12 dépôts
Interception of security frames from wireless networks to analyze authentication and recover passwords.
Distinct from Wireless Security Auditing: Focuses specifically on the capture of WPA/WPA2 handshakes for offline cracking, rather than general wireless protocol auditing.
Explore 12 awesome GitHub repositories matching security & cryptography · Handshake Captures. Refine with filters or upvote what's useful.
This project is a WPA Wi-Fi cracking toolkit designed for capturing authentication handshakes and recovering WPA/WPA2 passwords. It provides specialized utilities for scanning wireless networks, obfuscating hardware addresses, and generating password lists to facilitate security audits. The toolkit differentiates itself through a focused workflow that combines handshake capture tools with a password wordlist generator. It enables the interception of the four-way authentication process between wireless clients and access points and utilizes these captured credentials for recovery via dictionar
Sends forged management frames to force client reconnections and capture WPA four-way handshakes.
ESP32Marauder is a suite of specialized firmware images and tools designed for wireless network auditing, packet sniffing, and Bluetooth scanning on ESP32 hardware. It functions as a wireless penetration tool used to analyze network security and monitor signal traffic. The project includes capabilities for capturing wireless handshakes and simulating access points to test infrastructure resilience. It also features a Bluetooth low energy scanner used to identify hardware signatures and detect unauthorized signals or skimming devices. The firmware supports broader security operations includin
Provides capabilities to intercept security handshakes from wireless networks for password recovery analysis.
Pwnagotchi is an AI-powered wireless auditor and handshake capture tool that uses deep reinforcement learning to autonomously collect wireless security handshakes and crackable key material. It serves as an automation framework for network instrumentation, adapting its operational parameters based on the local wireless environment to maximize data collection. The system distinguishes itself through distributed coordination, allowing multiple hardware units to share presence and divide wireless channels to optimize collective capture and perform distributed wireless mapping. It incorporates ge
Autonomously captures WPA/WPA2 handshakes for offline password recovery using an AI-driven approach.
airgeddon is a bash-based wireless network audit suite and security toolkit for Linux. It serves as a framework for testing wireless vulnerabilities and verifying network configurations across various encryption standards, including WPA, WEP, and WPS. The project functions as an orchestration layer that integrates a collection of third-party wireless security tools. It features a modular approach to attack vectorization, coordinating tasks such as evil twin simulations with captive portals, WPA handshake interception, and the execution of WPS vulnerability tests. Its capabilities cover a bro
Collects network handshake files and identifiers to facilitate offline security analysis.
Wifite2 is an automated wireless network security auditor and password recovery suite. It coordinates multiple external auditing tools to scan for wireless networks and execute attacks to recover WEP, WPA, and WPS passwords. The project specializes in a variety of encryption attack vectors, including the interception of four-way handshakes and PMKID hash extraction for offline cracking. It provides dedicated capabilities for breaking legacy WEP encryption via fragmentation and packet replay, as well as recovering wireless keys through WPS PIN brute-force and Pixie-Dust attacks. The tool auto
Intercepts four-way handshakes and PMKID hashes from access points for offline password cracking.
Fluxion is a wireless security auditing framework that tests WPA/WPA2 networks by capturing handshakes and deploying rogue access points with captive portals. It operates by deauthenticating clients from legitimate access points, forcing them to reconnect to a cloned network where a fake authentication page collects the network passphrase. The tool distinguishes itself through a plugin-based attack lifecycle with mandatory hook functions for consistent execution, multilingual metadata scripts that load attack descriptions based on locale, and a handshake verification pipeline that validates c
Captures the 4-way authentication handshake from a target access point by listening or deauthenticating.
This firmware transforms an ESP32 device into a portable penetration testing platform by combining an embedded JavaScript runtime with multi-protocol wireless attack capabilities, USB and Bluetooth HID emulation, and a menu-driven user interface. It is designed as a unified system that integrates persistent storage, hardware abstraction for external radio modules, a serial command protocol for headless operation, and a web-based remote desktop that streams the device screen and relays button inputs for remote control. The custom JavaScript scripting environment enables users to write and run
Captures and cracks WPA/WPA2 handshakes using a wordlist to recover network passwords.
lscript est un framework de pentesting de réseau sans fil et une console de commande pilotée par clavier. Il fonctionne comme un orchestrateur d'outils de sécurité pour installer et gérer des frameworks de reconnaissance, aux côtés d'une boîte à outils d'automatisation pour exécuter des attaques sans fil. Le projet se distingue par une interface pilotée par clavier qui mappe des frappes spécifiques à des scripts de sécurité complexes et des opérations shell au niveau du système. Cela permet l'automatisation des flux de travail de reconnaissance sans fil, de capture de handshake et de récupération de mot de passe sans saisie manuelle de commandes. Le système couvre la gestion des adaptateurs sans fil, y compris l'usurpation d'adresse MAC et le basculement en mode moniteur. Il fournit des capacités pour l'analyse réseau via le scan sans fil et la surveillance de handshake, ainsi que des tests de sécurité via l'injection de paquets, la désauthentification de clients et l'automatisation des flux de travail d'exploitation.
Intercepts security frames from wireless networks to capture handshakes for offline password recovery.
Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe
Includes a tool to monitor wireless traffic and capture WPA handshakes for password verification and recovery.
This project is a wireless network security toolkit designed for monitoring wireless traffic and exploiting vulnerabilities in network authentication protocols. It provides a suite of tools for scanning networks, capturing authentication handshakes, and testing the security of wireless access points. The toolkit includes a password wordlist generator to create custom lists for offline key recovery and a handshake cracker to recover encrypted keys using brute-force methods. It also features a vulnerability scanner specifically for testing the security of the Wireless Protected Setup pin system
Intercepts WPA/WPA2 authentication security frames to analyze authentication and recover passwords.
Hijacker is a Wi-Fi security auditing suite designed for scanning wireless networks, capturing traffic, and recovering credentials. It provides a set of tools for detecting nearby access points and clients, intercepting WPA handshakes, and recovering WPA and WEP passwords. The project features a visual security audit interface that allows for the execution of specialized tools without using a command-line terminal. It includes a dedicated WPS pin recovery tool for extracting access point pins using pixie-dust attacks via external adapters. The toolkit covers network reconnaissance, including
Intercepts WPA security frames from wireless networks to enable offline password recovery.
WiFiBroot est un utilitaire en ligne de commande conçu pour l'audit de sécurité des réseaux sans fil et les tests d'intrusion. Il se concentre sur l'évaluation de la sécurité des réseaux WPA et WPA2 en capturant les handshakes d'authentification et en testant la résilience des points d'accès et des clients connectés. L'outil incorpore un framework d'attaque de désauthentification qui force les déconnexions des clients pour faciliter l'interception des données de handshake. Il utilise une reconstruction avec état pour assembler des échanges cryptographiques complets à partir du trafic sans fil fragmenté, qui sont ensuite utilisés pour la récupération hors ligne des identifiants. Le logiciel prend en charge les tests de stress réseau en évaluant comment les points d'accès gèrent les déconnexions forcées et les interruptions de trafic. Il tire parti du calcul parallélisé pour distribuer la charge de travail des tests de candidats de mots de passe sur plusieurs cœurs de processeur, tout en utilisant des techniques d'injection et de capture de paquets de bas niveau pour interagir directement avec le médium sans fil.
Intercepts WPA and WPA2 authentication handshakes from local traffic to enable offline password recovery.