Ettercap
Classic suite for MITM on a LAN.
KaliParrothigh
pkg: ettercap-graphical
Ettercap performs ARP poisoning and other MITM attacks to intercept and manipulate LAN traffic.
Syntax
ettercap -T -M arp /target1// /target2//
Example
ettercap -T -M arp:remote /10.0.0.5// /10.0.0.1//
ARP-poisons to sit between a host and the gateway, sniffing their traffic.
Options & flags
What each switch does. Toggle them in the builder below to assemble a command.
Command builder
Tick options (and fill any values) to build a ready-to-copy command.
ettercap
Usage examples
ettercap -T -M arp:remote /10.0.0.5// /10.0.0.1//
ARP-poison between host and gateway.
Advantages
- Battle-tested MITM toolkit
- Filters/plugins for manipulation
- GUI and CLI
Disadvantages
- Highly intrusive and detectable
- Can disrupt the network
- Largely LAN-bound
Tags
#mitm#arp#lan
Official docs: Ettercap ↗
Related commands
Frequently asked questions
What is Ettercap used for?
Ettercap performs ARP poisoning and other MITM attacks to intercept and manipulate LAN traffic.
What is an example Ettercap command?
A common example is: ettercap -T -M arp:remote /10.0.0.5// /10.0.0.1// — ARP-poisons to sit between a host and the gateway, sniffing their traffic.
Is Ettercap part of Kali Linux?
Yes. Ettercap ships with Kali Linux (and Parrot OS). If missing, install it with: sudo apt install ettercap-graphical.
What category of security tool is Ettercap?
Ettercap is a Sniffing & Spoofing tool with a high-risk profile when run against a live target.
Try recon tools live
Run real scans against a domain you control, stage by stage.