A one-month, lab-driven curriculum that takes a learner from wireless fundamentals to enterprise Wi-Fi penetration testing — 802.11 standards and encryption, monitor-mode capture, reconnaissance and traffic analysis, WEP/WPA/WPA2 cracking, WPA3 and TKIP attacks, rogue access points and wireless MITM, and enterprise (EAP/RADIUS) assessment with professional reporting.

Curriculum home: Vault Catalog


Course Information

Property Value
Course Title Wireless Security & WiFi Penetration Testing
Folder Wireless-Security-and-WiFi-Penetration-Testing/
Tag Wireless Security
Slug wifi-pentest
Level Advanced
Duration 1 Month (4 Weeks · ~30 Hours)
Focus Wireless Penetration Testing
Reference Platform Kali Linux · injection-capable adapters (Atheros AR9271 · Ralink RT3070)
Modules 14
Delivery Self-paced notes + hands-on labs
Language English

[!NOTE] What this course is A study-and-practice track built as an Obsidian knowledge base. Each module is a folder with its own Readme hub and a set of single-topic notes containing tagged, copy-ready command snippets. It is designed to be read in order but is fully cross-linked for reference use.


Course Description

Master wireless security testing and Wi-Fi penetration testing end to end: 802.11 standards and frame types, encryption and authentication (WEP, WPA/TKIP, WPA2/CCMP, WPA3), adapter setup for monitor mode and packet injection, reconnaissance and traffic analysis, security-control bypass, denial-of-service, WEP cracking, Chop-Chop and packet-replay attacks, the Caffe Latte client-side attack, WPA/WPA2 handshake and PMKID cracking, Cowpatty and precomputed-table attacks, advanced WPA-TKIP and WPA3 (KRACK/Dragonblood) attacks, rogue access points and wireless MITM — then apply those skills to enterprise WPA (EAP/RADIUS) assessment, wireless hardening, and penetration-test reporting.

The program is delivered through reproducible, hands-on labs against equipment you own and control, so every technique is paired with a working capture, attack, or configuration you can build, break, and defend.

[!WARNING] Authorized testing only Every technique here is documented for education, detection, and defense. Wireless attacks — deauthentication, jamming, rogue access points, handshake capture, and key cracking — are illegal against networks you do not own or lack explicit written permission to assess. Practice only in your own isolated RF lab, a CTF, or a sanctioned engagement.


Overview

The Wireless Security & WiFi Penetration Testing program provides practical, assessment-ready skills across wireless reconnaissance, attack, and defense. It is designed for ethical hackers, penetration testers, red-team operators, and wireless security analysts, and progresses from 802.11 fundamentals to advanced enterprise attacks.

By the end of the course, students will be able to:

  • Configure wireless adapters for monitor mode and packet injection
  • Discover hidden SSIDs and enumerate wireless infrastructure
  • Perform wireless DoS and deauthentication attacks
  • Crack WEP encryption using multiple attack techniques
  • Capture and crack WPA/WPA2 handshakes and PMKIDs
  • Deploy evil-twin and rogue access-point attacks
  • Conduct wireless Man-in-the-Middle attacks
  • Perform advanced WPA/TKIP and WPA3 exploitation
  • Assess enterprise WPA (EAP/RADIUS) deployments
  • Provide wireless hardening and remediation recommendations

[!TIP] Offense and defense are taught together Every attack module pairs the exploit with its detection and mitigation — deauth floods with 802.11w/management-frame protection, rogue APs with WIDS, weak PSKs with policy — so the skills transfer directly to defending the same networks.


Learning Path

The 14 modules are sequenced into four progressive phases. Complete each phase before advancing; later attack and enterprise modules assume the fundamentals and a capture-capable lab from earlier phases.

