A one-month, lab-driven curriculum that takes a learner from wireless fundamentals to enterprise Wi-Fi penetration testing — 802.11 standards and encryption, monitor-mode capture, reconnaissance and traffic analysis, WEP/WPA/WPA2 cracking, WPA3 and TKIP attacks, rogue access points and wireless MITM, and enterprise (EAP/RADIUS) assessment with professional reporting.
Curriculum home: Vault Catalog
Course Information
| Property | Value |
|---|---|
| Course Title | Wireless Security & WiFi Penetration Testing |
| Folder | Wireless-Security-and-WiFi-Penetration-Testing/ |
| Tag | Wireless Security |
| Slug | wifi-pentest |
| Level | Advanced |
| Duration | 1 Month (4 Weeks · ~30 Hours) |
| Focus | Wireless Penetration Testing |
| Reference Platform | Kali Linux · injection-capable adapters (Atheros AR9271 · Ralink RT3070) |
| Modules | 14 |
| Delivery | Self-paced notes + hands-on labs |
| Language | English |
[!NOTE] What this course is A study-and-practice track built as an Obsidian knowledge base. Each module is a folder with its own
Readmehub and a set of single-topic notes containing tagged, copy-ready command snippets. It is designed to be read in order but is fully cross-linked for reference use.
Course Description
Master wireless security testing and Wi-Fi penetration testing end to end: 802.11 standards and frame types, encryption and authentication (WEP, WPA/TKIP, WPA2/CCMP, WPA3), adapter setup for monitor mode and packet injection, reconnaissance and traffic analysis, security-control bypass, denial-of-service, WEP cracking, Chop-Chop and packet-replay attacks, the Caffe Latte client-side attack, WPA/WPA2 handshake and PMKID cracking, Cowpatty and precomputed-table attacks, advanced WPA-TKIP and WPA3 (KRACK/Dragonblood) attacks, rogue access points and wireless MITM — then apply those skills to enterprise WPA (EAP/RADIUS) assessment, wireless hardening, and penetration-test reporting.
The program is delivered through reproducible, hands-on labs against equipment you own and control, so every technique is paired with a working capture, attack, or configuration you can build, break, and defend.
[!WARNING] Authorized testing only Every technique here is documented for education, detection, and defense. Wireless attacks — deauthentication, jamming, rogue access points, handshake capture, and key cracking — are illegal against networks you do not own or lack explicit written permission to assess. Practice only in your own isolated RF lab, a CTF, or a sanctioned engagement.
Overview
The Wireless Security & WiFi Penetration Testing program provides practical, assessment-ready skills across wireless reconnaissance, attack, and defense. It is designed for ethical hackers, penetration testers, red-team operators, and wireless security analysts, and progresses from 802.11 fundamentals to advanced enterprise attacks.
By the end of the course, students will be able to:
- Configure wireless adapters for monitor mode and packet injection
- Discover hidden SSIDs and enumerate wireless infrastructure
- Perform wireless DoS and deauthentication attacks
- Crack WEP encryption using multiple attack techniques
- Capture and crack WPA/WPA2 handshakes and PMKIDs
- Deploy evil-twin and rogue access-point attacks
- Conduct wireless Man-in-the-Middle attacks
- Perform advanced WPA/TKIP and WPA3 exploitation
- Assess enterprise WPA (EAP/RADIUS) deployments
- Provide wireless hardening and remediation recommendations
[!TIP] Offense and defense are taught together Every attack module pairs the exploit with its detection and mitigation — deauth floods with 802.11w/management-frame protection, rogue APs with WIDS, weak PSKs with policy — so the skills transfer directly to defending the same networks.
Learning Path
The 14 modules are sequenced into four progressive phases. Complete each phase before advancing; later attack and enterprise modules assume the fundamentals and a capture-capable lab from earlier phases.
Phase 1 Fundamentals ....... Wireless Networks · Encryption & Authentication · Adapters
Phase 2 Recon & Bypass ..... Security Measures & Bypass · Reconnaissance & Traffic Analysis
Phase 3 Attacks ............ DoS · MITM/Rogue APs · WEP · Chop-Chop · Caffe Latte
WPA/WPA2 · Cowpatty · Advanced WPA-TKIP/WPA3
Phase 4 Enterprise ......... Enterprise WPA (EAP/RADIUS) · Hardening · Reporting
flowchart LR
A[Phase 1<br/>Fundamentals] --> B[Phase 2<br/>Recon & Bypass]
B --> C[Phase 3<br/>Attacks]
C --> D[Phase 4<br/>Enterprise & Reporting]
[!IMPORTANT] Prerequisite chaining The attack phases assume a capture-capable lab from Phase 1 and the discovery skills from Phase 2. Attempting a WPA/WPA2 handshake crack or an evil-twin attack without a monitor-mode, injection-capable adapter and clean reconnaissance will fail in ways that are hard to diagnose — complete each phase before advancing.
