Wi-Fi Ops
The complete reference for AirLeak Pro's authorized Wi-Fi assessment tools — purpose, options, and results for each, for sanctioned engagements only.
En esta página
These are the active Wi-Fi tools in the Ops Suite, run one at a time from the dedicated Wi-Fi radio. Each is described by what it is for in a sanctioned assessment, the options you set before starting it, and the result it hands back to the tester.
Captive / evil portal
Stands up a controlled portal page of the kind a network might present to a joining client. In an authorized engagement, it measures whether users on the client's network could be led to a lookalike sign-in page, and how the network and its clients respond.
The network name (SSID) the portal presents, and the portal page style shown to connecting clients.
A running client count as devices connect, and any credentials submitted during the sanctioned test — evidence for a phishing-resilience or user-awareness finding.
Packet capture (pcap)
Records raw Wi-Fi frames to a standard capture file for later analysis in the tools your workflow already uses.
The channel or channels to capture on.
A live frame count while it runs, and a .pcap file saved to the memory card — the raw evidence behind a finding, so claims in a report can be independently verified.
Beacon flood
Broadcasts additional fake network advertisements to test how client devices and network-management systems cope with a crowded, noisy RF environment, and whether the flood itself is detected.
The broadcast rate (frames per second).
A live throughput reading (advertisements per second actually sent) and observed client behaviour — evidence for a resilience or detection finding.
Deauthentication
Sends standard Wi-Fi disconnect frames to test whether a network enforces the modern protections — Protected Management Frames — meant to prevent forced disconnection. A scan-assisted mode helps target the specific network under test rather than guessing at its details.
The target network, and whether to run the scan-assisted targeting pass first.
A live frames-per-second rate and whether clients could actually be disconnected — a direct check of whether PMF or equivalent protections are in place and working.
Handshake / PMKID capture
Captures the brief authentication exchange a device performs when it joins a WPA network — either the full four-step (EAPOL 1–4) handshake or the single-message PMKID variant. In an authorized engagement, this feeds an offline password-strength audit: the capture is tested against a wordlist on your own equipment to see whether the network's password would hold up.
The target network to capture against.
A captured handshake or PMKID file, saved for offline analysis — the basis of a password-policy finding. AirLeak Pro does not crack passwords on-device; it collects the evidence.
Drone Remote ID
Broadcasts the Remote ID signal drones use to identify themselves over Wi-Fi. In an assessment this exercises Remote ID detection systems, and confirms whether they correctly pick up and interpret the broadcasts they're meant to catch.
The identity fields carried in the broadcast.
A running Remote ID broadcast a detection system can be checked against — presence and identity information exactly as a real drone would send it.