# Hexstrike Ai MCP server

Agent View of the PolicyLayer registry record for Hexstrike Ai: identity, probed posture, risk grade, and all 150 tools classified. HTML page: https://policylayer.com/tools/hexstrike-ai

## Facts

- Server id: `0x4m4/hexstrike-ai`
- Homepage: https://github.com/0x4m4/hexstrike-ai
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 150
- Tool categories present: Destructive, Execute, Read, Write
- Tags: hexstrike ai, admin, automation
- Record last modified: 2026-07-07T04:47:56.673Z

## Tools (150)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `clear_cache` | Destructive | Critical | https://policylayer.com/tools/hexstrike-ai/clear-cache.md |
| `delete_file` | Destructive | Critical | https://policylayer.com/tools/hexstrike-ai/delete-file.md |
| `advanced_payload_generation` | Execute | High | https://policylayer.com/tools/hexstrike-ai/advanced-payload-generation.md |
| `ai_generate_attack_suite` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ai-generate-attack-suite.md |
| `ai_generate_payload` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ai-generate-payload.md |
| `ai_reconnaissance_workflow` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ai-reconnaissance-workflow.md |
| `ai_test_payload` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ai-test-payload.md |
| `ai_vulnerability_assessment` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ai-vulnerability-assessment.md |
| `amass_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/amass-scan.md |
| `angr_symbolic_execution` | Execute | High | https://policylayer.com/tools/hexstrike-ai/angr-symbolic-execution.md |
| `api_fuzzer` | Execute | High | https://policylayer.com/tools/hexstrike-ai/api-fuzzer.md |
| `arjun_parameter_discovery` | Execute | High | https://policylayer.com/tools/hexstrike-ai/arjun-parameter-discovery.md |
| `arjun_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/arjun-scan.md |
| `arp_scan_discovery` | Execute | High | https://policylayer.com/tools/hexstrike-ai/arp-scan-discovery.md |
| `autorecon_comprehensive` | Execute | High | https://policylayer.com/tools/hexstrike-ai/autorecon-comprehensive.md |
| `autorecon_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/autorecon-scan.md |
| `binwalk_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/binwalk-analyze.md |
| `browser_agent_inspect` | Execute | High | https://policylayer.com/tools/hexstrike-ai/browser-agent-inspect.md |
| `bugbounty_authentication_bypass_testing` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-authentication-bypass-testing.md |
| `bugbounty_business_logic_testing` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-business-logic-testing.md |
| `bugbounty_comprehensive_assessment` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-comprehensive-assessment.md |
| `bugbounty_file_upload_testing` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-file-upload-testing.md |
| `bugbounty_osint_gathering` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-osint-gathering.md |
| `bugbounty_reconnaissance_workflow` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-reconnaissance-workflow.md |
| `bugbounty_vulnerability_hunting` | Execute | High | https://policylayer.com/tools/hexstrike-ai/bugbounty-vulnerability-hunting.md |
| `burpsuite_alternative_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/burpsuite-alternative-scan.md |
| `burpsuite_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/burpsuite-scan.md |
| `checkov_iac_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/checkov-iac-scan.md |
| `clair_vulnerability_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/clair-vulnerability-scan.md |
| `comprehensive_api_audit` | Execute | High | https://policylayer.com/tools/hexstrike-ai/comprehensive-api-audit.md |
| `create_attack_chain_ai` | Execute | High | https://policylayer.com/tools/hexstrike-ai/create-attack-chain-ai.md |
| `dalfox_xss_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/dalfox-xss-scan.md |
