Setup and Hardware
Monitor mode setup, adapter selection, drivers, and chipsets
Setting Up Monitor Mode in Kali
Wireless Adapter Pentesting: Chipsets and Hardware
Covers selecting compatible wireless adapters for pentesting, focusing on chipset support, monitor mode, packet injection capabilities, and driver compatibility.
Wireless Driver Management in Kali
Reconnaissance
Guides on passive scanning, WPS discovery, and frame analysis
802.11 Frame Analysis with Wireshark and tshark
Passive Wireless Scanning with airodump-ng
Passive Wireless Scanning with Kismet
Discover and fingerprint wireless networks passively using Kismet to capture beacon frames, probe requests, and device metadata without transmitting packets.
WPS Network Discovery with wash
Enumeration
AP clients, auth types, PMKID capture, and remote sniffing
Enumerating AP Capabilities and Clients
Identifying Enterprise vs Personal Authentication
PMKID Capture with hcxdumptool and hcxtools
Capture PMKID hashes from WPA/WPA2 networks without de-authentication using hcxdumptool, then convert and crack with hcxtools and hashcat.
Remote Wireless Packet Capture over SSH
Vulnerability Discovery
Guides for finding weak wireless configs and attack surfaces
Detecting Captive Portal Bypass Opportunities
Detecting Open Wireless Networks
Detecting WEP Networks
Detecting WPA Enterprise PEAP Without Certificate Validation
Detecting WPA2 Networks Without MFP
Detecting WPS Vulnerable Networks
Exploitation
WEP/WPA cracking, evil twins, EAP harvest, rogue APs, WPS attacks
ARP Spoofing and Traffic Interception with Bettercap
Captive Portal Credential Harvesting
Capturing Plaintext Traffic on Open Networks
Cracking MSCHAPv2 with Asleap and Hashcat
Evil Twin AP with hostapd-mana and Aireplay-ng
Creates a rogue AP cloning a legitimate SSID using hostapd-mana, forcing client deauthentication via Aireplay-ng to capture credentials or handshakes.
Harvesting EAP Credentials with hostapd-mana
Post-Exploitation
Decrypt traffic, recon networks, and map AP relationships post-auth
Decrypting WPA Traffic with Airdecap-ng and Wireshark
Decrypt captured WPA/WPA2 wireless traffic using Airdecap-ng and Wireshark after obtaining the PSK or PMKID during post-exploitation analysis.