The complete Wi-Fi audit suite: passively capture the 4-way handshake, then crack it offline. Nothing teaches 'passwords are the weakest link' like cracking WPA yourself.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Needs a USB adapter that supports monitor mode (Alfa cards are the classic choice).
Maps who's around: channels, encryption, clients.
Lock onto one AP+channel and wait for a client to reconnect.
Legal ONLY on your own AP โ jamming radios is illegal broadly.
Handshakes crack offline โ no AP interaction needed now.
| airmon-ng | monitor mode control |
| airodump-ng | capture frames |
| aireplay-ng | inject / deauth |
| aircrack-ng -w | wordlist crack |
| -c / --bssid | channel / AP filter |
| hcxdumptool | PMKID modern path |
Do the free official 'Getting Started' tutorial โ it's a legendary first lab.
Clientless PMKID (hcxdumptool โ hashcat -m 22000) is the modern move.
Weak-PIN routers: reaver/bully โ mostly dead, still exam-worthy.
Defense lesson you just proved: long random passphrases are uncrackable in practice.
Use Aircrack-ng suite only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.