Responder

S0174

Tool.View on attack.mitre.org

About this tool

Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1040
Network Sniffing

Responder captures hashes and credentials that are sent to the system after the name services have been poisoned.

T1557.001
Name Resolution Poisoning and SMB Relay

Responder is used to poison name services to gather hashes and credentials from systems within a local network.

Groups that use it3

Campaigns1

References1

  1. GitHub Responder Open source
    Gaffie, L. (2016, August 25). Responder. Retrieved November 17, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.