Skip to content
hackingtools.ai
Responder

Responder

Responder is a free open-source LLMNR, NBT-NS and MDNS poisoner with rogue auth servers for authorised AD and internal network pentests and labs.

0

0 upvotes · 0 downvotes

Pricing
Free
Platforms
LinuxWindowsmacOS
Licence
Open source
Reviewed
Last reviewed 1 October 2026

What it is

Responder is a free open-source network poisoning toolkit maintained by Laurent Gaffie (lgandx/Responder on GitHub). In authorised internal assessments and lab environments it answers LLMNR, NBT-NS and MDNS name-resolution requests and presents rogue authentication services so testers can observe how Windows clients authenticate when name resolution fails or is abused.

What it helps with

- Demonstrating LLMNR, NBT-NS and MDNS poisoning risks on authorised internal networks.
- Capturing NetNTLM challenge-response material and other authentication artefacts for offline analysis in scoped tests.
- Exercising rogue HTTP, SMB, LDAP, MSSQL, FTP, Kerberos and related authentication listeners in a controlled lab.
- Supporting red-team and penetration-test scenarios that validate name-resolution hardening and SMB signing controls.
- Pairing with hash-cracking and relay workflows already used in authorised AD assessments.
- Running as a Python tool under GPL without a commercial licence for the core project.

Who it's for

Penetration testers, red teams and defenders who need an established LLMNR/NBT-NS/MDNS poisoning tool for authorised Active Directory and internal network assessments, as a peer to Impacket and NetExec-style tooling.

Worth knowing

Responder is free and open source (GPL). The actively maintained line is github.com/lgandx/Responder; older SpiderLabs forks are largely historical. Official website field is GitHub-only for this listing. No formal project logo exists; the listing uses the maintainer GitHub avatar as the best official asset. Authorised penetration testing and lab use only; do not use against networks without explicit permission.

← Back to directory