Wireless Setup and Discovery
Preparing a wireless adapter and discovering nearby networks is the foundation of any Wi-Fi assessment. This section covers adapter drivers, monitor mode, transmit power, Kismet, and site-survey and discovery tooling such as airodump-ng, Kismet and Bettercap.
Wireless Adapter and Drivers
A wireless assessment needs an adapter that supports monitor mode and packet injection. Realtek-based adapters such as the Alfa AWUS036ACH are common choices, and usually require an out-of-tree driver on Kali.
Installing Realtek Drivers (rtl8812au / rtl88xxau)
# Preferred: install the packaged driversudo apt install realtek-rtl88xxau-dkms
# Plug in the NIC. In a Kali VM, attach the adapter under# Settings -> Ports -> USB (select USB 3.0) and add the "Realtek 802.11n NIC" filter.
# Build the aircrack-ng rtl8812au driver from sourcegit clone -b v5.6.4.2 https://github.com/aircrack-ng/rtl8812au.gitcd rtl8812ausudo ./dkms-install.sh# 2024 rebuild sequence if the driver breaks after an update# 1. Unplug the USB adapter# 2. Find the installed dkms module namedkms status# 3. Remove the old driver (replace <module name> with the value above)sudo dkms remove <module name> --all# 4. Restart the VM# 5. Delete the old git folder (rtl8812au)# 6. Re-clone and build a known-working commitgit clone https://github.com/aircrack-ng/rtl8812au.gitcd rt*sudo apt-get updatesudo apt-get install bc mokutil build-essential libelf-dev linux-headers-`uname -r`sudo apt-get upgradegit checkout 63cf0b4 # set to the known-working versiongit statussudo makesudo make installsudo service NetworkManager restart# 7. Plug in the USB adapterAlfa AWUS036ACH
# Driver source and concurrent-mode patchhttps://github.com/ivanovborislav/rtl8812au
# Alfa AWUS036ACH (2025) buildsudo apt updatesudo apt upgradesudo apt-get dist-upgradesudo apt install linux-headers-$(uname -r | sed 's,[^-]*-[^-]*-,,')git clone https://github.com/morrownr/8812au-20210820cd 8812au-20210820sudo ./install-driver.shAdapter Troubleshooting
# If Wi-Fi will not connect after driver installsudo systemctl stop wpa_supplicant.servicesudo systemctl mask wpa_supplicant.servicerebootsudo systemctl unmask wpa_supplicant.servicesudo systemctl start wpa_supplicant.service
# On Parrot etc. if your USB Wi-Fi adapter is given a long interface namesudo ln -s /dev/null /etc/udev/rules.d/80-net-setup-link.rulesMonitor Mode
The quickest way to enable monitor mode is airmon-ng; the manual method with ip/iw is more reliable on some adapters and lets you kill interfering processes first.
# Check the wireless deviceiwconfigiw dev wlan0 info
# Quick methodsudo airmon-ng start wlan0sudo airodump-ng wlan0mon
# Kill processes that interfere with monitor modesudo airmon-ng check kill
# Manual methodsudo ip link set wlan0 downsudo iw dev wlan0 set type monitor # or: sudo iwconfig wlan0 mode monitorsudo ip link set wlan0 up
# Return the card to managed modesudo ip link set wlan0 downsudo iw dev wlan0 set type managedsudo service networking restartsudo service NetworkManager restartsudo ip link set wlan0 upAdjusting TX Power and Channel
# Set transmit power and channelsudo iwconfig wlan0 txpower 30sudo iw wlan0 set channel 6
# View / change the channel of a monitor interfaceiwlist mon0 channeliwconfig mon0 channel 3Installing Kismet
# Kismetwget -O - https://www.kismetwireless.net/repos/kismet-release.gpg.key | sudo apt-key add -echo 'deb https://www.kismetwireless.net/repos/apt/git/kali kali main' | sudo tee /etc/apt/sources.list.d/kismet.listsudo apt updatesudo apt install kismetsudo apt install kismet-capture-linux-wifi kismet-capture-linux-bluetooth kismet-logtools
# Additional wireless toolingsudo apt-get install hcxtoolsNetwork Discovery and Site Survey
Identify approved and rogue access points, the clients associated to them, and any traffic leaking outside the intended coverage area.
airodump-ng
# Detect surrounding networks in monitor modesudo airodump-ng wlan0mon
# See only network SSIDs quicklyiw dev wlan0 scan | grep SSID
# Target a specific AP on its channel and write a capturesudo airodump-ng -c <channel> --bssid AA:BB:CC:DD:EE:FF -w capture wlan0monKismet and Bettercap
# Kismetsudo kismet -c wlan0# Web UI: http://127.0.0.1:2501/
# Bettercapsudo bettercap -caplet http-ui -iface wlan0 # default creds: user:pass# Web UI: http://127.0.0.1:80/
# Bettercap recon from the CLIsudo bettercap -iface wlan0wifi.recon onset wifi.show.sort clients descset ticker.commands 'clear; wifi.show'set ticker.period 5ticker onnmcli
sudo nmcli dev wifi listScanning for WPS-Enabled Networks
# wash lists WPS-enabled access points (see the WPS page for the attacks)sudo wash --interface wlan0 --scan --surveyReference Commands
# Set / view the channel of the monitor interfaceiwconfig mon0 channel 3iwlist mon0 channel
# Injection testsudo aireplay-ng -9 wlan0mon


