/ DETECTION WALL

Every one of these was
run against us first.

This isn’t a feature list. It’s the coverage we’ve proven by firing the real attack tool at the app — over and over — until it raised the alarm.

AttackDoes it slip past us?HardenRe-test

We stand up a Kali attacker on a real network and run the same tools an intruder would — Responder, mitm6, THC-IPv6, bettercap, evil-ssdp, and more. If an attack gets through, that’s a bug. We fix it and run the attack again until it’s caught reliably — with the false-positive guards to keep it quiet on a normal home network.

19attack types detected
6attack surfaces covered
Realtools, real networks
On-devicenothing leaves your PC
/ 01 — ON-WIRE L2 / L3

On-wire L2 / L3

The Ethernet + IP layer an attacker poisons to sit in the middle of your traffic.

Detected

ARP spoofing

A device claiming your router’s address to intercept traffic — fast, and the patient low-and-slow variant.

Detected

Rogue DHCP

An unauthorized server handing out network settings to redirect you.

Detected

DHCP starvation

A flood of fake devices draining the router’s address pool before a rogue takeover.

Detected

Route injection (TunnelVision)

A DHCP option-121 route that pulls traffic out of your VPN in the clear — CVE-2024-3661.

/ 02 — DNS INTEGRITY

DNS integrity

Where a name you type gets quietly pointed at an attacker.

Detected

DNS spoofing

A network rewriting the answers for globally-fixed addresses.

Detected

Targeted DNS forgery

One site steered to a device on your network, cross-checked against an unforgeable encrypted resolver.

/ 03 — NAME & DEVICE DISCOVERY

Name & device discovery

The four protocols Windows uses to find printers, shares and “network” devices — each a lure.

Detected

Name-service poisoning

LLMNR / NetBIOS / mDNS poisoners (Responder-class) that hijack name lookups to steal your login.

Detected

Rogue UPnP / SSDP

A fake device that pops phishing or credential-capture prompts.

Detected

Rogue WS-Discovery

A fake device planted in your File Explorer “Network” folder.

/ 04 — IPV6

IPv6

The second internet running on your network that most tools ignore entirely.

Detected

Rogue IPv6 router / mitm6

An attacker becoming your IPv6 router and DNS, including the stealth DHCPv6-only variant.

Detected

Neighbor-cache poisoning

The IPv6 twin of ARP spoofing — your router’s hardware address swapped for an attacker’s.

Detected

Rogue router-advert flood

A fake network injected via Router Advertisements, or a flood that grinds the device down.

Detected

IPv6 address starvation

An attacker denying your PC any IPv6 address to force traffic onto a path they watch.

/ 05 — WI-FI

Wi-Fi

The radio + the connection itself.

Detected

Evil twin

A look-alike access point impersonating a network you trust — nearby or connected.

Detected

Deauthentication

Forced disconnects used to knock you onto an attacker’s AP.

Detected

Auto-join / KARMA lure

A known network name appearing on unfamiliar hardware your device silently joins.

/ 06 — ROUTER & CREDENTIALS

Router & credentials

The exposure that outlives the attacker — and the moment your login actually leaks.

Detected

UPnP port-forward abuse

The router opening your RDP / file-sharing / remote-desktop ports to the whole internet.

Detected

Login-hash theft

Confirmation that your Windows sign-in was handed to a device that’s actively luring on the network.

Detected

New device on network

Unrecognized hardware joining, so a foothold doesn’t go unnoticed.

The wall keeps growing.
Get on the right side of it.