Phase 1  Fundamentals ....... Wireless Networks · Encryption & Authentication · Adapters
Phase 2  Recon & Bypass ..... Security Measures & Bypass · Reconnaissance & Traffic Analysis
Phase 3  Attacks ............ DoS · MITM/Rogue APs · WEP · Chop-Chop · Caffe Latte
                              WPA/WPA2 · Cowpatty · Advanced WPA-TKIP/WPA3
Phase 4  Enterprise ......... Enterprise WPA (EAP/RADIUS) · Hardening · Reporting
flowchart LR
    A[Phase 1<br/>Fundamentals] --> B[Phase 2<br/>Recon & Bypass]
    B --> C[Phase 3<br/>Attacks]
    C --> D[Phase 4<br/>Enterprise & Reporting]

[!IMPORTANT] Prerequisite chaining The attack phases assume a capture-capable lab from Phase 1 and the discovery skills from Phase 2. Attempting a WPA/WPA2 handshake crack or an evil-twin attack without a monitor-mode, injection-capable adapter and clean reconnaissance will fail in ways that are hard to diagnose — complete each phase before advancing.


Prerequisites

Requirement Level Notes
Basic networking knowledge Required IP addressing, TCP/IP, ports
Linux command-line familiarity Required All tooling is Kali-based
Basic cybersecurity concepts Recommended Reinforced in-course
An injection-capable Wi-Fi adapter Required See Hardware Requirements
Prior wireless experience Not required Course starts from 802.11 basics

[!TIP] No wireless background needed Phase 1 assumes no prior 802.11 knowledge. If you already run wireless assessments, you can skim the fundamentals and start at Reconnaissance & Bypass.


Software Requirements

All tooling runs on Kali Linux, which ships most of these packages preinstalled; the rest are a single apt install away. The core of wireless testing is the aircrack-ng suite, complemented by capture, cracking, and rogue-AP utilities.

Component Recommended Purpose
Base OS Kali Linux Tooling distribution
Cracking suite aircrack-ng (airodump-ng, aireplay-ng, airbase-ng) WEP/WPA/WPA2 capture and cracking
GPU cracking hashcat WPA/WPA2/PMKID key recovery
PMKID capture hcxdumptool / hcxtools Capture and hash-format conversion
WPS attacks reaver, bully, wash WPS PIN brute-forcing
Detection / IDS kismet Sniffing and wireless IDS
Traffic analysis wireshark, tcpdump, bettercap 802.11 packet analysis and MITM
Rogue AP hostapd, dnsmasq, wifipumpkin3, wifiphisher Evil twin, captive portal, MITM

[!WARNING] Injection and RF transmission are regulated Monitor mode, packet injection, and running your own access point transmit on licensed spectrum. Use a lawful regulatory domain (iw reg set), keep power low, and transmit only in an isolated lab — do not radiate onto neighbouring networks.


Hardware Requirements

A dedicated, injection-capable wireless adapter is the single most important piece of kit for this course — the onboard Wi-Fi on most laptops cannot enter monitor mode or inject packets reliably.

Resource Minimum Recommended
Wireless adapter 1 injection-capable adapter (Atheros AR9271) 2 adapters — one for capture, one for a rogue AP
Test access point 1 router/AP you own Dedicated AP with WEP/WPA/WPA2 SSIDs (e.g. TP-Link EAP110)
Client device 1 phone or laptop Multiple STAs for handshake and deauth labs
Host Kali VM with USB passthrough Bare-metal Kali for timing-reliable injection

[!IMPORTANT] Chipset — not brand — decides injection Atheros (AR9271) and Ralink (RT3070/RT5372) chipsets are the safe choices. Confirm the card enters RFMON with sudo airmon-ng start wlan0 and passes sudo aireplay-ng --test wlan0mon before starting the attack modules. Note the TL-WN722N caveat: only the v1 revision carries the injection-capable Atheros chipset.


Virtualization Requirements

Kali can run bare-metal or virtualized. The one hard requirement in a VM is exposing the USB Wi-Fi adapter to the guest — the hypervisor's virtual NIC cannot enter monitor mode.

Item Detail
Hypervisor VirtualBox 7.x, VMware Workstation/Player, or KVM/QEMU (libvirt + virt-manager)
Guest Kali Linux
Adapter access USB passthrough of the external adapter to the Kali guest
Snapshots Take a clean baseline snapshot before each attack lab
Bare-metal option Preferred when USB passthrough makes injection/timing unreliable

[!TIP] Prefer bare-metal for timing-sensitive attacks USB passthrough works for most capture and cracking labs, but injection-timing attacks (Chop-Chop, fragmentation, active WEP) are more reliable on bare-metal Kali. If an injection test intermittently fails in a VM, retry on bare-metal before debugging the attack.


