_processExecuteResume a paused process.
-
ropgadget_searchExecuteropgadget_search
-
ropper_gadget_searchExecuteropper_gadget_search
-
rpcclient_enumerationExecuterpcclient_enumeration
-
rustscan_fast_scanExecuterustscan_fast_scan
-
scout_suite_assessmentExecutescout_suite_assessment
-
select_optimal_tools_aiExecuteselect_optimal_tools_ai
-
smbmap_scanExecutesmbmap_scan
-
sqlmap_scanExecuteExecute SQLMap for SQL injection testing with enhanced logging.
-
subfinder_scanExecutesubfinder_scan
-
terrascan_iac_scanExecuteterrascan_iac_scan
-
test_error_recoveryExecutetest_error_recovery
-
threat_hunting_assistantExecutethreat_hunting_assistant
-
trivy_scanExecutetrivy_scan
-
volatility_analyzeExecutevolatility_analyze
-
volatility3_analyzeExecutevolatility3_analyze
-
wafw00f_scanExecuteExecute wafw00f to identify and fingerprint WAF products with enhanced logging.
-
wfuzz_scanExecutewfuzz_scan
-
wpscan_analyzeExecuteExecute WPScan for WordPress vulnerability scanning with enhanced logging.
-
x8_parameter_discoveryExecutex8_parameter_discovery
-
xsser_scanExecuteExecute XSSer for XSS vulnerability testing with enhanced logging.
-
zap_scanExecutezap_scan
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.