โ† All cheat sheets

KISMET

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Wireless network detector, sniffer, and IDS. Supports WiFi,
Bluetooth, SDR, and other wireless protocols.

INSTALLATION#

sudo apt install kismet                     # Kali/Debian
# Or from source: https://www.kismetwireless.net/docs/readme/installing/

# Add user to kismet group (avoids running as root)
sudo usermod -aG kismet $USER

STARTING KISMET#

# Start with auto-detected source
kismet

# Specify WiFi source
kismet -c wlan0

# Specify source with options
kismet -c wlan0:name=MyWiFi,hop=true,channels="1,6,11"

# Multiple sources
kismet -c wlan0 -c wlan1

# Start as daemon
kismet --daemonize

# Web UI access (default)
# http://localhost:2501
# First run creates admin credentials

CAPTURE SOURCES#

# WiFi
kismet -c wlan0                             # Standard WiFi
kismet -c wlan0mon                          # Monitor mode

# Bluetooth
kismet -c hci0:type=linuxbluetooth

# RTL-SDR (Software Defined Radio)
kismet -c rtl433-0:type=rtl433             # 433MHz devices
kismet -c rtladsb-0:type=rtladsb           # ADS-B aircraft

# Remote capture (distributed)
kismet_cap_linux_wifi --connect HOST:3501 --source wlan0

SOURCE OPTIONS#

# Channel hopping
kismet -c wlan0:hop=true                    # Enable hopping
kismet -c wlan0:hop=false,channel=6         # Lock to channel 6
kismet -c wlan0:channels="1,6,11"           # Specific channels
kismet -c wlan0:hoprate=5                   # Hops per second

# Band selection
kismet -c wlan0:band=2.4GHz
kismet -c wlan0:band=5GHz

WEB UI FEATURES#

# Dashboard
  - Live device count, packet rates, alerts
  - GPS mapping (if GPS connected)
  - Channel activity graph

# Devices view
  - All discovered wireless devices
  - Filter by type (AP, client, bridged, etc.)
  - Sort by signal strength, packets, time
  - Click device for details

# Device details
  - BSSID, ESSID, encryption type
  - Channel, frequency, signal strength
  - Connected clients
  - Packet counts and data rates
  - Manufacturer (OUI lookup)
  - GPS location (if available)

# Alerts
  - Rogue AP detection
  - Deauth flood detection
  - BSSID spoofing
  - Channel hopping anomalies

REST API#

# Kismet exposes a full REST API

# Get system status
curl http://localhost:2501/system/status.json \
  -H "KISMET: admin:password"

# List devices
curl http://localhost:2501/devices/all_devices.json \
  -H "KISMET: admin:password"

# Filter devices
curl -X POST http://localhost:2501/devices/summary/devices.json \
  -H "KISMET: admin:password" \
  -d '{"fields":["kismet.device.base.name","kismet.device.base.macaddr"]}'

# Get specific device
curl http://localhost:2501/devices/by-mac/AA:BB:CC:DD:EE:FF/devices.json \
  -H "KISMET: admin:password"

# Download PCAP
curl http://localhost:2501/datasource/by-uuid/UUID/pcap/capture.pcap \
  -H "KISMET: admin:password" -o capture.pcap

LOGGING#

# Kismet logs to .kismet files (SQLite database)

# Convert to other formats
kismetdb_to_pcap --in capture.kismet --out capture.pcap
kismetdb_to_wiglecsv --in capture.kismet --out wigle.csv
kismetdb_to_kml --in capture.kismet --out map.kml

# Log types
kismet -c wlan0 --log-types pcapng,kismet   # Multiple log types
kismet -c wlan0 --log-prefix mylog          # Custom prefix

WARDRIVE MODE#

# Combine with GPS for wardriving
kismet -c wlan0 --override wardrive

# GPS sources
gpsd                                        # gpsd daemon
kismet -c wlan0 --gps serial:/dev/ttyUSB0   # Serial GPS
kismet -c wlan0 --gps gpsd:host=localhost,port=2947

# Upload results to WiGLE.net
kismetdb_to_wiglecsv --in capture.kismet --out wigle.csv

DETECTION / IDS#

# Kismet detects:
  - New/unknown APs on network
  - Deauthentication floods
  - BSSID spoofing / evil twin APs
  - Probe request tracking
  - Channel hopping anomalies
  - Unusual client behavior
  - WPS attacks
  - KARMA attacks

TIPS#

  - Web UI at port 2501 is the primary interface
  - Add user to kismet group to avoid running as root
  - .kismet files are SQLite โ€” query with standard SQL tools
  - Use multiple WiFi adapters for better coverage
  - Channel locking is better for targeted capture
  - GPS integration enables wardrive mapping
  - REST API allows integration with custom tools
  - Supports remote capture for distributed sensing
  - Kismet can detect rogue APs and evil twins
  - Export to PCAP for detailed analysis in Wireshark