{"repo":"RedTeamPentesting/pretender","free":true,"listed":false,"github":"https://github.com/RedTeamPentesting/pretender","clone":"git clone https://github.com/RedTeamPentesting/pretender.git","description":"Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.","language":"Go","stars":1297,"topics":["go","mdns","dns","llmnr","netbios","security","dhcpv6","spoofer","pentesting","pretender"],"license":"MIT","category":"security-tools","readme_excerpt":"pretender Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing --- pretender is a tool developed by RedTeam Pentesting to obtain machine-in-the-middle positions via spoofed local name resolution and DHCPv6 DNS takeover attacks. pretender primarily targets Windows hosts, as it is intended to be used for relaying attacks but can be deployed on Linux, Windows and all other platforms Go supports. Name resolution queries can be answered with arbitrary IPs for situations where the relaying tool runs on a different host than pretender . It is designed to work with tools such as Impacket's ntlmrelayx.py and krbrelayx that handle the incoming connections for relaying attacks or hash dumping. Read our blog post for more information about DHCPv6 DNS takeover, local name resolution spoofing and relay attacks. --- Usage To get a feel for the situation in the local network, pretender can be started in --dry mode where it only logs incoming queries and does not answer any of them: To perform local name resolution spoofing via mDNS, LLMNR and NetBIOS-NS as well as a DHCPv6 DNS takeover with router advertisements, simply run pretender like this: You can disable certain attacks with --no-dhcp-dns (disabled DHCPv6, DNS and router advertisements), --no-lnr (disabled mDNS, LLMNR and NetBIOS-NS), --no-mdns , --no-llmnr , --no-netbios and --no-ra . If ntlmrelayx.py runs on a different host (say 10.0.0.10 / fe80::5 ), run pretender like","default_branch":null,"files":null,"tree":[],"storefront":"/r/RedTeamPentesting","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/RedTeamPentesting/pretender/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}