KISMET
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Wireless network detector, sniffer, and IDS. Supports WiFi, Bluetooth, SDR, and other wireless protocols.
INSTALLATION#
sudo apt install kismet # Kali/Debian # Or from source: https://www.kismetwireless.net/docs/readme/installing/ # Add user to kismet group (avoids running as root) sudo usermod -aG kismet $USER
STARTING KISMET#
# Start with auto-detected source kismet # Specify WiFi source kismet -c wlan0 # Specify source with options kismet -c wlan0:name=MyWiFi,hop=true,channels="1,6,11" # Multiple sources kismet -c wlan0 -c wlan1 # Start as daemon kismet --daemonize # Web UI access (default) # http://localhost:2501 # First run creates admin credentials
CAPTURE SOURCES#
# WiFi kismet -c wlan0 # Standard WiFi kismet -c wlan0mon # Monitor mode # Bluetooth kismet -c hci0:type=linuxbluetooth # RTL-SDR (Software Defined Radio) kismet -c rtl433-0:type=rtl433 # 433MHz devices kismet -c rtladsb-0:type=rtladsb # ADS-B aircraft # Remote capture (distributed) kismet_cap_linux_wifi --connect HOST:3501 --source wlan0
SOURCE OPTIONS#
# Channel hopping kismet -c wlan0:hop=true # Enable hopping kismet -c wlan0:hop=false,channel=6 # Lock to channel 6 kismet -c wlan0:channels="1,6,11" # Specific channels kismet -c wlan0:hoprate=5 # Hops per second # Band selection kismet -c wlan0:band=2.4GHz kismet -c wlan0:band=5GHz
WEB UI FEATURES#
# Dashboard - Live device count, packet rates, alerts - GPS mapping (if GPS connected) - Channel activity graph # Devices view - All discovered wireless devices - Filter by type (AP, client, bridged, etc.) - Sort by signal strength, packets, time - Click device for details # Device details - BSSID, ESSID, encryption type - Channel, frequency, signal strength - Connected clients - Packet counts and data rates - Manufacturer (OUI lookup) - GPS location (if available) # Alerts - Rogue AP detection - Deauth flood detection - BSSID spoofing - Channel hopping anomalies
REST API#
# Kismet exposes a full REST API
# Get system status
curl http://localhost:2501/system/status.json \
-H "KISMET: admin:password"
# List devices
curl http://localhost:2501/devices/all_devices.json \
-H "KISMET: admin:password"
# Filter devices
curl -X POST http://localhost:2501/devices/summary/devices.json \
-H "KISMET: admin:password" \
-d '{"fields":["kismet.device.base.name","kismet.device.base.macaddr"]}'
# Get specific device
curl http://localhost:2501/devices/by-mac/AA:BB:CC:DD:EE:FF/devices.json \
-H "KISMET: admin:password"
# Download PCAP
curl http://localhost:2501/datasource/by-uuid/UUID/pcap/capture.pcap \
-H "KISMET: admin:password" -o capture.pcap
LOGGING#
# Kismet logs to .kismet files (SQLite database) # Convert to other formats kismetdb_to_pcap --in capture.kismet --out capture.pcap kismetdb_to_wiglecsv --in capture.kismet --out wigle.csv kismetdb_to_kml --in capture.kismet --out map.kml # Log types kismet -c wlan0 --log-types pcapng,kismet # Multiple log types kismet -c wlan0 --log-prefix mylog # Custom prefix
WARDRIVE MODE#
# Combine with GPS for wardriving kismet -c wlan0 --override wardrive # GPS sources gpsd # gpsd daemon kismet -c wlan0 --gps serial:/dev/ttyUSB0 # Serial GPS kismet -c wlan0 --gps gpsd:host=localhost,port=2947 # Upload results to WiGLE.net kismetdb_to_wiglecsv --in capture.kismet --out wigle.csv
DETECTION / IDS#
# Kismet detects: - New/unknown APs on network - Deauthentication floods - BSSID spoofing / evil twin APs - Probe request tracking - Channel hopping anomalies - Unusual client behavior - WPS attacks - KARMA attacks
TIPS#
- Web UI at port 2501 is the primary interface - Add user to kismet group to avoid running as root - .kismet files are SQLite โ query with standard SQL tools - Use multiple WiFi adapters for better coverage - Channel locking is better for targeted capture - GPS integration enables wardrive mapping - REST API allows integration with custom tools - Supports remote capture for distributed sensing - Kismet can detect rogue APs and evil twins - Export to PCAP for detailed analysis in Wireshark