Prerequisites
| Requirement | Level | Notes |
|---|---|---|
| Basic networking knowledge | Required | IP addressing, TCP/IP, ports |
| Linux command-line familiarity | Required | All tooling is Kali-based |
| Basic cybersecurity concepts | Recommended | Reinforced in-course |
| An injection-capable Wi-Fi adapter | Required | See Hardware Requirements |
| Prior wireless experience | Not required | Course starts from 802.11 basics |
[!TIP] No wireless background needed Phase 1 assumes no prior 802.11 knowledge. If you already run wireless assessments, you can skim the fundamentals and start at Reconnaissance & Bypass.
Software Requirements
All tooling runs on Kali Linux, which ships most of these packages preinstalled; the rest are a single apt install away. The core of wireless testing is the aircrack-ng suite, complemented by capture, cracking, and rogue-AP utilities.
| Component | Recommended | Purpose |
|---|---|---|
| Base OS | Kali Linux | Tooling distribution |
| Cracking suite | aircrack-ng (airodump-ng, aireplay-ng, airbase-ng) | WEP/WPA/WPA2 capture and cracking |
| GPU cracking | hashcat | WPA/WPA2/PMKID key recovery |
| PMKID capture | hcxdumptool / hcxtools | Capture and hash-format conversion |
| WPS attacks | reaver, bully, wash | WPS PIN brute-forcing |
| Detection / IDS | kismet | Sniffing and wireless IDS |
| Traffic analysis | wireshark, tcpdump, bettercap | 802.11 packet analysis and MITM |
| Rogue AP | hostapd, dnsmasq, wifipumpkin3, wifiphisher | Evil twin, captive portal, MITM |
[!WARNING] Injection and RF transmission are regulated Monitor mode, packet injection, and running your own access point transmit on licensed spectrum. Use a lawful regulatory domain (
iw reg set), keep power low, and transmit only in an isolated lab — do not radiate onto neighbouring networks.
Hardware Requirements
A dedicated, injection-capable wireless adapter is the single most important piece of kit for this course — the onboard Wi-Fi on most laptops cannot enter monitor mode or inject packets reliably.
| Resource | Minimum | Recommended |
|---|---|---|
| Wireless adapter | 1 injection-capable adapter (Atheros AR9271) | 2 adapters — one for capture, one for a rogue AP |
| Test access point | 1 router/AP you own | Dedicated AP with WEP/WPA/WPA2 SSIDs (e.g. TP-Link EAP110) |
| Client device | 1 phone or laptop | Multiple STAs for handshake and deauth labs |
| Host | Kali VM with USB passthrough | Bare-metal Kali for timing-reliable injection |
[!IMPORTANT] Chipset — not brand — decides injection Atheros (AR9271) and Ralink (RT3070/RT5372) chipsets are the safe choices. Confirm the card enters RFMON with
sudo airmon-ng start wlan0and passessudo aireplay-ng --test wlan0monbefore starting the attack modules. Note the TL-WN722N caveat: only the v1 revision carries the injection-capable Atheros chipset.
Virtualization Requirements
Kali can run bare-metal or virtualized. The one hard requirement in a VM is exposing the USB Wi-Fi adapter to the guest — the hypervisor's virtual NIC cannot enter monitor mode.
| Item | Detail |
|---|---|
| Hypervisor | VirtualBox 7.x, VMware Workstation/Player, or KVM/QEMU (libvirt + virt-manager) |
| Guest | Kali Linux |
| Adapter access | USB passthrough of the external adapter to the Kali guest |
| Snapshots | Take a clean baseline snapshot before each attack lab |
| Bare-metal option | Preferred when USB passthrough makes injection/timing unreliable |
[!TIP] Prefer bare-metal for timing-sensitive attacks USB passthrough works for most capture and cracking labs, but injection-timing attacks (Chop-Chop, fragmentation, active WEP) are more reliable on bare-metal Kali. If an injection test intermittently fails in a VM, retry on bare-metal before debugging the attack.
