Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Inveigh — Herramienta de intermediario .NET para IPv4/IPv6 para pentesters | Kitploit
Herramientas/GitHubGitHub/kevin-robertson/inveigh
Pruebas de PenetraciónRed Teaming
GitHubkevin-robertson/inveigh

Inveigh

Herramienta de intermediario .NET para IPv4/IPv6 para pentesters

Ver Repositorio
3.0k47213hace 10 mesesRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Inveigh

Inveigh es una herramienta multiplataforma .NET IPv4/IPv6 de intermediario (machine-in-the-middle) para probadores de penetración. Este repositorio contiene la versión principal en C# así como la versión heredada en PowerShell.

Resumen

Inveigh realiza ataques de suplantación y capturas de hashes/credenciales tanto mediante la captura de paquetes como mediante oyentes/sockets específicos de protocolo. El método de captura de paquetes, que fue la base de la versión original en PowerShell de esta herramienta, tiene las siguientes ventajas:

  • Capturas de desafío/respuesta NTLM a través del servicio SMB de Windows
  • Menos enlaces de puertos visibles en el sistema anfitrión

La principal desventaja es el acceso elevado requerido.

En las versiones actuales de Windows, los servicios UDP en ejecución por defecto permiten la reutilización de puertos. Por lo tanto, la captura de paquetes ya no proporciona una ventaja para evitar puertos UDP en uso. Todos los oyentes UDP de Inveigh están configurados para aprovechar la reutilización de puertos.

Descripciones de Versiones

  • PowerShell Inveigh - versión original desarrollada durante muchos años. Por ahora al menos, esta versión (1.506) se quedará sin actualizaciones adicionales. La documentación se puede encontrar aquí.
  • C# Inveigh (también conocido como InveighZero) - código POC original en C# combinado con un puerto a C# de la mayor parte del código de la versión de PowerShell. Esta versión ha sido reconstruida para C# y está asumiendo el rol de versión principal.

Características

La versión C# de Inveigh contiene ataques para los siguientes protocolos:

  • LLMNR [capturador de paquetes | oyente]
  • DNS [capturador de paquetes | oyente]
  • mDNS [capturador de paquetes | oyente]
  • NBNS [capturador de paquetes | oyente]
  • DHCPv6 [capturador de paquetes | oyente]
  • ICMPv6 [socket en bruto privilegiado]
  • HTTP [oyente]
  • HTTPS [oyente]
  • SMB [capturador de paquetes | oyente]
  • LDAP [oyente]
  • WebDAV [oyente]
  • Proxy Auth [oyente]

Inveigh funciona tanto con IPv4 como con IPv6 en los casos en que el protocolo subyacente proporciona soporte para ambos.

Soporte Multiplataforma

El archivo de proyecto estilo SDK de Inveigh está configurado para .NET 3.5, 4.6.2 y 6.0, siendo 6.0 la versión que también funciona con Linux y macOS.

<TargetFrameworks>net35;net62;net6.0</TargetFrameworks>

Problemas Conocidos

  • El capturador de paquetes solo está disponible en Windows debido a diferencias en la configuración de sockets en bruto. Cuando se compila para Linux o macOS, el capturador de paquetes simplemente se desactiva. En su lugar, se puede usar el oyente SMB de Inveigh si el puerto 445 está abierto.
  • macOS requiere que existan rutas para unirse a grupos multicast. En mis pruebas, he tenido que agregar rutas para multicast DHCPv6 para poder llevar a cabo ese ataque en esta plataforma.
    sudo route -nv add -net ff02::1:2 -interface en0

Ejecución

dotnet Inveigh.dll

Compilaciones Dirigidas a Plataformas Linux/macOS

  • Con .NET 6.0 instalado en el sistema de destino
    dotnet publish -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

  • Sin .NET 6.0 instalado en el sistema de destino
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r linux-x64 -f net8.0 -p:AssemblyName=inveigh
    dotnet publish --self-contained=true -p:PublishSingleFile=true -r osx-x64 -f net8.0 -p:AssemblyName=inveigh

Uso

Los valores predeterminados de los parámetros se encuentran al inicio de Program.cs. Recomiendo revisar y configurar todo según sus necesidades antes de compilar. Todos los parámetros de habilitar/deshabilitar se pueden establecer con valores Y/N.``` //begin parameters - set defaults as needed before compile public static string argCert = "MIIKaQIBAzCCC..." public static string argCertPassword = "password"; public static string argChallenge = ""; public static string argConsole = "5"; public static string argConsoleLimit = "-1"; public static string argConsoleStatus = "0"; public static string argConsoleUnique = "Y"; public static string argDHCPv6 = "N"; public static string argDHCPv6TTL = "30"; public static string argDNS = "Y"; ... //end parameters

### Ayuda de Parámetros```
.\Inveigh.exe -?

Control:

  -Inspect        Default=Disabled: (Y/N) inspect traffic only.

  -IPv4           Default=Enabled: (Y/N) IPv4 spoofing/capture.

  -IPv6           Default=Enabled: (Y/N) IPv6 spoofing/capture.

  -RunCount       Default=Unlimited: Number of NetNTLM captures to perform before auto-exiting.

  -RunTime        Default=Unlimited: Run time duration in minutes.


Output:

  -Console        Default=5: Set the level for console output. (0=none, 1=only captures/spoofs, 2=no disabled, no informational, 3=no disabled, no filtered, 4=no disabled, 5=all)  

  -ConsoleLimit   Default=Unlimited: Limit to queued console entries.

  -ConsoleStatus  Default=Disabled: Interval in minutes for auto-displaying capture details.

  -ConsoleUnique  Default=Enabled: (Y/N) displaying only unique (user and system combination) hashes at time of capture.

  -FileDirectory  Default=Working Directory: Valid path to an output directory for enabled file output.

  -FileOutput     Default=Enabled: (Y/N) real time file output.

  -FilePrefix     Default=Inveigh: Prefix for all output files.

  -FileUnique     Default=Enabled: (Y/N) outputting only unique (user and system combination) hashes.

  -LogOutput      Default=Disabled: (Y/N) outputting log entries.


Spoofers:

  -DHCPV6         Default=Disabled: (Y/N) DHCPv6 spoofing.

  -DHCPv6TTL      Default=300: Lease lifetime in seconds.

  -DNS            Default=Enabled: (Y/N) DNS spoofing.

  -DNSHost        Fully qualified hostname to use SOA/SRV responses.

  -DNSSRV         Default=LDAP: Comma separated list of SRV request services to answer.

  -DNSSuffix      DNS search suffix to include in DHCPv6/ICMPv6 responses.

  -DNSTTL         Default=30: DNS TTL in seconds.

  -DNSTYPES       Default=A: (A, AAAA, SOA, SRV) Comma separated list of DNS types to spoof.

  -ICMPv6         Default=Enabled: (Y/N) sending ICMPv6 router advertisements.

  -ICMPv6Interval Default=200: ICMPv6 RA interval in seconds.
  
  -ICMPv6TTL	  Default=300: ICMPv6 TTL in seconds.

  -IgnoreDomains  Default=None: Comma separated list of domains to ignore when spoofing.



  -IgnoreIPs      Default=Local: Comma separated list of source IP addresses to ignore when spoofing.

  -IgnoreMACs     Default=Local: Comma separated list of MAC addresses to ignore when DHCPv6 spoofing.
  
  -IgnoreQueries  Default=None: Comma separated list of name queries to ignore when spoofing.

  -Local          Default=Disabled: (Y/N) performing spoofing attacks against the host system.

  -LLMNR          Default=Enabled: (Y/N) LLMNR spoofing.

  -LLMNRTTL       Default=30: LLMNR TTL in seconds.

  -MAC            Local MAC address for DHCPv6.

  -MDNS           Default=Enabled: (Y/N) mDNS spoofing.

  -MDNSQuestions  Default=QU,QM: Comma separated list of question types to spoof. (QU,QM)

  -MDNSTTL        Default=120: mDNS TTL in seconds.

  -MDNSTypes      Default=A: Comma separated list of mDNS record types to spoof. (A,AAAA,ANY)

  -MDNSUnicast    Default=Enabled: (Y/N) sending a unicast only response to a QM request.

  -NBNS           Default=Disabled: (Y/N) NBNS spoofing.

  -NBNSTTL        Default=165: NBNS TTL in seconds.

  -NBNSTypes      Default=00,20: Comma separated list of NBNS types to spoof. (00,03,20,1B)

  -ReplyToDomains Default=All: Comma separated list of domains to respond to when spoofing.
Descargar herramienta