Homebrew
AlternativeHomebrewbrew install aircrack-ng
- macOS driver support for monitor mode is effectively absent for most chips; the tools install but capture rarely works. Use Linux on the hardware instead.
Wi-Fi security audit suite for your own network
Needs review. May lag the current upstream release. Verify before relying on it. Cross-check against the upstream documentation before relying on a command.
Aircrack-ng is a suite: interface tools to put a wireless card into monitor mode, capture tools to record frames, and analysis tools to test whether a pre-shared key protects a network. In practice it is used to answer one question about your own Wi-Fi: is this key guessable from a captured handshake?
Wireless testing is legally sensitive. Radio ranges overlap into neighbours' property, and many jurisdictions criminalise any access to a network you do not own. Restrict this tool to a network you own or have written permission to assess, and to the 2.4/5 GHz experimentation rules that apply where you live.
Supported platforms
8
Documented install or usage guidance
Learning curve
advanced
Difficulty of becoming productive, not of the underlying theory
Tags
wifi, handshake, wpa2, monitor mode, wireless, audit
Dataset entry
aircrack-ng.ts
Reviewed 2026-01-05
Grouped by platform. Elevation requirements are marked per method.
brew install aircrack-ng
Needs elevated privileges (sudo / Administrator).
sudo apt update
sudo apt install aircrack-ng
sudo pacman -S aircrack-ng
sudo dnf install aircrack-ng
Needed when your distribution's version lacks support for a newer driver or for pcap with monitor headers.
Needs elevated privileges (sudo / Administrator).
sudo apt install build-essential autoconf libtool pkg-config libnl-3-dev libnl-genl-3-dev libssl-dev
./autogen.sh && ./configure && make -j$(nproc) && sudo make install
Package availability follows your distribution and enabled repositories. Entry revised 5 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Shows which cards exist and whether they advertise monitor-mode support.
iw list | grep -A6 'Supported interface modes'
Notes
Creates a capture interface that records 802.11 frames instead of associating with a network.
sudo airmon-ng start wlan0
Notes
Lists beacons and clients around you without transmitting anything.
sudo airodump-ng -w lab-scan mon0
Example output
Illustrative only — real output depends on the target, version and your position on the network.
BSSID PWR Beacon #IVs ENCRY ESSID AA:BB.. -42 100 0 WPA2 LAB-TEST
Notes
Narrows the recording to the network under test so the handshake is actually in the file.
sudo airodump-ng --bssid AA:BB:CC:DD:EE:FF -c 6 -w lab-handshake mon0
Notes
Checks the recorded file for four-way EAPOL frames before you spend time on attacks.
aircrack-ng -J lab-handshake-01.cap
Example output
Illustrative only — real output depends on the target, version and your position on the network.
01 handshake (0 EAPOL) found? yes
Notes
Runs a wordlist offline against the recorded EAPOL frames — no client traffic required after capture.
aircrack-ng -w /usr/share/wordlists/wifi.txt lab-handshake-01.cap
Notes
The pre-shared-key derivation material can sometimes be taken from a single beacon-adjacent frame, without deauthenticating anyone.
hcxdumptool -i mon0 -o pmkid.pcapng --status=1
Notes
Converts the WPA material and lets hashcat work through the list at GPU speed.
hcxpcapngtool -o wpahash.22000 lab-handshake-01.cap
Notes
Sequences of commands in the order they are used, with what you should expect to learn from each.
A bench router with WPA2-PSK, one client, nothing else in scope.
Confirm the card can do monitor mode
sudo iw dev wlan0 interface add mon0 type monitor && sudo ip link set mon0 up
Record the network passively
sudo airodump-ng --bssid AA:BB:CC:DD:EE:FF -c 6 -w lab mon0
Test the passphrase against the capture
aircrack-ng -w my-own-testlist.txt lab-01.cap
Either the passphrase falls to your list (change it and prefer WPA3/PMF), or it does not. Record which, plus the candidate count covered.
Prove a passphrase is not dictionary-derivable before a real attacker tries.
Check which chipsets support capture and injection for a survey rig.
Read 802.11 frame structure in a controlled environment.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Stop NetworkManager for the duration, or create the interface with `iw` directly; verify with `iw dev`.
sudo airmon-ng check kill
sudo systemctl stop NetworkManager
Possible causes
Usual fix
Lock `-c` to the AP's channel, keep capturing until you see an EAPOL line in the header, and confirm the chipset's reputation for capture.
Possible causes
Usual fix
Use a chipset documented for injection, and verify with `aireplay-ng --test` on the monitor interface before anything else.
Possible causes
Usual fix
Bound the run (`--timer 600`), record the tested candidate count, and stop rather than letting it grind for days.
Where to verify anything on this page. External links open in a new tab.
Wifite, Hashcat cover adjacent parts of the same job.