Ross ROSS = Recommend OSS · open-source software intelligence for agents

RedTeamPentesting/pretender

Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing. observed · 2026-08-28

github.com/RedTeamPentesting/pretender · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

92/100

  • Activity 90
  • Release rhythm 91
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 8.5
  • age_days: 1514
  • days_rel: 61
  • days_push: 61
  • n_releases_24m: 5

Full methodology

Adoption not part of the score

1299 stars · 97 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR, NetBIOS-NS) and DHCPv6 DNS takeover attacks. It primarily targets Windows hosts and is designed to pair with relaying tools like Impacket's ntlmrelayx.py and krbrelayx.

Use cases

  • spoof local name resolution in a Windows network for relay attacks
  • perform DHCPv6 DNS takeover to intercept traffic
  • redirect name resolution queries to an ntlmrelayx or krbrelayx host
  • passively observe name resolution queries in dry mode
  • capture NTLM hashes during pentests
  • test Windows networks for poisoning vulnerabilities

When to choose

  • you need a MitM position for relaying attacks in an Active Directory environment
  • you want a single tool combining mDNS, LLMNR, NetBIOS-NS spoofing and DHCPv6 DNS takeover
  • you need to point spoofed responses at a relay tool running on a different host
  • you want a cross-platform Go tool for network spoofing

When to avoid

  • you need a full exploitation framework rather than a spoofing helper
  • your target network does not use Windows or vulnerable name resolution protocols
  • you lack authorization to test the network
  • you need GUI-based tooling

Facets

cli-tool · maturity active

security networking penetration-testing security penetration-testing networking developer-tools windows cli cross-platform go mitm spoofing dhcpv6 mdns llmnr netbios dns-takeover relay-attacks active-directory red-team linux macos

1 source

Member repositories

RepositoryRoleHealth v2
RedTeamPentesting/pretendermain92

For agents

markdown · JSON · MCP: product_card(name="RedTeamPentesting/pretender")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem