NetHunter — All-in-One Wireless Security Auditing Suite
NetHunter is an advanced wireless security auditing suite combining the automated attack powers of NetHunter (Wifite2) with the comprehensive penetration testing capabilities of NetHunter+ (Airgeddon). Designed for security researchers and ethical hackers to audit Wi-Fi security across 2.4 GHz and 5 GHz frequency bands.
Architectural & Engineering Highlights
Dual-Engine Unified Architecture
Seamless toggle between NetHunter (Wifite2) for 1-click automated auditing and NetHunter+ (Airgeddon) for deep, multi-vector penetration testing, captive portals, and evil twin attacks.
Clientless PMKID & Handshake Pipeline
Automated retrieval of 128-bit PMKID hashes via hcxdumptool without waiting for active clients, plus targeted 4-way EAPOL handshake capture with real-time tshark verification.
WPA3 Transition & 802.11w (PMF) Audits
Verifies dual WPA2/WPA3 (SAE/PSK) networks for Transition Disable (TMD) enforcement, and tests Access Points and clients for Protected Management Frames compliance against spoofed deauth bursts.
WPS Pixie-Dust & PIN Exploitation
Integrated Pixie-Dust offline hash attacks and online PIN brute-force using reaver and bully with automated WPS lock detection and intelligent rate backoff.
MAC Randomization & Spectrum Control
Automated MAC address spoofing via macchanger prior to scanning. Full dual-band support (2.4 GHz & 5 GHz) with automated monitor mode orchestration and process sanitization.
IEEE OUI Intelligence & Cracking Suite
Real-time hardware vendor resolution via offline IEEE MAC database, handshake manager (--check), and seamless piping into Hashcat, Aircrack-ng, and John the Ripper.
Attack Vectors & Security Modules
Comprehensive wireless penetration testing capabilities implemented in NetHunter.
| Attack Vector | Target Protocol | Tool / Underlying Engine | Execution Mode |
|---|---|---|---|
| PMKID Hash Retrieval | WPA / WPA2-PSK | hcxdumptool + hcxtools |
Clientless & Automated |
| 4-Way Handshake Capture | WPA / WPA2-PSK | aireplay-ng + tshark |
Active Deauth & Passive |
| WPS Pixie-Dust Attack | WPS 1.0 / 2.0 | reaver / bully + pixiewps |
Offline PRNG Recovery |
| WPA3 Transition Downgrade | WPA3-SAE / WPA2 Transition | Custom TMD Auditor | Transition Disable Audit |
| 802.11w PMF Compliance | Protected Mgmt Frames | Custom Deauth Resistance Checker | Deauth Resistance Audit |
| WEP Multi-Attack Suite | Legacy WEP (64/128-bit) | Chop-Chop, Fragmentation, Hirte | Instant Automated Crack |
Command-Line Usage & Quick Recipes
# Launch NetHunter interactive menu
# Attack all targets in range automatically
# Scan 5 GHz spectrum on specific interface
# Verify captured handshakes and update IEEE OUI DB
Installation & Deployment Guide
Installs `nethunter` globally into your system binary path so you can run it from any directory:
Run inside an isolated Docker container with all penetration testing utilities pre-configured:
Ready to audit wireless networks?
Explore the open-source repository or download the latest release.