51fff82867643b21d97847b3233d9d68de0fcd06
AP ARP proxy sends REPLY frames with the disconnected client's MAC as the Ethernet source. Treating those as genuine device signals kept last_seen fresh, preventing the watchdog from detecting departure. Only ARP REQUEST (opcode 1) frames originate from the device itself. Skip _update_last_seen() for opcode 2 (REPLY) frames.
Description
Network drop implant — passive SOC + active exploitation. Deploy on any Debian host.
Languages
Python
89.2%
Shell
8.5%
HTML
1.1%
C
0.9%
Jinja
0.3%