Adding answer name spoofing capabilities when poisoning LLMNR for Kerberos relaying purpose

This commit is contained in:
User 2025-01-23 14:35:41 -08:00
parent e918fe01c6
commit d3dd37a324
4 changed files with 30 additions and 9 deletions

View file

@ -172,6 +172,7 @@ class Settings:
self.DHCP_DNS = options.DHCP_DNS
self.ExternalIP6 = options.ExternalIP6
self.Quiet_Mode = options.Quiet
self.AnswerName = options.AnswerName
# TTL blacklist. Known to be detected by SOC / XDR
TTL_blacklist = [b"\x00\x00\x00\x1e", b"\x00\x00\x00\x78", b"\x00\x00\x00\xa5"]