Responder
Poison LLMNR, NBT-NS, and mDNS to capture NTLM hashes on the network
- Tool
- responder
- Category
- Credential Attacks / NTLM Relay & Coercion
- Platform
- linux
- Requires
- no credentials
- Protocols
- NTLM
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
responder -I <interface> -dwv
Examples
responder -I eth0 -dwv
Tags
Related commands
- NTLM Relay to SMB NTLM relay attack targeting SMB service
- NTLM Relay to LDAP Relay NTLM authentication to LDAP to configure RBCD delegation
- NTLM Relay to ADCS Relay NTLM authentication to ADCS web enrollment to obtain a certificate
- Coercer Coerce NTLM authentication using multiple RPC protocols
- Coercer Scan (Find Coercion Vectors) Probe a target for every known authentication-coercion RPC method (PetitPotam,…
- DFSCoerce Coerce NTLM authentication using MS-DFSNM (Distributed File System)
- NetExec coerce_plus Module Unified coercion module — replaces the individual…
- NetExec Generate Relay Target List Scan a subnet over SMB and write a file containing every host with SMB signing disabled.…