Every one of these was
run against us first.
This isn’t a feature list. It’s the coverage we’ve proven by firing the real attack tool at the app — over and over — until it raised the alarm.
We stand up a Kali attacker on a real network and run the same tools an intruder would — Responder, mitm6, THC-IPv6, bettercap, evil-ssdp, and more. If an attack gets through, that’s a bug. We fix it and run the attack again until it’s caught reliably — with the false-positive guards to keep it quiet on a normal home network.
On-wire L2 / L3
The Ethernet + IP layer an attacker poisons to sit in the middle of your traffic.
ARP spoofing
A device claiming your router’s address to intercept traffic — fast, and the patient low-and-slow variant.
Rogue DHCP
An unauthorized server handing out network settings to redirect you.
DHCP starvation
A flood of fake devices draining the router’s address pool before a rogue takeover.
Route injection (TunnelVision)
A DHCP option-121 route that pulls traffic out of your VPN in the clear — CVE-2024-3661.
DNS integrity
Where a name you type gets quietly pointed at an attacker.
DNS spoofing
A network rewriting the answers for globally-fixed addresses.
Targeted DNS forgery
One site steered to a device on your network, cross-checked against an unforgeable encrypted resolver.
Name & device discovery
The four protocols Windows uses to find printers, shares and “network” devices — each a lure.
Name-service poisoning
LLMNR / NetBIOS / mDNS poisoners (Responder-class) that hijack name lookups to steal your login.
Rogue UPnP / SSDP
A fake device that pops phishing or credential-capture prompts.
Rogue WS-Discovery
A fake device planted in your File Explorer “Network” folder.
IPv6
The second internet running on your network that most tools ignore entirely.
Rogue IPv6 router / mitm6
An attacker becoming your IPv6 router and DNS, including the stealth DHCPv6-only variant.
Neighbor-cache poisoning
The IPv6 twin of ARP spoofing — your router’s hardware address swapped for an attacker’s.
Rogue router-advert flood
A fake network injected via Router Advertisements, or a flood that grinds the device down.
IPv6 address starvation
An attacker denying your PC any IPv6 address to force traffic onto a path they watch.
Wi-Fi
The radio + the connection itself.
Evil twin
A look-alike access point impersonating a network you trust — nearby or connected.
Deauthentication
Forced disconnects used to knock you onto an attacker’s AP.
Auto-join / KARMA lure
A known network name appearing on unfamiliar hardware your device silently joins.
Router & credentials
The exposure that outlives the attacker — and the moment your login actually leaks.
UPnP port-forward abuse
The router opening your RDP / file-sharing / remote-desktop ports to the whole internet.
Login-hash theft
Confirmation that your Windows sign-in was handed to a device that’s actively luring on the network.
New device on network
Unrecognized hardware joining, so a foothold doesn’t go unnoticed.