High-risk tools in Kali Security MCP
129 of the 194 tools in Kali Security MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
adaptive_cmdi_testExecute自适应命令注入测试
-
adaptive_create_execution_contextExecute创建自适应执行上下文
-
adaptive_execute_strategyExecute执行自适应策略
-
adaptive_intelligent_orchestrationExecute智能编排多目标自适应攻击
-
adaptive_network_penetrationExecute自适应网络渗透测试 - 智能化网络攻击。
-
adaptive_sqli_testExecute自适应SQL注入测试 - 智能检测和利用
-
adaptive_web_penetrationExecute自适应Web渗透测试 - 智能化Web应用攻击。
-
adaptive_xss_testExecute自适应XSS测试 - 上下文感知的XSS检测
-
add_chain_stepExecuteadd_chain_step
-
agent_runExecuteagent_run
-
aircrack_attackExecuteaircrack_attack
-
apt_comprehensive_attackExecute执行APT综合攻击链 - 全面的多向量并发攻击。
-
apt_network_penetrationExecute执行APT网络渗透攻击链 - 自动化多阶段网络渗透测试。
-
apt_web_application_attackExecute执行APT Web应用攻击链 - 自动化多阶段Web应用渗透。
-
arp_scanExecuteExecute arp-scan for network discovery.
-
auth_bypass_testExecute认证绕过测试 - 内置工作流
-
authorized_comprehensive_security_assessmentExecuteRun authorized full-chain assessment using neutral external naming.
-
authorized_controlled_validationExecuteRun controlled validation phase only when allowed_actions permits it.
-
authorized_credential_assessmentExecuteRun authorized credential audit phase only when allowed_actions permits it.
-
authorized_environment_reviewExecuteRun environment review phase only when allowed_actions permits it.
-
authorized_injection_verificationExecuteRun non-destructive injection verification only (no dump/exfiltration).
-
authorized_network_exposure_assessmentExecuteRun authorized network exposure assessment with phase-level output.
-
authorized_template_validationExecuteRun template-based security validation with constrained severity scope.
-
authorized_web_application_assessmentExecuteRun authorized web assessment with exposure review and vuln validation.
-
auto_reverse_analyzeExecute自动选择可用工具进行逆向分析 - 智能工具选择
-
bandit_scanExecutebandit_scan
-
bettercap_attackExecutebettercap_attack
-
browser_clickExecute模拟人工点击页面元素(带随机延迟和鼠标移动模拟)
-
browser_close_sessionExecute关闭浏览器会话并保存状态(cookies/storage持久化到磁盘)
-
browser_execute_jsExecute在浏览器上下文中执行JavaScript代码
-
browser_intercept_requestExecutebrowser_intercept_request
-
browser_navigateExecute在已有会话中导航到新页面
-
browser_start_sessionExecutebrowser_start_session
-
browser_type_textExecutebrowser_type_text
-
brutespray_attackExecutebrutespray_attack
-
bully_attackExecuteExecute bully for WPS attacks.
-
code_audit_comprehensiveExecutecode_audit_comprehensive
-
compile_task_handoffExecuteCompile handoff/progress for resume (do-not-rescan + next_actions).
-
comprehensive_reconExecutecomprehensive_recon
-
continue_from_handoffExecuteResume plan from last handoff without forcing full rescan.
-
create_attack_chainExecute创建攻击链。
-
cross_validate_vulnsExecute交叉验证黑盒和白盒发现的漏洞,提升置信度。
-
crowbar_attackExecutecrowbar_attack
-
ctf_pwn_solverExecutectf_pwn_solver
-
ctf_quick_scanExecuteCTF快速扫描 - 针对CTF环境优化的快速漏洞发现。
-
ctf_web_attackExecuteCTF Web攻击链 - 专门针对CTF Web题目的攻击。
-
detect_blind_vulnerabilityExecute盲注漏洞检测 - 基于响应差异
-
dirb_scanExecute使用 Dirb 执行目录枚举。
-
dnsenum_scanExecute使用 Dnsenum 执行 DNS 枚举。
-
dnsrecon_scanExecutednsrecon_scan
-
enum4linux_scanExecuteExecute Enum4linux Windows/Samba enumeration tool.
-
execute_commandExecuteExecute an arbitrary command on the Kali server.
-
fast_reconnaissanceExecute执行快速侦察工作流。
-
feroxbuster_scanExecute使用 Feroxbuster 执行目录与资源爆破。
-
ffuf_scanExecuteffuf_scan
-
fierce_scanExecute使用 Fierce 执行 DNS 侦察。
-
flawfinder_scanExecuteflawfinder_scan
-
fping_scanExecuteExecute fping for fast ping sweeps.