| `dirb_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/dirb-scan.md |
| `dirsearch_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/dirsearch-scan.md |
| `discover_attack_chains` | Execute | High | https://policylayer.com/tools/hexstrike-ai/discover-attack-chains.md |
| `docker_bench_security_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/docker-bench-security-scan.md |
| `dotdotpwn_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/dotdotpwn-scan.md |
| `enum4linux_ng_advanced` | Execute | High | https://policylayer.com/tools/hexstrike-ai/enum4linux-ng-advanced.md |
| `enum4linux_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/enum4linux-scan.md |
| `execute_command` | Execute | High | https://policylayer.com/tools/hexstrike-ai/execute-command.md |
| `execute_python_script` | Execute | High | https://policylayer.com/tools/hexstrike-ai/execute-python-script.md |
| `falco_runtime_monitoring` | Execute | High | https://policylayer.com/tools/hexstrike-ai/falco-runtime-monitoring.md |
| `feroxbuster_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/feroxbuster-scan.md |
| `ffuf_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ffuf-scan.md |
| `fierce_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/fierce-scan.md |
| `gdb_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/gdb-analyze.md |
| `gdb_peda_debug` | Execute | High | https://policylayer.com/tools/hexstrike-ai/gdb-peda-debug.md |
| `generate_exploit_from_cve` | Execute | High | https://policylayer.com/tools/hexstrike-ai/generate-exploit-from-cve.md |
| `generate_payload` | Execute | High | https://policylayer.com/tools/hexstrike-ai/generate-payload.md |
| `ghidra_analysis` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ghidra-analysis.md |
| `gobuster_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/gobuster-scan.md |
| `graphql_scanner` | Execute | High | https://policylayer.com/tools/hexstrike-ai/graphql-scanner.md |
| `hashcat_crack` | Execute | High | https://policylayer.com/tools/hexstrike-ai/hashcat-crack.md |
| `hashpump_attack` | Execute | High | https://policylayer.com/tools/hexstrike-ai/hashpump-attack.md |
| `http_framework_test` | Execute | High | https://policylayer.com/tools/hexstrike-ai/http-framework-test.md |
| `http_intruder` | Execute | High | https://policylayer.com/tools/hexstrike-ai/http-intruder.md |
| `http_repeater` | Execute | High | https://policylayer.com/tools/hexstrike-ai/http-repeater.md |
| `http_set_rules` | Execute | High | https://policylayer.com/tools/hexstrike-ai/http-set-rules.md |
| `httpx_probe` | Execute | High | https://policylayer.com/tools/hexstrike-ai/httpx-probe.md |
| `hydra_attack` | Execute | High | https://policylayer.com/tools/hexstrike-ai/hydra-attack.md |
| `install_python_package` | Execute | High | https://policylayer.com/tools/hexstrike-ai/install-python-package.md |
| `intelligent_smart_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/intelligent-smart-scan.md |
| `jaeles_vulnerability_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/jaeles-vulnerability-scan.md |
| `john_crack` | Execute | High | https://policylayer.com/tools/hexstrike-ai/john-crack.md |
| `katana_crawl` | Execute | High | https://policylayer.com/tools/hexstrike-ai/katana-crawl.md |
| `kube_bench_cis` | Execute | High | https://policylayer.com/tools/hexstrike-ai/kube-bench-cis.md |
| `kube_hunter_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/kube-hunter-scan.md |
| `masscan_high_speed` | Execute | High | https://policylayer.com/tools/hexstrike-ai/masscan-high-speed.md |
| `metasploit_run` | Execute | High | https://policylayer.com/tools/hexstrike-ai/metasploit-run.md |
| `msfvenom_generate` | Execute | High | https://policylayer.com/tools/hexstrike-ai/msfvenom-generate.md |
| `netexec_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/netexec-scan.md |
| `nikto_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/nikto-scan.md |
| `nmap_advanced_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/nmap-advanced-scan.md |