Lab Environment

A reference topology used across the attack modules:

                 ┌────────────────────────────┐
                 │   Kali Linux (attacker)    │
                 │  injection-capable adapter │
                 │   wlan0 → wlan0mon (RFMON)  │
                 └───────────────┬──────────��─┘
                                 │  802.11 (monitor / injection)
          ┌──────────────────────┼──────────────────────┐
          │                      │                       │
   ┌────────────┐        ┌───────────────┐       ┌────────────────┐
   │ Target AP  │        │  Enterprise   │       │  Rogue / Evil  │
   │ WEP·WPA·   │        │  AP + RADIUS  │       │  Twin AP       │
   │ WPA2 PSK   │        │ (hostapd +    │       │ (hostapd +     │
   │            │        │  FreeRADIUS)  │       │  dnsmasq)      │
   └──────┬─────┘        └───────┬───────┘       └───────┬────────┘
          │                      │                       │
   ┌────────────┐         ┌────────────┐          ┌────────────┐
   │  Client    │         │  802.1X    │          │  Victim    │
   │  STA       │         │  supplicant│          │  client    │
   └────────────┘         └──���─────────┘          └────────────┘
Role Node Exercised
Attacker Kali + adapter (wlan0mon) Capture, injection, cracking, rogue AP
Target AP Router with WEP·WPA·WPA2 SSIDs Handshake capture, WEP and WPS attacks
Enterprise AP hostapd + FreeRADIUS Enterprise WPA (EAP/RADIUS) assessment
Rogue AP hostapd + dnsmasq Evil twin, captive portal, MITM
Client STA / victim device Deauth, handshake generation, credential capture

[!NOTE] Isolate the RF lab Deauthentication, beacon floods, and rogue APs disrupt any real device in range and leak beyond your walls. Test on your own hardware in an isolated/low-power RF environment — never on a shared or production SSID.


Course Modules

The 14 teaching modules are grouped into four progressive phases. Each links to the module's own Readme hub, which in turn links out to its single-topic notes. Follow them in order — see the Learning Path for how the phases build on one another.

Phase 1 — Fundamentals

# Module Focus
1 Introduction to Wireless Networks 802.11 standards, network and frame types, frequency bands and channels
2 Wireless Encryption & Authentication WEP, WPA/TKIP, WPA2/CCMP, WPA3, and the four-way handshake
3 Wireless Network Cards & Adapters WNICs, external adapters, monitor mode, and packet injection

Phase 2 — Reconnaissance & Bypass

# Module Focus
4 Wireless Security Measures & Bypass MAC filtering and spoofing, hidden SSIDs, access-point identification
5 Wireless Reconnaissance & Traffic Analysis airodump-ng, Kismet, Bettercap, Wireshark, channel hopping, AP/client enumeration

Phase 3 — Attacks

# Module Focus
6 Wireless Denial-of-Service Attacks Deauthentication, RF and CSMA/CA jamming, beacon and association floods, mitigation
7 Wireless MITM & Rogue Access Points Evil twin, airbase-ng/hostapd, captive portals, credential harvesting
8 WEP Cracking Techniques aircrack-ng, IV collection, ARP replay, fragmentation, keystream reuse
9 Chop-Chop & Packet Replay Attacks Chop-Chop, PTW, KoreK, interactive packet replay
10 Caffe Latte Attack Client-side WEP recovery, attacking disconnected clients, gratuitous ARP
11 WPA/WPA2 Cracking WPS (Pixie Dust, Reaver, Bully), handshake and PMKID capture, dictionary/hashcat
12 Cowpatty & Hash Table Attacks Cowpatty, precomputed and rainbow tables, offline cracking, custom wordlists
13 Advanced WPA/TKIP & WPA3 Attacks Beck-Tews, Michael reset, KRACK, WPA3 Dragonblood

[!WARNING] The attack modules assume a lab you own and control. Run deauthentication, jamming, and rogue-AP attacks only against your own equipment in an isolated RF environment — never against third-party networks.

