More Than 350 Commands, 14 Categories, One Health-Checked Toolchain
CoordOps does not treat security tooling as a disconnected collection of shortcuts. It provides a structured command layer that connects established external tools to the active engagement, its authorized targets, execution history, parsed results, and supporting evidence.
The current catalog contains 368 command entries: 274 packaged command definitions, 91 purpose-built Nmap commands, and several specialized workflows with custom execution behavior. Commands are classified using a 14-category model covering Enumeration, Vulnerability Scanning, Exploitation, Web, Stress Testing, Forensics, Wireless, Sniffing and Spoofing, Password Operations, Maintaining Access, Reverse Engineering, Reporting, Hardware, and Dynamic workflows.
The Nmap catalog alone contains 91 individually modeled commands covering host discovery, service enumeration, protocol-specific checks, vulnerability scripts, Active Directory services, databases, industrial and specialized network technologies, and different scanning strategies. These are separate command definitions rather than one generic Nmap textbox, allowing each workflow to carry its own purpose, parameters, parser, and expected output behavior.
Each command can include a description, example usage, target and parameter placeholders, platform requirements, required executables, parser selection, and installation metadata. Before execution, CoordOps resolves the engagement-specific values and keeps the resulting command visible so the operator can review what will run.
Higher-level tools receive dedicated CoordOps interfaces rather than being reduced to generic command boxes. These integrated workspaces include Nmap, Nuclei, OpenVAS/GVM, SQLMap, Wfuzz, Dalfox, RESTler, Schemathesis, MSFVenom, GoLismero, Certipy, BloodHound CE, NetExec, Coercer, Impacket, Kerbrute, LDAP Query, Responder, network mapping, tunneling tools, and other engagement utilities.
These dedicated interfaces add tool-specific validation and workflows while retaining the underlying command. Depending on the integration, results can be streamed into the session, parsed into hosts, services, findings, shares, or Active Directory data, and retained with the execution record instead of being left in an unrelated terminal window.
CoordOps continuously checks whether the executables required by those workflows are available in the selected execution environment. Native Windows and Linux tools are resolved through their local executable paths, while WSL tools are checked inside the selected distribution. Availability results are cached and persisted globally, giving newly opened sessions an immediate status while a background scan verifies the current environment.
The availability system distinguishes between four meaningful states: not yet checked, currently checking, available, and unavailable. A probe that times out or cannot run is not incorrectly reported as proof that the tool is missing. This distinction prevents temporary WSL, process, or environment problems from poisoning the saved availability state.
A missing executable is not treated as a permanent failure. CoordOps retries confirmed missing dependencies on a controlled schedule—hourly by default—while avoiding repeated process launches or filesystem searches during every interface update. Availability checks run in the background at reduced priority so they do not interrupt the operator’s active work.
The same toolchain contains 50 supported tool preparation definitions covering assessment utilities, Active Directory tooling, web scanners, tunneling software, browser automation, password tools, wireless and RF utilities, databases, and supporting services. Depending on the tool and its distribution requirements, CoordOps may provide automated installation, verify an existing installation, manage a local tool package, or direct the operator to an approved manual setup process.
This distinction matters for security tooling that endpoint protection may classify or that an organization may require operators to obtain through an approved source. CoordOps does not assume that silently downloading every missing executable is appropriate. Availability checking, installation support, and execution remain separate decisions under the operator’s control.
The result is more than Kali integration or a large command list. It is an operational layer that connects established security tools to a consistent CoordOps workflow while leaving the underlying commands visible, auditable, and under the operator’s control. Before a workflow begins, operators can understand what it will run, whether its dependencies are ready, where it will execute, and how its results will return to the engagement record.