Can be run on provider edge and is much more stable than old ettercap. Of course set probe as close to target at possible. Combined with sslstrip+ and dns2proxy forwarding with multiple routeable interfaces hsts bypass flat dangerous  let along getting hooked bEef. 

https://www.bettercap.org/