EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium
A security analyst is investigating a suspected wireless intrusion. They have captured a large amount of raw 802.11 traffic in a .pcap file. To identify potential rogue access points, analyze beacon frames, and detect other anomalies, which specialized wireless analysis tool is specifically designed for passive sniffing and network discovery?
- ANmap
- BHping3
- CNetcat
- DKismet
Show answer & explanationAnswer & explanation
Correct answer: D. Kismet
Kismet is a wireless network detector, sniffer, and intrusion detection system. It operates in passive mode, collecting 802.11 frames to identify access points, clients, SSIDs, and detect various wireless anomalies and rogue devices, making it ideal for the described task.
Why the other options are wrong
- A. Nmap is a network scanner used for host discovery and service enumeration, not for passive wireless traffic analysis.
- B. Hping3 is a network packet crafting and analysis tool, primarily for active probing, not passive wireless discovery.
- C. Netcat is a networking utility for reading/writing across network connections, not for wireless sniffing and analysis.
Kismet Wireless Sniffer
Kismet is a powerful open-source wireless network detector, sniffer, and intrusion detection system. It passively collects 802.11 frames to discover wireless networks (APs and clients), SSIDs, detect hidden networks, and identify rogue access points or other wireless anomalies.
- Operates in passive mode, avoiding active probing.
- Analyzes raw 802.11 frames (beacon, probe, data).
- Used for network discovery, mapping, and intrusion detection.
Memory trick: Kismet listens passively to discover all wireless secrets.