# Claude C2 MCP server

Agent View of the PolicyLayer registry record for Claude C2: identity, probed posture, risk grade, and all 94 tools classified. HTML page: https://policylayer.com/tools/0xyg3n-claude-c2

## Facts

- Server id: `0xyg3n/claude-c2`
- Homepage: https://github.com/0xyg3n/claude-c2
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 94
- Tool categories present: Destructive, Execute, Read, Write
- Tags: 0xyg3n claude c2, admin, automation
- Record last modified: 2026-06-12T07:11:38.071Z

## Tools (94)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `kill` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/kill.md |
| `mv` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/mv.md |
| `persist_remove` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/persist-remove.md |
| `reg_delete` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/reg-delete.md |
| `rm` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/rm.md |
| `timestomp` | Destructive | Critical | https://policylayer.com/tools/0xyg3n-claude-c2/timestomp.md |
| `amsi_bypass` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/amsi-bypass.md |
| `bypassuac` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/bypassuac.md |
| `defender_exclude` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/defender-exclude.md |
| `etw_patch` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/etw-patch.md |
| `execute_assembly` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/execute-assembly.md |
| `firewall_rule` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/firewall-rule.md |
| `generate_payload` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/generate-payload.md |
| `get_payload` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/get-payload.md |
| `getsystem` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/getsystem.md |
| `inject` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/inject.md |
| `keylog_start` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/keylog-start.md |
| `keylog_stop` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/keylog-stop.md |
| `mcp_add_tool` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-add-tool.md |
| `mcp_append_code` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-append-code.md |
| `mcp_restart` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-restart.md |
| `mimikatz` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/mimikatz.md |
| `persist_registry` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/persist-registry.md |
| `persist_schtask` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/persist-schtask.md |
| `persist_service` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/persist-service.md |
| `persist_startup` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/persist-startup.md |
| `persist_wmi` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/persist-wmi.md |
| `portscan` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/portscan.md |
| `powershell` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/powershell.md |
| `privesc_check` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/privesc-check.md |
| `psexec` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/psexec.md |
| `runas` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/runas.md |
| `send_remote_command` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/send-remote-command.md |
| `server_shell` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/server-shell.md |
| `shell` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/shell.md |
| `spawn` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/spawn.md |
| `ssh_exec` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/ssh-exec.md |
| `webcam` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/webcam.md |
| `winrm` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/winrm.md |
| `wmiexec` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/wmiexec.md |
| `zip` | Execute | High | https://policylayer.com/tools/0xyg3n-claude-c2/zip.md |
| `browser_creds` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/browser-creds.md |
| `cat` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/cat.md |
| `client_info` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/client-info.md |
| `clipboard` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/clipboard.md |
| `defender_status` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/defender-status.md |
| `domain_info` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/domain-info.md |
| `download` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/download.md |
| `firewall_status` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/firewall-status.md |
| `hashdump` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/hashdump.md |
| `help` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/help.md |
| `installed_software` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/installed-software.md |
| `keylog_dump` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/keylog-dump.md |
| `list_clients` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/list-clients.md |
| `list_payloads` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/list-payloads.md |
| `list_remote_clients` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/list-remote-clients.md |
| `local_users` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/local-users.md |
| `loot_download` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/loot-download.md |
| `loot_list` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/loot-list.md |
| `ls` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/ls.md |
| `mcp_backup` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-backup.md |
| `mcp_list_source` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-list-source.md |
| `mcp_logs` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-logs.md |
| `mcp_read_source` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-read-source.md |
| `netinfo` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/netinfo.md |
| `netscan` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/netscan.md |
| `persist_list` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/persist-list.md |
| `project_info` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/project-info.md |
| `ps` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/ps.md |
| `pslist` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/pslist.md |
| `reg_read` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/reg-read.md |
| `scheduled_tasks` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/scheduled-tasks.md |
| `screenshot` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/screenshot.md |
| `search` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/search.md |
| `server_file_list` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/server-file-list.md |
| `server_file_read` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/server-file-read.md |
| `server_info` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/server-info.md |
| `services` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/services.md |
| `shares` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/shares.md |
| `startup_programs` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/startup-programs.md |
| `sysinfo` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/sysinfo.md |
| `tool_docs` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/tool-docs.md |
| `vault_creds` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/vault-creds.md |
| `wifi_passwords` | Read | Low | https://policylayer.com/tools/0xyg3n-claude-c2/wifi-passwords.md |
| `cp` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/cp.md |
| `mcp_config` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-config.md |
| `mcp_edit_code` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-edit-code.md |
| `mcp_restore` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-restore.md |
| `mcp_write_file` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/mcp-write-file.md |
| `mkdir` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/mkdir.md |
| `reg_write` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/reg-write.md |
| `server_file_write` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/server-file-write.md |
| `upload` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/upload.md |
| `write` | Write | Medium | https://policylayer.com/tools/0xyg3n-claude-c2/write.md |