| `nmap_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/nmap-scan.md |
| `nuclei_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/nuclei-scan.md |
| `objdump_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/objdump-analyze.md |
| `one_gadget_search` | Execute | High | https://policylayer.com/tools/hexstrike-ai/one-gadget-search.md |
| `optimize_tool_parameters_ai` | Execute | High | https://policylayer.com/tools/hexstrike-ai/optimize-tool-parameters-ai.md |
| `pacu_exploitation` | Execute | High | https://policylayer.com/tools/hexstrike-ai/pacu-exploitation.md |
| `paramspider_discovery` | Execute | High | https://policylayer.com/tools/hexstrike-ai/paramspider-discovery.md |
| `paramspider_mining` | Execute | High | https://policylayer.com/tools/hexstrike-ai/paramspider-mining.md |
| `prowler_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/prowler-scan.md |
| `pwninit_setup` | Execute | High | https://policylayer.com/tools/hexstrike-ai/pwninit-setup.md |
| `pwntools_exploit` | Execute | High | https://policylayer.com/tools/hexstrike-ai/pwntools-exploit.md |
| `qsreplace_parameter_replacement` | Execute | High | https://policylayer.com/tools/hexstrike-ai/qsreplace-parameter-replacement.md |
| `radare2_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/radare2-analyze.md |
| `research_zero_day_opportunities` | Execute | High | https://policylayer.com/tools/hexstrike-ai/research-zero-day-opportunities.md |
| `responder_credential_harvest` | Execute | High | https://policylayer.com/tools/hexstrike-ai/responder-credential-harvest.md |
| `resume_process` | Execute | High | https://policylayer.com/tools/hexstrike-ai/resume-process.md |
| `ropgadget_search` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ropgadget-search.md |
| `ropper_gadget_search` | Execute | High | https://policylayer.com/tools/hexstrike-ai/ropper-gadget-search.md |
| `rpcclient_enumeration` | Execute | High | https://policylayer.com/tools/hexstrike-ai/rpcclient-enumeration.md |
| `rustscan_fast_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/rustscan-fast-scan.md |
| `scout_suite_assessment` | Execute | High | https://policylayer.com/tools/hexstrike-ai/scout-suite-assessment.md |
| `select_optimal_tools_ai` | Execute | High | https://policylayer.com/tools/hexstrike-ai/select-optimal-tools-ai.md |
| `smbmap_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/smbmap-scan.md |
| `sqlmap_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/sqlmap-scan.md |
| `terrascan_iac_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/terrascan-iac-scan.md |
| `threat_hunting_assistant` | Execute | High | https://policylayer.com/tools/hexstrike-ai/threat-hunting-assistant.md |
| `trivy_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/trivy-scan.md |
| `volatility_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/volatility-analyze.md |
| `volatility3_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/volatility3-analyze.md |
| `wafw00f_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/wafw00f-scan.md |
| `wfuzz_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/wfuzz-scan.md |
| `wpscan_analyze` | Execute | High | https://policylayer.com/tools/hexstrike-ai/wpscan-analyze.md |
| `x8_parameter_discovery` | Execute | High | https://policylayer.com/tools/hexstrike-ai/x8-parameter-discovery.md |
| `xsser_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/xsser-scan.md |
| `zap_scan` | Execute | High | https://policylayer.com/tools/hexstrike-ai/zap-scan.md |
| `anew_data_processing` | Other | Low | https://policylayer.com/tools/hexstrike-ai/anew-data-processing.md |
| `analyze_target_intelligence` | Read | Low | https://policylayer.com/tools/hexstrike-ai/analyze-target-intelligence.md |
| `api_schema_analyzer` | Read | Low | https://policylayer.com/tools/hexstrike-ai/api-schema-analyzer.md |
| `checksec_analyze` | Read | Low | https://policylayer.com/tools/hexstrike-ai/checksec-analyze.md |
