Guides authorized Wi-Fi security assessments: capture, WPA handshake analysis, rogue AP detection and lab-only deauth testing.
- What it does
- This skill provides an instructional workflow for authorized wireless security assessments. It covers entering monitor mode, locking onto a target BSSID and channel, capturing WPA/WPA2 handshakes or PMKIDs, and running offline password-policy evaluation with hashcat or aircrack-ng. It also addresses rogue AP and captive-portal research and expects a report covering encryption type, client isolation, portal bypass and hardening recommendations.
- When to use it
- Use it when conducting a legally authorized wireless security assessment with written permission and a defined physical scope. It suits WPA/WPA2 handshake capture and offline evaluation, rogue AP or evil-twin detection research, and enterprise wireless isolation and portal security reviews.
- Requirements
- Instructions only; no scripts are shipped. It assumes a wireless adapter capable of monitor mode and tools such as the aircrack-ng suite, hcxdumptool/hcxtools, hashcat and Wireshark, plus written authorization and a defined target scope. It references a bundled rules file and related pentest skills.