
Responder
Responder is a free open-source LLMNR, NBT-NS and MDNS poisoner with rogue auth servers for authorised AD and internal network pentests and labs.
0 upvotes · 0 downvotes
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
Responder is a free open-source network poisoning toolkit maintained by Laurent Gaffie (lgandx/Responder on GitHub). In authorised internal assessments and lab environments it answers LLMNR, NBT-NS and MDNS name-resolution requests and presents rogue authentication services so testers can observe how Windows clients authenticate when name resolution fails or is abused.
What it helps with
- Demonstrating LLMNR, NBT-NS and MDNS poisoning risks on authorised internal networks.
- Capturing NetNTLM challenge-response material and other authentication artefacts for offline analysis in scoped tests.
- Exercising rogue HTTP, SMB, LDAP, MSSQL, FTP, Kerberos and related authentication listeners in a controlled lab.
- Supporting red-team and penetration-test scenarios that validate name-resolution hardening and SMB signing controls.
- Pairing with hash-cracking and relay workflows already used in authorised AD assessments.
- Running as a Python tool under GPL without a commercial licence for the core project.
Who it's for
Penetration testers, red teams and defenders who need an established LLMNR/NBT-NS/MDNS poisoning tool for authorised Active Directory and internal network assessments, as a peer to Impacket and NetExec-style tooling.
Worth knowing
Responder is free and open source (GPL). The actively maintained line is github.com/lgandx/Responder; older SpiderLabs forks are largely historical. Official website field is GitHub-only for this listing. No formal project logo exists; the listing uses the maintainer GitHub avatar as the best official asset. Authorised penetration testing and lab use only; do not use against networks without explicit permission.