Ettercap
E192904
Ettercap is a network security tool used for sniffing, intercepting, and manipulating traffic on local area networks, commonly employed for man-in-the-middle attacks and protocol analysis.
All labels observed (1)
| Label | Occurrences |
|---|---|
| Ettercap canonical | 1 |
How this entity was disambiguated
This entity first appeared as the object of triple T1717789 — resolving that mention is where its identity was fixed. The disambiguator weighed these candidate entities and picked the highlighted one (or “None”, minting a new entity). This is how homonymy is resolved: the same surface form can point to different entities.
Target entity: Ettercap Context triple: [Kali Linux, includesTool, Ettercap]
-
A.
Aircrack‑ng
Aircrack‑ng is an open-source suite of tools used for auditing and cracking Wi‑Fi network security, including WEP and WPA/WPA2 encryption.
-
B.
Wireshark
Wireshark is a widely used open-source network protocol analyzer that captures and interactively inspects traffic on computer networks for troubleshooting, analysis, and security auditing.
-
C.
Reaver (WPS attack tool)
Reaver is a specialized Wi-Fi security tool designed to exploit vulnerabilities in the WPS (Wi-Fi Protected Setup) protocol in order to recover WPA/WPA2 passphrases.
-
D.
Kali Linux
Kali Linux is a Debian-based Linux distribution specifically designed for digital forensics and penetration testing, widely used by security professionals and ethical hackers.
-
E.
ACKTR
ACKTR (Actor-Critic using Kronecker-Factored Trust Region) is a reinforcement learning algorithm that combines actor-critic methods with efficient second-order optimization via Kronecker-factored approximations to improve training stability and sample efficiency.
- F. None of above. chosen
- G. Unsure - the case is ambiguous/there is not enough information to decide.
Target entity: Ettercap Target entity description: Ettercap is a network security tool used for sniffing, intercepting, and manipulating traffic on local area networks, commonly employed for man-in-the-middle attacks and protocol analysis.
-
A.
Aircrack‑ng
Aircrack‑ng is an open-source suite of tools used for auditing and cracking Wi‑Fi network security, including WEP and WPA/WPA2 encryption.
-
B.
Wireshark
Wireshark is a widely used open-source network protocol analyzer that captures and interactively inspects traffic on computer networks for troubleshooting, analysis, and security auditing.
-
C.
Reaver (WPS attack tool)
Reaver is a specialized Wi-Fi security tool designed to exploit vulnerabilities in the WPS (Wi-Fi Protected Setup) protocol in order to recover WPA/WPA2 passphrases.
-
D.
Kali Linux
Kali Linux is a Debian-based Linux distribution specifically designed for digital forensics and penetration testing, widely used by security professionals and ethical hackers.
-
E.
ACKTR
ACKTR (Actor-Critic using Kronecker-Factored Trust Region) is a reinforcement learning algorithm that combines actor-critic methods with efficient second-order optimization via Kronecker-factored approximations to improve training stability and sample efficiency.
- F. None of above. chosen
Statements (51)
| Predicate | Object |
|---|---|
| instanceOf |
man-in-the-middle attack tool
ⓘ
network security tool ⓘ packet sniffer ⓘ protocol analyzer ⓘ |
| hasCapability |
ARP poisoning
ⓘ
DNS spoofing ⓘ SSL stripping (via plugins or filters) ⓘ connection hijacking ⓘ intercepting network traffic ⓘ manipulating network traffic ⓘ packet filtering ⓘ packet injection ⓘ password sniffing ⓘ performing man-in-the-middle attacks ⓘ sniffing network traffic ⓘ |
| hasFeature |
active sniffing
ⓘ
filtering language for packet modification ⓘ graphical user interface ⓘ passive sniffing ⓘ plugin architecture ⓘ text-based user interface ⓘ |
| isFree | true ⓘ |
| license | open-source license ⓘ |
| runsOn |
Linux
ⓘ
Unix-like operating systems ⓘ Windows ⓘ |
| supportsAttackTechnique |
ARP spoofing
ⓘ
DNS spoofing ⓘ HTTP content injection ⓘ MAC flooding ⓘ |
| supportsNetworkType | local area network ⓘ |
| supportsProtocol |
FTP
ⓘ
HTTP ⓘ HTTPS (for MITM analysis) ⓘ ICMP ⓘ IMAP ⓘ POP3 ⓘ Telnet ⓘ
surface form:
Rlogin
SMTP ⓘ SSH (for MITM analysis) ⓘ Transmission Control Protocol ⓘ
surface form:
TCP
Telnet ⓘ UDP ⓘ |
| typicalUser |
network administrator
ⓘ
penetration tester ⓘ security researcher ⓘ |
| usedFor |
demonstrating network vulnerabilities
ⓘ
network security testing ⓘ penetration testing ⓘ protocol analysis ⓘ security research ⓘ |
How these facts were elicited
The pipeline generated the facts above by prompting gpt-5.1 with this entity's name + description and the instruction below.
You are a knowledge base construction expert. Given a subject entity and a description of it, return factual statements that you know for the subject as a JSON list of dictionaries(triples), where keys must be "subject", "predicate" and "object". The number of facts may be very high, between 25 to 50 or more, for very popular subjects. For less popular subjects, the number of facts can be very low, like 5 or 10. # Requirements - If you don't know the subject at all, return an empty list. - If the subject is not a named entity, return an empty list. - Include at least one triple where predicate is "instanceOf". - Do not get too wordy. - Separate several objects into multiple triples with one object.
Subject: Ettercap Description of subject: Ettercap is a network security tool used for sniffing, intercepting, and manipulating traffic on local area networks, commonly employed for man-in-the-middle attacks and protocol analysis.
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.