Sniffing & Spoofing
Packet capture, MITM, ARP/DNS spoofing and traffic analysis. · 15 commands
Wireshark
passiveThe reference graphical packet analyzer.
tcpdump
passiveCommand-line packet capture.
TShark
passiveWireshark’s power in a terminal.
Ettercap
highClassic suite for MITM on a LAN.
bettercap
highModern, modular MITM & network attack swiss-army knife.
Responder
highLLMNR/NBT-NS/MDNS poisoner & credential capture.
mitmproxy
mediumInteractive HTTPS intercepting proxy.
dsniff
highClassic suite for password sniffing on a LAN.
arpspoof
highRedirect LAN traffic via ARP poisoning.
macchanger
lowView and spoof network MAC addresses.
mitm6
highAbuse IPv6 to MITM Windows networks.
Scapy
mediumInteractive packet manipulation in Python.
sslstrip
highDowngrade HTTPS to HTTP in a MITM.
ngrep
passivegrep for network packets.
tcpreplay
mediumReplay captured packets onto a network.