black electronics

Setup and Discovery

Wireless Setup and Discovery

Wireless Setup and Discovery

Preparing a wireless adapter and discovering nearby networks is the foundation of any Wi-Fi assessment. This section covers adapter drivers, monitor mode, transmit power, Kismet, and site-survey and discovery tooling such as airodump-ng, Kismet and Bettercap.

Wireless Adapter and Drivers

A wireless assessment needs an adapter that supports monitor mode and packet injection. Realtek-based adapters such as the Alfa AWUS036ACH are common choices, and usually require an out-of-tree driver on Kali.

Installing Realtek Drivers (rtl8812au / rtl88xxau)

Terminal window
# Preferred: install the packaged driver
sudo apt install realtek-rtl88xxau-dkms
# Plug in the NIC. In a Kali VM, attach the adapter under
# Settings -> Ports -> USB (select USB 3.0) and add the "Realtek 802.11n NIC" filter.
# Build the aircrack-ng rtl8812au driver from source
git clone -b v5.6.4.2 https://github.com/aircrack-ng/rtl8812au.git
cd rtl8812au
sudo ./dkms-install.sh
Terminal window
# 2024 rebuild sequence if the driver breaks after an update
# 1. Unplug the USB adapter
# 2. Find the installed dkms module name
dkms status
# 3. Remove the old driver (replace <module name> with the value above)
sudo dkms remove <module name> --all
# 4. Restart the VM
# 5. Delete the old git folder (rtl8812au)
# 6. Re-clone and build a known-working commit
git clone https://github.com/aircrack-ng/rtl8812au.git
cd rt*
sudo apt-get update
sudo apt-get install bc mokutil build-essential libelf-dev linux-headers-`uname -r`
sudo apt-get upgrade
git checkout 63cf0b4 # set to the known-working version
git status
sudo make
sudo make install
sudo service NetworkManager restart
# 7. Plug in the USB adapter

Alfa AWUS036ACH

Terminal window
# Driver source and concurrent-mode patch
https://github.com/ivanovborislav/rtl8812au
# Alfa AWUS036ACH (2025) build
sudo apt update
sudo apt upgrade
sudo apt-get dist-upgrade
sudo apt install linux-headers-$(uname -r | sed 's,[^-]*-[^-]*-,,')
git clone https://github.com/morrownr/8812au-20210820
cd 8812au-20210820
sudo ./install-driver.sh

Adapter Troubleshooting

Terminal window
# If Wi-Fi will not connect after driver install
sudo systemctl stop wpa_supplicant.service
sudo systemctl mask wpa_supplicant.service
reboot
sudo systemctl unmask wpa_supplicant.service
sudo systemctl start wpa_supplicant.service
# On Parrot etc. if your USB Wi-Fi adapter is given a long interface name
sudo ln -s /dev/null /etc/udev/rules.d/80-net-setup-link.rules

Monitor Mode

The quickest way to enable monitor mode is airmon-ng; the manual method with ip/iw is more reliable on some adapters and lets you kill interfering processes first.

Terminal window
# Check the wireless device
iwconfig
iw dev wlan0 info
# Quick method
sudo airmon-ng start wlan0
sudo airodump-ng wlan0mon
# Kill processes that interfere with monitor mode
sudo airmon-ng check kill
# Manual method
sudo ip link set wlan0 down
sudo iw dev wlan0 set type monitor # or: sudo iwconfig wlan0 mode monitor
sudo ip link set wlan0 up
# Return the card to managed mode
sudo ip link set wlan0 down
sudo iw dev wlan0 set type managed
sudo service networking restart
sudo service NetworkManager restart
sudo ip link set wlan0 up

Adjusting TX Power and Channel

Terminal window
# Set transmit power and channel
sudo iwconfig wlan0 txpower 30
sudo iw wlan0 set channel 6
# View / change the channel of a monitor interface
iwlist mon0 channel
iwconfig mon0 channel 3

Installing Kismet

Terminal window
# Kismet
wget -O - https://www.kismetwireless.net/repos/kismet-release.gpg.key | sudo apt-key add -
echo 'deb https://www.kismetwireless.net/repos/apt/git/kali kali main' | sudo tee /etc/apt/sources.list.d/kismet.list
sudo apt update
sudo apt install kismet
sudo apt install kismet-capture-linux-wifi kismet-capture-linux-bluetooth kismet-logtools
# Additional wireless tooling
sudo apt-get install hcxtools

Network Discovery and Site Survey

Identify approved and rogue access points, the clients associated to them, and any traffic leaking outside the intended coverage area.

airodump-ng

Terminal window
# Detect surrounding networks in monitor mode
sudo airodump-ng wlan0mon
# See only network SSIDs quickly
iw dev wlan0 scan | grep SSID
# Target a specific AP on its channel and write a capture
sudo airodump-ng -c <channel> --bssid AA:BB:CC:DD:EE:FF -w capture wlan0mon

Kismet and Bettercap

Terminal window
# Kismet
sudo kismet -c wlan0
# Web UI: http://127.0.0.1:2501/
# Bettercap
sudo bettercap -caplet http-ui -iface wlan0 # default creds: user:pass
# Web UI: http://127.0.0.1:80/
# Bettercap recon from the CLI
sudo bettercap -iface wlan0
wifi.recon on
set wifi.show.sort clients desc
set ticker.commands 'clear; wifi.show'
set ticker.period 5
ticker on

nmcli

Terminal window
sudo nmcli dev wifi list

Scanning for WPS-Enabled Networks

Terminal window
# wash lists WPS-enabled access points (see the WPS page for the attacks)
sudo wash --interface wlan0 --scan --survey

Reference Commands

Terminal window
# Set / view the channel of the monitor interface
iwconfig mon0 channel 3
iwlist mon0 channel
# Injection test
sudo aireplay-ng -9 wlan0mon
Useful LinksPentest PayloadsCheat Sheets