## Tool descriptions

- `kill` — Kill process. Auto-selects client.
- `mv` — Move/rename file. Auto-selects client.
- `persist_remove` — Remove persistence. Auto-selects client.
- `reg_delete` — Delete registry key/value. Auto-selects client.
- `rm` — Delete file/directory. Auto-selects client.
- `timestomp` — Modify file timestamps. Auto-selects client.
- `amsi_bypass` — Bypass AMSI. Auto-selects client.
- `bypassuac` — UAC bypass. Auto-selects client.
- `defender_exclude` — Add Defender exclusion. Auto-selects client.
- `etw_patch` — Patch ETW logging. Auto-selects client.
- `execute_assembly` — Load and execute .NET assembly in memory. Auto-selects client if only one connected.
- `firewall_rule` — Manage firewall rule. Auto-selects client.
- `generate_payload` — Generate customized payload with specific options
- `get_payload` — Get agent payload/implant for a specific platform
- `getsystem` — Get SYSTEM privileges. Auto-selects client.
- `inject` — Inject shellcode. Auto-selects client.
- `keylog_start` — Start keylogger. Auto-selects client.
- `keylog_stop` — Stop keylogger. Auto-selects client.
- `mcp_add_tool` — Add a new MCP tool dynamically (adds to tools list and handler)
- `mcp_append_code` — Append code to MCP server file
- `mcp_restart` — Restart the MCP server to apply code changes
- `mimikatz` — Run Mimikatz command. Auto-selects client.
- `persist_registry` — Registry run key persistence. Auto-selects client.
- `persist_schtask` — Scheduled task persistence. Auto-selects client.
- `persist_service` — Install as Windows service. Auto-selects client.
- `persist_startup` — Add to startup folder. Auto-selects client.
- `persist_wmi` — WMI event subscription persistence. Auto-selects client.
- `portscan` — Port scan target. Auto-selects client.
- `powershell` — Execute PowerShell command on Windows client. Auto-selects client if only one connected.
- `privesc_check` — Check privesc vectors. Auto-selects client.
- `psexec` — PsExec remote execution. Auto-selects client.
- `runas` — Run as different user. Auto-selects client.
- `send_remote_command` — Send a command to a remote client
- `server_shell` — Execute any shell command on C2 server (bash, no sandbox, full permissions). Use sudo for privileged ops.
- `shell` — Execute shell command on remote client (cmd.exe on Windows, /bin/sh on Linux). If only one client connected, client_id is auto-selected.
- `spawn` — Spawn process. Auto-selects client.
- `ssh_exec` — SSH remote execution. Auto-selects client.
- `webcam` — Capture webcam photo. Auto-selects client.
- `winrm` — WinRM remote execution. Auto-selects client.
- `wmiexec` — WMI remote execution. Auto-selects client.
- `zip` — Compress to zip. Auto-selects client.
- `browser_creds` — Extract browser passwords. Auto-selects client.
- `cat` — Read file contents. Auto-selects client.
- `client_info` — Get detailed info about a specific client
- `clipboard` — Get clipboard contents. Auto-selects client.
- `defender_status` — Get Defender status. Auto-selects client.
- `domain_info` — Get AD domain info. Auto-selects client.
- `download` — Download file from client to C2. Auto-selects client.
- `firewall_status` — Get firewall status. Auto-selects client.
- `hashdump` — Dump password hashes (requires admin). Auto-selects client.
- `help` — Get help about Claude C2 - shows available commands, usage, and documentation
- `installed_software` — List installed programs. Auto-selects client.
- `keylog_dump` — Get captured keystrokes. Auto-selects client.
- `list_clients` — List all connected remote clients/implants
- `list_payloads` — List all available payload types and platforms
- `list_remote_clients` — List all connected remote clients
- `local_users` — List local users/groups. Auto-selects client.
- `loot_download` — Download loot file
- `loot_list` — List collected loot/exfiltrated data
- `ls` — List directory. Auto-selects client.
- `mcp_backup` — Backup MCP server files before editing
- `mcp_list_source` — List all source files in MCP project
- `mcp_logs` — Get MCP server logs
- `mcp_read_source` — Read MCP server source code files
- `netinfo` — Get network config (IPs, routes, connections). Auto-selects client.
- `netscan` — Scan network for hosts. Auto-selects client.
- `persist_list` — List persistence mechanisms. Auto-selects client.
- `project_info` — Get complete project structure, architecture, and codebase knowledge for making modifications
- `ps` — List processes. Auto-selects client.
- `pslist` — List running processes. Auto-selects client.
- `reg_read` — Read registry value. Auto-selects client.
- `scheduled_tasks` — List scheduled tasks. Auto-selects client.
- `screenshot` — Take screenshot. Auto-selects client.
- `search` — Search files by pattern. Auto-selects client.
- `server_file_list` — List directory on C2 server
- `server_file_read` — Read any file from C2 server
- `server_info` — Get C2 server system info
- `services` — List Windows services. Auto-selects client.
- `shares` — List network shares. Auto-selects client.
- `startup_programs` — List startup programs. Auto-selects client.
- `sysinfo` — Get system info (OS, hardware, domain). Auto-selects client.
- `tool_docs` — Get detailed documentation for a specific tool or category
- `vault_creds` — Get Windows Vault credentials. Auto-selects client.
- `wifi_passwords` — Get saved WiFi passwords. Auto-selects client.
- `cp` — Copy file. Auto-selects client.
- `mcp_config` — Read or update MCP server configuration
- `mcp_edit_code` — Edit MCP server code using find/replace
- `mcp_restore` — Restore MCP server from backup
- `mcp_write_file` — Write/overwrite entire file in MCP project
- `mkdir` — Create directory. Auto-selects client.
- `reg_write` — Write registry value. Auto-selects client.
- `server_file_write` — Write file to C2 server (auto-creates parent dirs)
- `upload` — Upload file to client. Auto-selects client.
- `write` — Write to file. Auto-selects client.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (813 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- MCP Framework Personal (643 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xyg3n-claude-c2 · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/0xyg3n-claude-c2
