responder
LLMNR/NBT-NS/mDNS poisoning and hash capture
How to use it
responder is exposed by the Mergen MCP MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the responder tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Mergen MCP
pip install -r requirements.txtOther tools in Mergen MCP (39)
Comprehensive domain recon (active + passive)
Application surface mapping and analysis
HTTP parameter discovery
Firmware and binary file analysis and extraction
Binary security property checker
Subdomain discovery via certificate transparency logs
XSS detection and exploitation
Web path discovery
DNS enumeration
SMB/Samba user, group, and share enumeration
AI-assisted exploit synthesis
Recursive content discovery
Fast web fuzzer — directories, parameters, vhosts
DNS zone transfer and subdomain brute-force
URL collection from Archive.org and other sources
NSA software reverse engineering suite (headless mode)
Directory, file, and subdomain brute-force
GPU-accelerated hash cracking (300+ hash types)
HTTP/HTTPS service detection and fingerprinting
Network service brute-force (50+ protocols)
John the Ripper — password hash cracking with custom rules
JavaScript-aware web crawler
Internet-scale port scanning
Metasploit Framework integration
SMB/WinRM/SSH network exploitation framework
Web server configuration auditing
Advanced port scanning with stealth, aggressive, and vuln script modes
Template-based vulnerability scanner (10,000+ templates)
Ultra-fast port scanner used as a Nmap pre-stage
Exploit-DB database search
SMB share access mapping
Automatic SQL injection detection and exploitation
Printable string extraction from binaries
Passive subdomain discovery
Secret and credential detection in Git repositories
WAF detection and fingerprinting
Historical URL discovery from Wayback Machine
Web technology identification (CMS, framework, version)
WordPress security scanner