Lab Environment
A reference topology used across the attack modules:
┌────────────────────────────┐
│ Kali Linux (attacker) │
│ injection-capable adapter │
│ wlan0 → wlan0mon (RFMON) │
└───────────────┬──────────��─┘
│ 802.11 (monitor / injection)
┌──────────────────────┼──────────────────────┐
│ │ │
┌────────────┐ ┌───────────────┐ ┌────────────────┐
│ Target AP │ │ Enterprise │ │ Rogue / Evil │
│ WEP·WPA· │ │ AP + RADIUS │ │ Twin AP │
│ WPA2 PSK │ │ (hostapd + │ │ (hostapd + │
│ │ │ FreeRADIUS) │ │ dnsmasq) │
└──────┬─────┘ └───────┬───────┘ └───────┬────────┘
│ │ │
┌────────────┐ ┌────────────┐ ┌────────────┐
│ Client │ │ 802.1X │ │ Victim │
│ STA │ │ supplicant│ │ client │
└────────────┘ └──���─────────┘ └────────────┘
| Role | Node | Exercised |
|---|---|---|
| Attacker | Kali + adapter (wlan0mon) |
Capture, injection, cracking, rogue AP |
| Target AP | Router with WEP·WPA·WPA2 SSIDs | Handshake capture, WEP and WPS attacks |
| Enterprise AP | hostapd + FreeRADIUS | Enterprise WPA (EAP/RADIUS) assessment |
| Rogue AP | hostapd + dnsmasq | Evil twin, captive portal, MITM |
| Client | STA / victim device | Deauth, handshake generation, credential capture |
[!NOTE] Isolate the RF lab Deauthentication, beacon floods, and rogue APs disrupt any real device in range and leak beyond your walls. Test on your own hardware in an isolated/low-power RF environment — never on a shared or production SSID.
Course Modules
The 14 teaching modules are grouped into four progressive phases. Each links to the module's own Readme hub, which in turn links out to its single-topic notes. Follow them in order — see the Learning Path for how the phases build on one another.
Phase 1 — Fundamentals
| # | Module | Focus |
|---|---|---|
| 1 | Introduction to Wireless Networks | 802.11 standards, network and frame types, frequency bands and channels |
| 2 | Wireless Encryption & Authentication | WEP, WPA/TKIP, WPA2/CCMP, WPA3, and the four-way handshake |
| 3 | Wireless Network Cards & Adapters | WNICs, external adapters, monitor mode, and packet injection |
Phase 2 — Reconnaissance & Bypass
| # | Module | Focus |
|---|---|---|
| 4 | Wireless Security Measures & Bypass | MAC filtering and spoofing, hidden SSIDs, access-point identification |
| 5 | Wireless Reconnaissance & Traffic Analysis | airodump-ng, Kismet, Bettercap, Wireshark, channel hopping, AP/client enumeration |
Phase 3 — Attacks
| # | Module | Focus |
|---|---|---|
| 6 | Wireless Denial-of-Service Attacks | Deauthentication, RF and CSMA/CA jamming, beacon and association floods, mitigation |
| 7 | Wireless MITM & Rogue Access Points | Evil twin, airbase-ng/hostapd, captive portals, credential harvesting |
| 8 | WEP Cracking Techniques | aircrack-ng, IV collection, ARP replay, fragmentation, keystream reuse |
| 9 | Chop-Chop & Packet Replay Attacks | Chop-Chop, PTW, KoreK, interactive packet replay |
| 10 | Caffe Latte Attack | Client-side WEP recovery, attacking disconnected clients, gratuitous ARP |
| 11 | WPA/WPA2 Cracking | WPS (Pixie Dust, Reaver, Bully), handshake and PMKID capture, dictionary/hashcat |
| 12 | Cowpatty & Hash Table Attacks | Cowpatty, precomputed and rainbow tables, offline cracking, custom wordlists |
| 13 | Advanced WPA/TKIP & WPA3 Attacks | Beck-Tews, Michael reset, KRACK, WPA3 Dragonblood |
[!WARNING] The attack modules assume a lab you own and control. Run deauthentication, jamming, and rogue-AP attacks only against your own equipment in an isolated RF environment — never against third-party networks.
