EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A penetration tester is performing a wireless assessment and identifies several access points broadcasting the same SSID. They notice that clients frequently roam between these access points. To efficiently map the physical locations of these APs and their associated clients, and to understand the overall wireless network topology, which of the following tools is BEST suited for passive wireless reconnaissance and visualization?

  1. ABurp Suite
  2. BMetasploit Framework
  3. CKismet
  4. DNmap
Show answer & explanation

Correct answer: C. Kismet

Kismet is a passive wireless network detector, sniffer, and intrusion detection system. It excels at discovering and mapping wireless networks (APs and clients), including hidden SSIDs, and can visualize the network topology, making it ideal for the described reconnaissance task.

Why the other options are wrong

  • A. Burp Suite is a web application security testing tool, unrelated to wireless network reconnaissance at the 802.11 layer.
  • B. Metasploit Framework is a powerful exploitation framework, not primarily a passive wireless reconnaissance tool.
  • D. Nmap is a network scanner used for host discovery and service enumeration on wired and wireless networks (IP level), but not for low-level 802.11 mapping.

Kismet Wireless Reconnaissance

Kismet is a passive wireless network detector, sniffer, and intrusion detection system that identifies wireless networks, clients, and their relationships without actively transmitting.

  • Operates in passive mode, minimizing detection.
  • Identifies APs, clients, SSIDs (including hidden ones).
  • Can visualize network topology and client-AP associations.

Memory trick: Kismet silently watches, mapping the hidden Wi-Fi world.

More Wireless Network Hacking questions