InveighZero is a C# LLMNR/NBNS/mDNS/DNS/DHCPv6 spoofer and man-in-the-middle tool designed to assist penetration testers/red teamers that find themselves limited to a Windows system. This version shares many features with the PowerShell version of Inveigh.
Privileged Mode Features (elevated admin required)
Unprivileged Mode Features
Other Features
Notable Missing Features
Notable Differences
Minimum .NET Version
Parameters
In most cases, when present, the InveighZero parameters mirror Inveigh’s parameters.
Why The Zero In The Name?
Inveigh started as a C# proof of concept before I switched over to PowerShell. The “Zero” is just a reference to the fact that the C# version sort of existed before the PowerShell version. Mainly though, I just needed a unique repo name.
Usage
Inveigh.exe
Inveigh.exe -IP 192.168.1.1
Inveigh.exe -IP 192.168.1.1 -SpooferIP 192.168.1.2
Inveigh.exe -Pcap Y -PcapTCP 80,445
Screenshots
When people ask how UDP works, the simplest answer is this: UDP sends data quickly…
Endpoint Detection and Response (EDR) solutions have become a cornerstone of modern cybersecurity, designed to…
A large-scale malware campaign leveraging AI-assisted development techniques has been uncovered, revealing how attackers are…
How Does a Firewall Work Step by Step? What Is a Firewall and How Does…
People trying to securely connect to work are being tricked into doing the exact opposite.…
A newly disclosed Android vulnerability is making noise for a good reason. Researchers showed that…