Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Dementor

IPv6/IPv4 LLMNR/NBT-NS/mDNS Poisoner and rogue service provider - you can think if it as Responder 2.0. Get more information on the Documentation page.

Offers

  • No reliance on hardcoded or precomputed packets
  • Fine-grained, per-protocol configuration using a modular system (see Docs - Configuration)
  • Near-complete protocol parity with Responder (see Docs - Compatibility)
  • Easy integration of new protocols via the extension system
  • A lot of new protocols (e.g. IPP, MySQL, X11, ...)

Installation

Installation via pip/pipx from GitHub or PyPI:

pip install dementor

Usage

Just type in Dementor, specify the target interface and you are good to go! It is recommended to run Dementor with sudo as most protocol servers use privileged ports.

sudo Dementor -I "$INTERFACE_NAME"

Let's take a look.

index_video

CLI Options

 Usage: Dementor [OPTIONS]

╭─ Options ───────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ --interface   -I      NAME        Network interface to use (required for poisoning)                                     │
│ --analyze     -A                  Only analyze traffic, don't respond to requests                                       │
│ --config      -c      PATH        Path to a configuration file (otherwise standard path is used)                        │
│ --option      -O      KEY=VALUE   Add an extra option to the global configuration file.                                 │
│ --host        -H      HOST        Host FQDN for all protocol servers (e.g. DC01.contoso.lab). Shortcut for -O           │
│                                   Globals.Host=FQDN.                                                                    │
│ --yes,--yolo  -y                  Do not ask before starting attack mode.                                               │
│ --target      -t      NAME[,...]  Target host(s) to attack                                                              │
│ --ignore      -i      NAME[,...]  Target host(s) to ignore                                                              │
│ --quiet       -q                  Don't print banner at startup                                                         │
│ --version                         Show Dementor's version number                                                        │
│ --ts                              Log timestamps to the terminal too                                                    │
│ --paths                           Displays the default configuration paths                                              │
│ --repl        -F                  Starts Dementor in interactive mode supporting runtime configuration                  │
│ --help                            Show this message and exit.                                                           │
╰─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯

You need more?

Take a look at the Documentation on GitHub-Pages or at the Blog Series.

License

Distributed under the MIT License. See LICENSE for more information.

Disclaimer

Dementor is intended only for lawful educational purposes: learning, testing in your own lab, or assessments on systems where you have explicit written authorization. You agree not to use this software to access, damage, interfere with, or exfiltrate data from systems for which you do not have permission. We make no promises about safety, completeness, or fitness for any purpose. Use at your own risk. If you discover a vulnerability, please follow responsible disclosure by using the private disclosing feature offered by GitHub.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dementor-1.0.0.dev25.tar.gz (255.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dementor-1.0.0.dev25-py3-none-any.whl (286.5 kB view details)

Uploaded Python 3

File details

Details for the file dementor-1.0.0.dev25.tar.gz.

File metadata

  • Download URL: dementor-1.0.0.dev25.tar.gz
  • Upload date:
  • Size: 255.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for dementor-1.0.0.dev25.tar.gz
Algorithm Hash digest
SHA256 5ce394563ca16d0fe7eeda3ecfd09ce2f281db0a533aa94f2d3fd4153c40ddd7
MD5 5502cd6ab4bc992c1d3cff47d908ae19
BLAKE2b-256 dbf549cd41616f96713bc2e753f1a8716a4b51c3119d70a35898a07ba186e42f

See more details on using hashes here.

Provenance

The following attestation bundles were made for dementor-1.0.0.dev25.tar.gz:

Publisher: wheel-publish.yml on MatrixEditor/dementor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file dementor-1.0.0.dev25-py3-none-any.whl.

File metadata

  • Download URL: dementor-1.0.0.dev25-py3-none-any.whl
  • Upload date:
  • Size: 286.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for dementor-1.0.0.dev25-py3-none-any.whl
Algorithm Hash digest
SHA256 ed5faea5545e842f0691459c69804f3867445436f98559e14788abe7c65cf45b
MD5 e93ed8e0b12fc475cdd5f03b841161c3
BLAKE2b-256 6c6da60bc5872b4a14cdac42e82fee650da6739458a8cdcaac2a361566993d92

See more details on using hashes here.

Provenance

The following attestation bundles were made for dementor-1.0.0.dev25-py3-none-any.whl:

Publisher: wheel-publish.yml on MatrixEditor/dementor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page