| `cloudmapper_analysis` | Read | Low | https://policylayer.com/tools/hexstrike-ai/cloudmapper-analysis.md |
| `correlate_threat_intelligence` | Read | Low | https://policylayer.com/tools/hexstrike-ai/correlate-threat-intelligence.md |
| `create_scan_summary` | Read | Low | https://policylayer.com/tools/hexstrike-ai/create-scan-summary.md |
| `detect_technologies_ai` | Read | Low | https://policylayer.com/tools/hexstrike-ai/detect-technologies-ai.md |
| `display_system_metrics` | Read | Low | https://policylayer.com/tools/hexstrike-ai/display-system-metrics.md |
| `dnsenum_scan` | Read | Low | https://policylayer.com/tools/hexstrike-ai/dnsenum-scan.md |
| `error_handling_statistics` | Read | Low | https://policylayer.com/tools/hexstrike-ai/error-handling-statistics.md |
| `exiftool_extract` | Read | Low | https://policylayer.com/tools/hexstrike-ai/exiftool-extract.md |
| `foremost_carving` | Read | Low | https://policylayer.com/tools/hexstrike-ai/foremost-carving.md |
| `format_tool_output_visual` | Read | Low | https://policylayer.com/tools/hexstrike-ai/format-tool-output-visual.md |
| `gau_discovery` | Read | Low | https://policylayer.com/tools/hexstrike-ai/gau-discovery.md |
| `get_cache_stats` | Read | Low | https://policylayer.com/tools/hexstrike-ai/get-cache-stats.md |
| `get_live_dashboard` | Read | Low | https://policylayer.com/tools/hexstrike-ai/get-live-dashboard.md |
| `get_process_dashboard` | Read | Low | https://policylayer.com/tools/hexstrike-ai/get-process-dashboard.md |
| `get_process_status` | Read | Low | https://policylayer.com/tools/hexstrike-ai/get-process-status.md |
| `get_telemetry` | Read | Low | https://policylayer.com/tools/hexstrike-ai/get-telemetry.md |
| `hakrawler_crawl` | Read | Low | https://policylayer.com/tools/hexstrike-ai/hakrawler-crawl.md |
| `jwt_analyzer` | Read | Low | https://policylayer.com/tools/hexstrike-ai/jwt-analyzer.md |
| `libc_database_lookup` | Read | Low | https://policylayer.com/tools/hexstrike-ai/libc-database-lookup.md |
| `list_active_processes` | Read | Low | https://policylayer.com/tools/hexstrike-ai/list-active-processes.md |
| `list_files` | Read | Low | https://policylayer.com/tools/hexstrike-ai/list-files.md |
| `monitor_cve_feeds` | Read | Low | https://policylayer.com/tools/hexstrike-ai/monitor-cve-feeds.md |
| `nbtscan_netbios` | Read | Low | https://policylayer.com/tools/hexstrike-ai/nbtscan-netbios.md |
| `pause_process` | Read | Low | https://policylayer.com/tools/hexstrike-ai/pause-process.md |
| `server_health` | Read | Low | https://policylayer.com/tools/hexstrike-ai/server-health.md |
| `steghide_analysis` | Read | Low | https://policylayer.com/tools/hexstrike-ai/steghide-analysis.md |
| `strings_extract` | Read | Low | https://policylayer.com/tools/hexstrike-ai/strings-extract.md |
| `subfinder_scan` | Read | Low | https://policylayer.com/tools/hexstrike-ai/subfinder-scan.md |
| `test_error_recovery` | Read | Low | https://policylayer.com/tools/hexstrike-ai/test-error-recovery.md |
| `uro_url_filtering` | Read | Low | https://policylayer.com/tools/hexstrike-ai/uro-url-filtering.md |
| `vulnerability_intelligence_dashboard` | Read | Low | https://policylayer.com/tools/hexstrike-ai/vulnerability-intelligence-dashboard.md |
| `waybackurls_discovery` | Read | Low | https://policylayer.com/tools/hexstrike-ai/waybackurls-discovery.md |
| `xxd_hexdump` | Read | Low | https://policylayer.com/tools/hexstrike-ai/xxd-hexdump.md |
| `create_file` | Write | Medium | https://policylayer.com/tools/hexstrike-ai/create-file.md |
| `create_vulnerability_report` | Write | Medium | https://policylayer.com/tools/hexstrike-ai/create-vulnerability-report.md |
| `http_set_scope` | Write | Medium | https://policylayer.com/tools/hexstrike-ai/http-set-scope.md |
| `modify_file` | Write | Medium | https://policylayer.com/tools/hexstrike-ai/modify-file.md |
| `terminate_process` | Write | Medium | https://policylayer.com/tools/hexstrike-ai/terminate-process.md |

## Tool descriptions

- `clear_cache` — Clear the cache on the HexStrike AI server.
