Attack Tool(s): Responder, Impacket, MITM6, Inveigh
- Responder: https://github.com/lgandx/Responder
- Impacket: https://github.com/SecureAuthCorp/impacket
- MITM6: https://github.com/dirkjanm/mitm6
- Inveigh: https://github.com/Kevin-Robertson/Inveigh
Detection Link(s):
- Active Defense and Cyber Deception
- User and Entity Behavior Analytics (UEBA)
- Firewall Log Analysis
- Endpoint Security Protection Analysis
Helpful Blogs (BHIS):
- “How to Disable LLMNR & Why You Want To” – https://www.blackhillsinfosec.com/how-to-disable-llmnr-why-you-want-to/ – Responder and LLMNR poisoning.
- “MITM6 Strikes Again: The Dark Side of IPv6” – https://www.blackhillsinfosec.com/mitm6-strikes-again-the-dark-side-of-ipv6/ – MITM6 tactics.