Phase 4 — Enterprise & Reporting
| # | Module | Focus |
|---|---|---|
| 14 | Enterprise Wireless Security & Reporting | Enterprise WPA (EAP/RADIUS), FreeRADIUS, WIDS, hardening, penetration-test reporting |
Learning Outcomes
On completion, a student can:
| Domain | Outcome |
|---|---|
| Reconnaissance | Discover networks and clients, enumerate access points, and analyze 802.11 traffic |
| Adapters | Configure monitor mode and packet injection reliably |
| WEP | Crack WEP via IV collection, ARP replay, Chop-Chop, and fragmentation |
| WPA/WPA2 | Capture and crack four-way handshakes and PMKIDs |
| Rogue infrastructure | Deploy evil-twin and rogue access points and conduct wireless MITM |
| Advanced | Execute WPA-TKIP and WPA3 (KRACK/Dragonblood) attacks |
| Enterprise | Assess EAP/RADIUS wireless and report findings professionally |
| Defense | Recommend wireless hardening, detection, and remediation |
Certification Mapping
This course's content aligns with the objectives of the major wireless-security certifications. It is exam-relevant preparation, not a guarantee of passing.
| Certification | Alignment | Strongly covered | Partially covered |
|---|---|---|---|
| OSWP (Offensive Security Wireless Professional) | ⭐⭐⭐⭐ High | Recon, WEP/WPA/WPA2 cracking, WPS, rogue APs, PMKID — the practical attack chain | Exam-specific wpa_supplicant/scripting workflow drilled only in labs |
| CWSP (Certified Wireless Security Professional) | ⭐⭐⭐ Medium | 802.11 security, encryption/authentication, EAP/RADIUS, WIDS, rogue-AP detection | Vendor-neutral policy, design, and monitoring architecture |
| CEH (Wireless Hacking domain) | ⭐⭐⭐⭐ High | Discovery, deauth/DoS, WEP/WPA cracking, evil twin, MITM tooling | Broader CEH domains outside wireless |
| CompTIA Security+ (wireless topics) | ⭐⭐⭐ Medium | WPA2/WPA3, EAP methods, evil twin, rogue AP, wireless hardening | The rest of the Security+ blueprint (non-wireless) |
[!TIP] Best-fit exam The hands-on attack depth here maps most directly to OSWP — reconnaissance, WEP/WPA/WPA2 cracking, WPS, and rogue-AP attacks are covered end to end. The encryption, EAP/RADIUS, and WIDS material additionally supports CWSP revision.
References
- IEEE 802.11 Wireless LAN Standard — https://standards.ieee.org/ieee/802.11/7028/
- Wi-Fi Alliance — WPA3 Specification — https://www.wi-fi.org/discover-wi-fi/security
- aircrack-ng Documentation — https://www.aircrack-ng.org/documentation.html
- hashcat Wiki — https://hashcat.net/wiki/
- Kismet Documentation — https://www.kismetwireless.net/docs/
- Wireshark 802.11 Wiki — https://wiki.wireshark.org/Wi-Fi
- KRACK Attacks (Key Reinstallation Attacks) — https://www.krackattacks.com/
- Dragonblood — WPA3 Vulnerabilities — https://wpa3.mathyvanhoef.com/
- Wi-Fi Alliance Security Whitepapers — https://www.wi-fi.org/security
Related Courses
Sibling courses in this vault that pair well with wireless penetration testing:
- Certified Ethical Hacking and Penetration Testing — the broader offensive methodology this course specializes.
- Network Sniffing — packet capture and traffic analysis beyond 802.11.
- Password Cracking — hashcat/John workflows applied to WPA/WPA2 hashes.
- Social Engineering — the human layer behind evil-twin and captive-portal attacks.
See also the vault hub Wireless Security & WiFi Penetration Testing and the full curriculum catalog.
Contribution
Contributions that improve accuracy, add labs, or deepen module notes are welcome.
| Guideline | Detail |
|---|---|
| Conventions | Follow vault house style: one H1 per note (= filename), intro sentence, standard sections, tagged code fences |
| Links | Use relative Markdown links ([text](https://github.com/armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing/blob/main/../Folder/Note.md), [text](https://github.com/armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing/blob/main/Note.md#heading-slug)) — they render on GitHub and still resolve in Obsidian. Avoid [[wikilinks]] (GitHub does not render them). Keep link integrity when renaming/moving notes |
| Callouts | Use GitHub alert syntax — > [!NOTE], > [!TIP], > [!IMPORTANT], > [!WARNING], > [!CAUTION] (marker alone on its line; a title goes on the next line as > **Title**). These render as callouts on GitHub and in Obsidian |
| Scope | Keep each note single-topic; wire new notes into the relevant module Readme hub |
| Accuracy | Prefer tested commands and cite upstream docs for configuration claims |
| No placeholders | Do not link to files that do not yet exist; mark planned work as forthcoming |
[!WARNING] All techniques are documented for authorized testing and education only. Test only against equipment and networks you own or have explicit written permission to assess.
Comments