Skip to content

Aircrack-ng

Wi-Fi security audit suite for your own network

Needs reviewWireless· Wi-Fi AssessmentAdvancedGPL-2.0Open sourceEntry revised 5 Jan 2026
  • Linux
  • Kali
  • Parrot
  • Arch
  • Fedora
  • macOS
  • Docker
  • Source

Needs review. May lag the current upstream release. Verify before relying on it. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

8 commands documented

Aircrack-ng is a suite: interface tools to put a wireless card into monitor mode, capture tools to record frames, and analysis tools to test whether a pre-shared key protects a network. In practice it is used to answer one question about your own Wi-Fi: is this key guessable from a captured handshake?

Wireless testing is legally sensitive. Radio ranges overlap into neighbours' property, and many jurisdictions criminalise any access to a network you do not own. Restrict this tool to a network you own or have written permission to assess, and to the 2.4/5 GHz experimentation rules that apply where you live.

Supported platforms

8

Documented install or usage guidance

Learning curve

advanced

Difficulty of becoming productive, not of the underlying theory

Tags

wifi, handshake, wpa2, monitor mode, wireless, audit

Dataset entry

aircrack-ng.ts

Reviewed 2026-01-05

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

AlternativeHomebrew
brew install aircrack-ng
  • macOS driver support for monitor mode is effectively absent for most chips; the tools install but capture rarely works. Use Linux on the hardware instead.

Package availability follows your distribution and enabled repositories. Entry revised 5 Jan 2026 — confirm the current release on the project's own download page.

Commands

8 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01List wireless interfaces and capabilities

bash

Shows which cards exist and whether they advertise monitor-mode support.

iw list | grep -A6 'Supported interface modes'

Notes

  • `airmon-ng check kill` (next step) is the documented way to stop NetworkManager from stealing the interface.

02Enable monitor mode

bash

Creates a capture interface that records 802.11 frames instead of associating with a network.

sudo airmon-ng start wlan0
  • Requires a driver and card that support monitor mode and packet injection; this is the single most common blocker.

Notes

  • Newer kernels prefer `iw dev wlan0 interface add mon0 type monitor` — `airmon-ng` is a convenience wrapper, not magic.

03Passive scan of the local area

bash

Lists beacons and clients around you without transmitting anything.

sudo airodump-ng -w lab-scan mon0

Example output

Illustrative only — real output depends on the target, version and your position on the network.

BSSID  PWR  Beacon  #IVs  ENCRY  ESSID
AA:BB..  -42   100      0  WPA2   LAB-TEST

Notes

  • Stop with Ctrl+C. This records frames from every network in range — handle the capture file as third-party data even on your own bench.

04Capture from one BSS on one channel

bash

Narrows the recording to the network under test so the handshake is actually in the file.

sudo airodump-ng --bssid AA:BB:CC:DD:EE:FF -c 6 -w lab-handshake mon0

Notes

  • Locking the channel is essential; hopping loses the EAPOL frames you came for.

05Verify a capture contains a usable handshake

bash

Checks the recorded file for four-way EAPOL frames before you spend time on attacks.

aircrack-ng -J lab-handshake-01.cap

Example output

Illustrative only — real output depends on the target, version and your position on the network.

01 handshake (0 EAPOL) found? yes

Notes

  • `wpaclean` and `tcpdump -r file -e` are the fallback checks when a capture is partial.

06Test a passphrase against a captured handshake

bash

Runs a wordlist offline against the recorded EAPOL frames — no client traffic required after capture.

aircrack-ng -w /usr/share/wordlists/wifi.txt lab-handshake-01.cap
  • Offline key testing is only lawful against a network you own or are explicitly authorized to assess.

Notes

  • PMF/protected management frames on WPA3-Personal (SAE) make the classic capture-then-crack path far weaker; that is the point of enabling it.

07Capture a PMKID and test it offline

bash

The pre-shared-key derivation material can sometimes be taken from a single beacon-adjacent frame, without deauthenticating anyone.

hcxdumptool -i mon0 -o pmkid.pcapng --status=1
  • Deliberately disconnecting clients (deauth) is disruptive and, in most places, unlawful outside your own network. Prefer the passive route and note that some tooling in this area is dual-use.

Notes

  • `hcxpsktool` and `hcxpcapngtool` convert captures into hashcat's PMKID format for a wordlist test.

08Hand the capture to a GPU cracker

bash

Converts the WPA material and lets hashcat work through the list at GPU speed.

hcxpcapngtool -o wpahash.22000 lab-handshake-01.cap

Notes

  • Then: `hashcat -m 22000 wpahash.22000 wordlist.txt`. Mode 22000 is the modern PMKID/EAPOL format.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Checking your own lab router's passphrase strength

A bench router with WPA2-PSK, one client, nothing else in scope.

  1. 1

    Confirm the card can do monitor mode

    sudo iw dev wlan0 interface add mon0 type monitor && sudo ip link set mon0 up
  2. 2

    Record the network passively

    sudo airodump-ng --bssid AA:BB:CC:DD:EE:FF -c 6 -w lab mon0
  3. 3

    Test the passphrase against the capture

    aircrack-ng -w my-own-testlist.txt lab-01.cap

Either the passphrase falls to your list (change it and prefer WPA3/PMF), or it does not. Record which, plus the candidate count covered.

What it is used for

  • Home/lab wireless hardening

    Prove a passphrase is not dictionary-derivable before a real attacker tries.

  • Driver and adapter evaluation

    Check which chipsets support capture and injection for a survey rig.

  • Radio coursework

    Read 802.11 frame structure in a controlled environment.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"No such device" / mon0 disappears immediatelyCause 1/4

Possible causes

  • Driver does not support monitor mode via airmon-ng, or a network service reclaims the interface.

Usual fix

Stop NetworkManager for the duration, or create the interface with `iw` directly; verify with `iw dev`.

sudo airmon-ng check kill
sudo systemctl stop NetworkManager
Capture runs, but '0 handshake' at the endCause 2/4

Possible causes

  • No client associated during the window, channel hopping left the target, or the card does not capture data frames.

Usual fix

Lock `-c` to the AP's channel, keep capturing until you see an EAPOL line in the header, and confirm the chipset's reputation for capture.

Injection test reports 'is not working'Cause 3/4

Possible causes

  • The driver drops injected frames (very common with built-in laptop cards).

Usual fix

Use a chipset documented for injection, and verify with `aireplay-ng --test` on the monitor interface before anything else.

aircrack-ng runs forever with no key foundCause 4/4

Possible causes

  • The passphrase is not in the list. This is a normal result, not an error.

Usual fix

Bound the run (`--timer 600`), record the tested candidate count, and stop rather than letting it grind for days.

Tips

  • Chipset before tooling: buy an adapter with documented monitor + injection support and you skip 80% of the troubleshooting.
  • Keep captures small and delete them after the audit — they contain other people's frames.
  • Prefer WPA3-SAE with PMF enabled; the audit result is the same either way, but the protection is real.
  • Read your national rules on radio interception before any test beyond your own network. This is not a formality.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Wireless