1. Where mitm6 Fits in a Defender's Workflow
mitm6 is a specialized IPv6/AD attack simulation tool used in authorized labs and purple-team exercises to teach defenders how IPv6/NTLM relay paths can be abused and how to harden and detect them.
The role here is "IPv6/AD lab attack simulation (dual-use)." That scoping matters. A triage tool used as an investigation tool produces the wrong level of depth; an investigation tool used as a monitoring tool burns analyst time. Pick the right phase, then pick the tool.
Start with a concrete question — "Is this service reachable from the DMZ?" or "Do we have stale DNS records for this domain?" — rather than opening the tool and seeing what turns up.