High-risk tools in Zebbern Kali MCP
83 of the 128 tools in Zebbern Kali MCP are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
api_newman_runExecuteRun a Postman/Newman collection against API endpoints.
-
callback_startExecutecallback_start
-
callback_stopExecutecallback_stop
-
callback_waitExecutecallback_wait
-
msf_session_executeExecutemsf_session_execute
-
parse_tool_outputExecuteparse_tool_output
-
payload_host_startExecuteStart HTTP server to host generated payloads for download.
-
payload_host_stopExecuteStop the payload hosting server.
-
pivot_chisel_clientExecuteStart a Chisel client to connect to a Chisel server.
-
pivot_chisel_serverExecuteStart a Chisel server for tunneling.
-
pivot_ligolo_startExecuteStart a Ligolo-ng proxy server for pivoting.
-
pivot_stop_all_tunnelsExecuteStop all active tunnels and port forwards.
-
pivot_stop_tunnelExecuteStop a specific tunnel.
-
reverse_shell_listener_startExecutereverse_shell_listener_start
-
reverse_shell_stopExecuteStop a reverse shell session.
-
ssh_session_startExecutessh_session_start
-
ssh_session_stopExecuteStop/disconnect an SSH session.
-
tools_assetfinderExecuteExecute Assetfinder for asset discovery.
-
tools_byp4xxExecuteExecute byp4xx for 403 bypass testing.
-
tools_enum4linuxExecuteExecute Enum4linux Windows/Samba enumeration tool.
-
tools_fierceExecuteExecute Fierce for DNS reconnaissance.
-
tools_httpxExecuteExecute httpx for HTTP probing.
-
tools_johnExecuteExecute John the Ripper password cracker.
-
tools_subfinderExecuteExecute Subfinder for subdomain enumeration.
-
tools_subzyExecuteExecute Subzy for subdomain takeover detection.
-
tools_waybackurlsExecuteExecute waybackurls to fetch URLs from Wayback Machine.
-
ad_asreproastExecutePerform AS-REP Roasting to get hashes for accounts with pre-auth disabled.
-
ad_bloodhound_collectExecutead_bloodhound_collect
-
ad_kerberoastExecutead_kerberoast
-
ad_password_sprayExecutead_password_spray
-
ad_psexecExecutead_psexec
-
ad_secretsdumpExecutead_secretsdump
-
ad_wmiexecExecutead_wmiexec
-
api_auth_bypass_testExecuteTest for authentication bypass vulnerabilities.
-
api_ffuf_fuzzExecuteapi_ffuf_fuzz
-
api_fuzz_endpointExecuteapi_fuzz_endpoint
-
api_graphql_fuzzExecuteFuzz a GraphQL endpoint for vulnerabilities.
-
api_jwt_crackExecuteAttempt to crack a JWT token's signing secret.
-
api_kiterunner_scanExecuteScan API endpoints using Kiterunner for route discovery.
-
api_nuclei_scanExecuteRun Nuclei templates against API endpoints.
-
api_rate_limit_testExecuteTest API rate limiting controls.
-
callback_checkExecutecallback_check
-
callback_latestExecutecallback_latest
-
cve_searchExecutecve_search
-
exec_streamExecuteexec_stream
-
exploit_suggest_for_serviceExecuteGet exploit suggestions for a specific service.
-
exploit_suggest_from_nmapExecuteAnalyze nmap scan output and suggest exploits for discovered services.
-
fingerprint_wafExecuteDetect Web Application Firewall (WAF) on a target URL.
-
payload_one_linerExecutepayload_one_liner
-
pivot_ssh_localExecutepivot_ssh_local
-
pivot_ssh_remoteExecutepivot_ssh_remote
-
reverse_shell_commandExecutereverse_shell_command
-
reverse_shell_download_contentExecuteDownload file content from target via reverse shell and return as base64.
-
ssh_session_commandExecutessh_session_command
-
tools_amassExecutetools_amass
-
tools_arjunExecutetools_arjun
-
tools_gobusterExecutetools_gobuster
-
tools_gowitnessExecutetools_gowitness
-
tools_hydraExecutetools_hydra
-
tools_katanaExecutetools_katana
-
tools_masscanExecutetools_masscan
-
tools_niktoExecutetools_nikto
-
tools_nmapExecutetools_nmap
-
tools_sqlmapExecutetools_sqlmap
-
tools_ssh_auditExecutetools_ssh_audit
-
tools_sslscanExecutetools_sslscan
-
tools_wpscanExecutetools_wpscan
-
zebbern_execExecutezebbern_exec
-
callback_generateExecutecallback_generate
-
ctf_connectExecutectf_connect
-
msf_session_createExecuteCreate a new persistent Metasploit (msfconsole) session.
-
payload_generateExecutepayload_generate
-
pivot_add_pivotExecutepivot_add_pivot
-
pivot_generate_proxychainsExecuteGenerate a proxychains configuration for pivoting through SOCKS proxy.
-
pivot_socat_forwardExecuteCreate a socat port forward.
-
pivot_ssh_dynamicExecuteCreate an SSH dynamic SOCKS proxy.
-
reverse_shell_generate_payloadExecutereverse_shell_generate_payload
-
reverse_shell_send_payloadExecutereverse_shell_send_payload
-
reverse_shell_upload_contentExecutereverse_shell_upload_content
-
send_inputExecutesend_input
-
ssh_session_upload_contentExecutessh_session_upload_content
-
vpn_connectExecutevpn_connect
-
vpn_disconnectExecutevpn_disconnect
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.