Wireless Testing Tools
Comprehensive collection of hardware and software tools for wireless security assessments, from WiFi to Bluetooth, RF, and beyond.
Information
🔧 WiFi Attack Suites
Aircrack-ng
SuiteComplete suite of tools to assess WiFi network security including capture, cracking, analysis, and replay.
Installation
aircrack-ng -w wordlist.txt capture.capaircrack-ng -w wordlist.txt capture.capBettercap
FrameworkPowerful framework for network attacks, MITM, sniffing, and monitoring with WiFi, BLE, and HID support.
Installation
bettercap -iface wlan0monbettercap -iface wlan0monWifite2
AutomationAutomated wireless attack tool for WEP, WPA/WPA2, WPS with Pixie Dust support.
Installation
wifite --kill -i wlan0monwifite --kill -i wlan0monAirgeddon
AutomationMulti-use bash script with DoS attacks, evil twin, WPS attacks, and enterprise targeting.
Installation
./airgeddon.sh./airgeddon.shHcxdumptool
CaptureCapture WPA/WPA2 handshakes and PMKID from access points. Works with hashcat.
Installation
hcxdumptool -i wlan0mon -o capture.pcapng --enable_status=15hcxdumptool -i wlan0mon -o capture.pcapng --enable_status=15Hcxtools
ConversionPortable solution for conversion of packet captures to hashcat/JtR formats.
Installation
hcxpcapngtool -o hash.hc22000 capture.pcapnghcxpcapngtool -o hash.hc22000 capture.pcapng🎯 Attack & Exploitation
EAPHammer
EnterpriseTargeted evil twin attacks against WPA2-Enterprise networks with credential harvesting.
Installation
./eaphammer --cert-wizard./eaphammer --cert-wizardMDK4
AttackWiFi testing tool for DoS attacks, beacon flooding, deauthentication, and more.
Installation
mdk4 wlan0mon d -c 6mdk4 wlan0mon d -c 6Reaver
WPSWPS PIN brute force attack tool for WPS-enabled routers.
Installation
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -vvreaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -vvBully
WPSAlternative WPS brute force tool with Pixie Dust attack support.
Installation
bully wlan0mon -b AA:BB:CC:DD:EE:FF -d -v 3bully wlan0mon -b AA:BB:CC:DD:EE:FF -d -v 3Wifiphisher
PhishingAutomated phishing attacks against WiFi networks for credential harvesting.
Installation
wifiphisher -aI wlan0 -jI wlan1wifiphisher -aI wlan0 -jI wlan1Fluxion
PhishingSocial engineering tool for WPA key recovery with captive portal attacks.
Installation
./fluxion.sh./fluxion.sh📡 Scanning & Reconnaissance
Kismet
ScannerWireless network detector, sniffer, and IDS with web interface and extensive protocol support.
Installation
kismet -c wlan0monkismet -c wlan0monLinSSID
ScannerGraphical WiFi scanner showing channels, security, signal strength, and vendor info.
Installation
linssidlinssidWash
ScannerIdentify WPS-enabled access points and check for Pixie Dust vulnerability.
Installation
wash -i wlan0monwash -i wlan0monAirodump-ng
CapturePacket capture tool for raw 802.11 frames, part of Aircrack-ng suite.
Installation
airodump-ng wlan0monairodump-ng wlan0monHorst
AnalysisLightweight 802.11 wireless LAN analyzer with ncurses interface.
Installation
horst -i wlan0monhorst -i wlan0monSparrow-wifi
VisualizationWiFi spectrum analyzer with GPS tracking for wardriving and heatmaps.
Installation
sparrow-wifisparrow-wifi🔓 Cracking & Decryption
Hashcat
CrackingWorld's fastest password cracker with GPU acceleration. Supports WPA/WPA2/WPA3.
Installation
hashcat -m 22000 capture.hc22000 wordlist.txthashcat -m 22000 capture.hc22000 wordlist.txtJohn the Ripper
CrackingOpen-source password cracker with WiFi hash support via wpapsk format.
Installation
john --wordlist=rockyou.txt --format=wpapsk hashes.txtjohn --wordlist=rockyou.txt --format=wpapsk hashes.txtCowpatty
CrackingWPA-PSK dictionary attack tool with precomputed hash support.
Installation
cowpatty -f wordlist.txt -r capture.cap -s ESSIDcowpatty -f wordlist.txt -r capture.cap -s ESSIDPyrit
CrackingWPA/WPA2 cracker utilizing GPU and cloud computing for massive speed.
Installation
pyrit -r capture.cap -i wordlist.txt attack_passthroughpyrit -r capture.cap -i wordlist.txt attack_passthrough📻 Bluetooth & BLE Tools
Btlejack
BLEBluetooth Low Energy Swiss Army knife for sniffing, jamming, and hijacking.
Installation
btlejack -f 0x9c68fd30 -t -mbtlejack -f 0x9c68fd30 -t -mBettercap (BLE)
BLEBLE device discovery, MITM attacks, and characteristic manipulation.
