RedTeamPentesting/pretender
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing. observed · 2026-08-28
Health v2 · maintenance only
92/100
- Activity 90
- Release rhythm 91
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 8.5
- age_days: 1514
- days_rel: 61
- days_push: 61
- n_releases_24m: 5
Adoption not part of the score
1299 stars · 97 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR, NetBIOS-NS) and DHCPv6 DNS takeover attacks. It primarily targets Windows hosts and is designed to pair with relaying tools like Impacket's ntlmrelayx.py and krbrelayx.
Use cases
- spoof local name resolution in a Windows network for relay attacks
- perform DHCPv6 DNS takeover to intercept traffic
- redirect name resolution queries to an ntlmrelayx or krbrelayx host
- passively observe name resolution queries in dry mode
- capture NTLM hashes during pentests
- test Windows networks for poisoning vulnerabilities
When to choose
- you need a MitM position for relaying attacks in an Active Directory environment
- you want a single tool combining mDNS, LLMNR, NetBIOS-NS spoofing and DHCPv6 DNS takeover
- you need to point spoofed responses at a relay tool running on a different host
- you want a cross-platform Go tool for network spoofing
When to avoid
- you need a full exploitation framework rather than a spoofing helper
- your target network does not use Windows or vulnerable name resolution protocols
- you lack authorization to test the network
- you need GUI-based tooling
Facets
cli-tool · maturity active
security networking penetration-testing security penetration-testing networking developer-tools windows cli cross-platform go mitm spoofing dhcpv6 mdns llmnr netbios dns-takeover relay-attacks active-directory red-team linux macos
1 source
- readme: https://github.com/RedTeamPentesting/pretender · fetched 2026-08-28 · 6a3861a29bc0
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| RedTeamPentesting/pretender | main | 92 |
For agents
markdown · JSON · MCP: product_card(name="RedTeamPentesting/pretender")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem