Webcast: How to attack when LLMNR, mDNS, and WPAD attacks fail – eavesarp (Tool Overview)
ID: 1bab9a05-0925-5197-b0eb-c08a8e940a73
STIX ID: report--1bab9a05-0925-5197-b0eb-c08a8e940a73
Feed Name: Black Hills Infosec Blog
This webcast introduces eavesarp, a tool by Justin Angel (with John Strand) that analyzes ARP traffic to discover and exploit stale network address configurations (SNAC) for lateral movement when common LLMNR, WPAD, and mDNS techniques fail; it provides background on ARP cache poisoning, a live demo, Q&A, and practical defensive guidance, with references to the GitHub repo and a detailed blog post.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