Installation
bettercap --eval 'ble.recon on'bettercap --eval 'ble.recon on'Bluez
BluetoothOfficial Linux Bluetooth protocol stack with scanning and management tools.
Installation
hcitool scan; bluetoothctlhcitool scan; bluetoothctlUbertooth
HardwareOpen-source 2.4 GHz wireless development platform for Bluetooth experimentation.
Installation
ubertooth-btle -fubertooth-btle -fCrackle
BLECrack BLE encryption to decrypt captured traffic.
Installation
crackle -i capture.pcapcrackle -i capture.pcapGatttool
BLEGeneric Attribute Profile (GATT) tool for BLE device interaction.
Installation
gatttool -b AA:BB:CC:DD:EE:FF -Igatttool -b AA:BB:CC:DD:EE:FF -I📡 SDR & RF Tools
Universal Radio Hacker (URH)
SDRInvestigate wireless protocols like a boss with signal analysis, modulation, and reverse engineering.
Installation
urhurhGQRX
SDRSoftware-defined radio receiver powered by GNU Radio and Qt GUI.
Installation
gqrxgqrxGNU Radio
SDRFree software development toolkit for signal processing and SDR.
Installation
gnuradio-companiongnuradio-companionRFCrack
RFSoftware-defined radio attack tool for rolling code and frequency hopping.
Installation
python rfcrack.pypython rfcrack.pyInspectrum
AnalysisOffline radio signal analyser for visualizing captured RF data.
Installation
inspectrum capture.cu8inspectrum capture.cu8rtl_433
RFGeneric data receiver for ISM band devices (433.92 MHz, 868 MHz, 915 MHz).
Installation
rtl_433 -f 433.92Mrtl_433 -f 433.92M🖥️ Hardware
ALFA AWUS036ACH
WiFi AdapterDual-band AC1200 WiFi adapter with monitor mode and packet injection (chipset: RTL8812AU).
Installation
N/A - HardwareN/A - HardwareALFA AWUS036NHA
WiFi AdapterHigh-power 802.11n adapter, excellent for long-range attacks (chipset: AR9271).
Installation
N/A - HardwareN/A - HardwareTP-Link TL-WN722N v1
WiFi AdapterBudget-friendly adapter with monitor mode support (chipset: AR9271). Beware v2/v3!
Installation
N/A - HardwareN/A - HardwareWiFi Pineapple
PlatformPurpose-built pentesting platform for MITM, evil twin, and reconnaissance.
Installation
Web InterfaceWeb InterfaceHackRF One
SDRHalf-duplex SDR transceiver covering 1 MHz to 6 GHz. Hardware hacking workhorse.
Installation
hackrf_infohackrf_infoRTL-SDR
SDRBudget SDR receiver (RX only) for 500 kHz to 1.7 GHz. Perfect for learning.
Installation
rtl_testrtl_testUbertooth One
BluetoothOpen-source 2.4 GHz development platform specifically for Bluetooth research.
Installation
ubertooth-util -vubertooth-util -vYard Stick One
RFSub-1 GHz RF transceiver for testing <1 GHz wireless devices (RfCat compatible).
Installation
rfcat -rrfcat -rFlipper Zero
Multi-toolPortable multi-tool for pentesting and debugging digital hardware with sub-GHz, RFID, NFC, IR.
Installation
Web InterfaceWeb InterfaceProxmark3
RFID/NFCRFID/NFC research tool for reading, writing, and emulating RFID/NFC tags.
Installation
pm3pm3Wireless Finding Documentation
Wireless Pentesting Quick Reference
Hackers Manifest - hackersmanifest.com
Monitor Mode
sudo airmon-ng check kill sudo airmon-ng start wlan0 iwconfig wlan0mon aireplay-ng --test wlan0mon
Scanning
sudo airodump-ng wlan0mon sudo airodump-ng --band abg wlan0mon sudo airodump-ng -c 6 --bssid XX wlan0mon sudo kismet -c wlan0mon
WPA Cracking (hashcat modes)
22000 WPA-PMKID-PBKDF2 + EAPOL 5500 MSCHAPv2 (EAP Enterprise) 2500 WPA-PBKDF2 (legacy) hcxpcapngtool -o out.hc22000 in.pcapng
WPS Attacks
wash -i wlan0mon # scan WPS reaver -i wlan0mon -b BSSID # brute force bully wlan0mon -b BSSID -d # pixie dust wifite --kill --wps-only # auto
Deauth
aireplay-ng -0 5 -a AP -c STA wlan0mon aireplay-ng -0 0 -a AP wlan0mon # cont. sudo mdk4 wlan0mon d -b target.txt
MITRE ATT&CK Mapping
T1040 Network Sniffing (capture) T1557 AiTM / Evil Twin T1078 Valid Accounts (cred capture) T1110 Brute Force (WPS/hashcat) T1499 Endpoint DoS (deauth)
Generated from Hackers Manifest | For authorized security testing only | hackersmanifest.com