-
fuzz_all_paramsExecute全参数模糊测试 - 自动识别并测试所有参数
-
fuzz_parameterExecutefuzz_parameter
-
generate_attack_pathsExecute生成针对目标的APT攻击路径。
-
generate_poc_from_current_sessionExecute从当前活跃会话生成PoC - 无需指定会话ID,直接从当前会话生成。
-
generate_poc_from_sessionExecute从指定攻击会话生成PoC - 自动分析攻击链并生成多种格式的PoC。
-
ghidra_analyze_binaryExecute使用Ghidra分析二进制文件 - NSA开源逆向分析工具
-
gobuster_scanExecutegobuster_scan
-
grpc_callExecutegrpc_call
-
hashcat_crackExecutehashcat_crack
-
http_compareExecute比较两个HTTP响应的差异 - 用于盲注检测
-
http_replayExecute重放历史HTTP请求,可修改参数
-
http_sendExecutehttp_send
-
http_send_rawExecute发送原始HTTP请求 - 完全控制请求格式
-
http_session_manageExecutehttp_session_manage
-
httpx_probeExecutehttpx_probe
-
hydra_attackExecutehydra_attack
-
intelligent_apt_campaignExecute智能APT攻击活动 - 最高级别的自适应攻击。
-
issue_vulnerabilityExecuteissue_vulnerability
-
john_crackExecutejohn_crack
-
joomscan_scanExecuteExecute joomscan for Joomla security testing.
-
kali_runExecutekali_run
-
llm_auto_pentestExecutellm_auto_pentest
-
masscan_fast_scanExecutemasscan_fast_scan
-
medusa_attackExecute使用 Medusa 执行口令验证测试。
-
metasploit_runExecuteExecute a Metasploit module.
-
multi_target_execute_batchExecute批量执行多目标攻击任务
-
multi_target_orchestrateExecute执行多目标攻击编排
-
ncrack_attackExecute使用 Ncrack 执行网络服务凭据验证。
-
netdiscover_scanExecutenetdiscover_scan
-
nikto_scanExecuteExecute Nikto web server scanner.
-
nmap_scanExecutenmap_scan
-
nuclei_cve_scanExecuteExecute Nuclei CVE vulnerability scan.
-
nuclei_network_scanExecuteExecute Nuclei network security scan.
-
nuclei_scanExecutenuclei_scan
-
nuclei_technology_detectionExecuteExecute Nuclei technology detection scan.
-
nuclei_web_scanExecuteExecute Nuclei web application security scan.
-
parallel_directory_scanningExecute并行执行多个目标的目录扫描。
-
parallel_port_scanningExecute并行执行多个目标的端口扫描。
-
patator_attackExecutepatator_attack
-
pixiewps_attackExecutepixiewps_attack
-
proxy_startExecute启动代理服务器 - 用于流量拦截
-
pwn_comprehensive_attackExecutepwn_comprehensive_attack
-
quick_pwn_checkExecutequick_pwn_check
-
radare2_analyze_binaryExecute使用Radare2分析二进制文件 - 开源逆向分析工具
-
reaver_attackExecuteExecute Reaver for WPS PIN attacks.
-
recon_ng_runExecuteExecute recon-ng for reconnaissance.
-
run_playbookExecuteRun a named playbook (web_surface | api_surface | auth_surface | svc_surface).
-
run_surface_chainExecuterun_surface_chain
-
run_surface_chain_multiExecuterun_surface_chain_multi
-
scan_startExecuteStart a heavy scan in background; returns job_id immediately.
-
scan_waitExecuteBlock until an async scan job finishes or timeout_s elapses.
-
semgrep_scanExecutesemgrep_scan
-
sqlmap_scanExecuteExecute SQLmap SQL injection scanner.
-
start_adaptive_apt_attackExecutestart_adaptive_apt_attack
-
start_attack_sessionExecute开始新的攻击会话 - 启动自动日志记录和PoC生成。
-
start_taskExecuteCreate/open a task workspace and seed target graph nodes.
-
subfinder_scanExecuteExecute Subfinder for fast subdomain discovery.
-
submit_apt_attack_chainExecute提交APT攻击链工作流 - 基于知识图谱的智能化并发攻击。
-
submit_concurrent_taskExecute提交并发任务。
-
submit_workflowExecutesubmit_workflow
-
trigger_next_attack_phaseExecute手动触发下一攻击阶段 - 强制进入下一轮攻击。
-
verify_findingExecuteVerify a candidate finding by replaying command and matching expected_signal.
-
verify_vulnerabilityExecute验证候选漏洞 (candidate → verified/failed)。
-
wfuzz_scanExecute使用 Wfuzz 执行参数与路径模糊测试。
-
whatweb_scanExecutewhatweb_scan
-
workflow_executeExecute执行测试工作流
-
wpscan_scanExecutewpscan_scan
-
ws_connectExecute建立WebSocket连接
-
ws_fuzzExecuteWebSocket模糊测试
-
ws_sendExecutews_send
-
yersinia_attackExecuteyersinia_attack
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.