- `delete_file` — Delete a file or directory on the HexStrike server.
- `ai_generate_attack_suite` — Generate comprehensive attack suite with multiple payload types.
- `amass_scan` — Execute Amass for subdomain enumeration with enhanced logging.
- `bugbounty_file_upload_testing` — Create file upload vulnerability testing workflow with bypass techniques.
- `bugbounty_osint_gathering` — Create OSINT (Open Source Intelligence) gathering workflow for bug bounty reconnaissance.
- `dirb_scan` — Execute Dirb for directory brute forcing with enhanced logging.
- `enum4linux_scan` — Execute Enum4linux for SMB enumeration with enhanced logging.
- `execute_command` — Execute an arbitrary command on the HexStrike AI server with enhanced logging.
- `fierce_scan` — Execute fierce for DNS reconnaissance with enhanced logging.
- `http_intruder` — Simple Intruder (sniper) fuzzing. Iterates payloads over each param individually.
- `http_repeater` — Send a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data.
- `http_set_rules` — Set match/replace rules used to rewrite parts of URL/query/headers/body before sending.
- `install_python_package` — Install a Python package in a virtual environment on the HexStrike server.
- `metasploit_run` — Execute a Metasploit module with enhanced logging.
- `nikto_scan` — Execute Nikto web vulnerability scanner with enhanced logging.
- `resume_process` — Resume a paused process.
- `sqlmap_scan` — Execute SQLMap for SQL injection testing with enhanced logging.
- `wafw00f_scan` — Execute wafw00f to identify and fingerprint WAF products with enhanced logging.
- `wpscan_analyze` — Execute WPScan for WordPress vulnerability scanning with enhanced logging.
- `xsser_scan` — Execute XSSer for XSS vulnerability testing with enhanced logging.
- `analyze_target_intelligence` — Analyze target using AI-powered intelligence to create comprehensive profile.
- `checksec_analyze` — Check security features of a binary with enhanced logging.
- `detect_technologies_ai` — Use AI to detect technologies and provide technology-specific testing recommendations.
- `display_system_metrics` — Display current system metrics and performance indicators with visual formatting.
- `error_handling_statistics` — Get intelligent error handling system statistics and recent error patterns.
- `get_cache_stats` — Get cache statistics from the HexStrike AI server.
- `get_live_dashboard` — Get a beautiful live dashboard showing all active processes with enhanced visual formatting.
- `get_process_dashboard` — Get enhanced process dashboard with visual status indicators.
- `get_process_status` — Get the status of a specific process.
- `get_telemetry` — Get system telemetry from the HexStrike AI server.
- `list_active_processes` — List all active processes on the HexStrike AI server.
- `list_files` — List files in a directory on the HexStrike server.
- `pause_process` — Pause a specific running process.
- `server_health` — Check the health status of the HexStrike AI server.
- `strings_extract` — Extract strings from a binary file with enhanced logging.
- `create_file` — Create a file with specified content on the HexStrike server.
- `http_set_scope` — Define in-scope host (and optionally subdomains) so out-of-scope requests are skipped.
- `terminate_process` — Terminate a specific running process.

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (811 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md
- TinyFn (572 tools) — https://policylayer.com/tools/io-tinyfn-tinyfn.md
- Mcp (571 tools) — https://policylayer.com/tools/io-github-2s-io-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=hexstrike-ai · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/hexstrike-ai