Phase 4 — Enterprise & Reporting

# Module Focus
14 Enterprise Wireless Security & Reporting Enterprise WPA (EAP/RADIUS), FreeRADIUS, WIDS, hardening, penetration-test reporting

Learning Outcomes

On completion, a student can:

Domain Outcome
Reconnaissance Discover networks and clients, enumerate access points, and analyze 802.11 traffic
Adapters Configure monitor mode and packet injection reliably
WEP Crack WEP via IV collection, ARP replay, Chop-Chop, and fragmentation
WPA/WPA2 Capture and crack four-way handshakes and PMKIDs
Rogue infrastructure Deploy evil-twin and rogue access points and conduct wireless MITM
Advanced Execute WPA-TKIP and WPA3 (KRACK/Dragonblood) attacks
Enterprise Assess EAP/RADIUS wireless and report findings professionally
Defense Recommend wireless hardening, detection, and remediation

Certification Mapping

This course's content aligns with the objectives of the major wireless-security certifications. It is exam-relevant preparation, not a guarantee of passing.

Certification Alignment Strongly covered Partially covered
OSWP (Offensive Security Wireless Professional) ⭐⭐⭐⭐ High Recon, WEP/WPA/WPA2 cracking, WPS, rogue APs, PMKID — the practical attack chain Exam-specific wpa_supplicant/scripting workflow drilled only in labs
CWSP (Certified Wireless Security Professional) ⭐⭐⭐ Medium 802.11 security, encryption/authentication, EAP/RADIUS, WIDS, rogue-AP detection Vendor-neutral policy, design, and monitoring architecture
CEH (Wireless Hacking domain) ⭐⭐⭐⭐ High Discovery, deauth/DoS, WEP/WPA cracking, evil twin, MITM tooling Broader CEH domains outside wireless
CompTIA Security+ (wireless topics) ⭐⭐⭐ Medium WPA2/WPA3, EAP methods, evil twin, rogue AP, wireless hardening The rest of the Security+ blueprint (non-wireless)

[!TIP] Best-fit exam The hands-on attack depth here maps most directly to OSWP — reconnaissance, WEP/WPA/WPA2 cracking, WPS, and rogue-AP attacks are covered end to end. The encryption, EAP/RADIUS, and WIDS material additionally supports CWSP revision.


References


Sibling courses in this vault that pair well with wireless penetration testing:

  • Certified Ethical Hacking and Penetration Testing — the broader offensive methodology this course specializes.
  • Network Sniffing — packet capture and traffic analysis beyond 802.11.
  • Password Cracking — hashcat/John workflows applied to WPA/WPA2 hashes.
  • Social Engineering — the human layer behind evil-twin and captive-portal attacks.

See also the vault hub Wireless Security & WiFi Penetration Testing and the full curriculum catalog.


Contribution

Contributions that improve accuracy, add labs, or deepen module notes are welcome.

Guideline Detail
Conventions Follow vault house style: one H1 per note (= filename), intro sentence, standard sections, tagged code fences
Links Use relative Markdown links ([text](https://github.com/armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing/blob/main/../Folder/Note.md), [text](https://github.com/armourinfosec/Wireless-Security-and-WiFi-Penetration-Testing/blob/main/Note.md#heading-slug)) — they render on GitHub and still resolve in Obsidian. Avoid [[wikilinks]] (GitHub does not render them). Keep link integrity when renaming/moving notes
Callouts Use GitHub alert syntax — > [!NOTE], > [!TIP], > [!IMPORTANT], > [!WARNING], > [!CAUTION] (marker alone on its line; a title goes on the next line as > **Title**). These render as callouts on GitHub and in Obsidian
Scope Keep each note single-topic; wire new notes into the relevant module Readme hub
Accuracy Prefer tested commands and cite upstream docs for configuration claims
No placeholders Do not link to files that do not yet exist; mark planned work as forthcoming

[!WARNING] All techniques are documented for authorized testing and education only. Test only against equipment and networks you own or have explicit written permission to assess.