Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
evil-twin-ap — Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research. | Kitploit
Tools/GitHubGitHub/jean-nestor/evil-twin-ap
Packet Sniffing & AnalysisWi-Fi AuditingNetwork SecurityWireless SecurityPenetration TestingLearning & EducationRed Teaming
GitHubjean-nestor/evil-twin-ap

evil-twin-ap

Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research.

View Repository
1116411 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Evil Twin Access Point Toolkit

License Platform Shell

A complete, modular, and reproducible evil twin access point setup for defensive security testing, penetration testing, and wireless security research.

⚠️ Legal Disclaimer

FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY

This tool is provided for:

  • Educational purposes
  • Authorized penetration testing
  • Security research in controlled environments
  • Defensive security training

ILLEGAL USE IS STRICTLY PROHIBITED. Unauthorized access to computer networks is a crime in most jurisdictions. Users are solely responsible for:

  • Obtaining written authorization before testing
  • Compliance with all applicable laws and regulations
  • Any consequences resulting from misuse

By using this tool, you agree to use it only on networks you own or have explicit written permission to test.


📋 Table of Contents

  • Overview
  • Features
  • Hardware Requirements
  • Software Requirements
  • Installation
  • Configuration
  • Usage
  • Traffic Capture
  • Monitoring
  • Troubleshooting
  • Project Structure
  • Security Considerations
  • Contributing
  • License

🎯 Overview

This toolkit creates a rogue wireless access point (evil twin) that mimics a legitimate network. It captures network traffic by creating an identical SSID that clients may automatically connect to, believing it's the legitimate network.

What is an Evil Twin Attack?

An evil twin is a fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communications. The attack works by positioning a rogue access point near the target network, broadcasting the same SSID, and tricking devices into connecting.

Use Cases

  • 🔐 Penetration testing wireless security
  • 🎓 Security awareness training and demonstrations
  • 🧪 Network security research in lab environments
  • 🛡️ Testing wireless intrusion detection systems
  • 📱 Analyzing device behavior and client connectivity

✨ Features

  • 🔧 Modular Design: Clear separation of concerns with reusable functions
  • 📊 Verbose Output: Color-coded status messages for every operation
  • 🔍 Real-time Monitoring: Live tracking of connected clients with timestamps
  • 📝 Comprehensive Logging: Detailed logs for hostapd, dnsmasq, and connections
  • 🌐 Internet Sharing: Automatic NAT configuration for internet passthrough
  • 🔄 Auto-Discovery: Automatic detection of internet-facing interface
  • 🧹 Clean Teardown: Graceful shutdown with full system restoration
  • ✅ Dependency Management: Automated installation and verification
  • 🎨 Cross-Platform: Supports Debian, Ubuntu, Kali, Fedora, Arch, and more
  • 📦 Reproducible: Version-controllable configuration files
  • 📡 Interface Detection: Automatic wireless adapter detection and AP mode verification
  • 📸 Traffic Capture: Built-in PCAP capture with filtering and rotation

🔌 Hardware Requirements

Wireless Network Adapter

Your wireless adapter MUST support AP (Access Point) mode. Not all wireless cards support this functionality.

✅ Recommended Adapters

These adapters are known to work well and support AP mode:

ChipsetModel ExamplesFeaturesPrice Range
RTL8812AUAlfa AWUS036ACH, TP-Link Archer T4UDual-band (2.4/5GHz), High power, Excellent range$40-60
RTL8814AUAlfa AWUS1900, TP-Link Archer T9UHQuad antenna, AC1900, Long range$60-80
Atheros AR9271TP-Link TL-WN722N v1, Alfa AWUS036NHAStable, Well-supported, Budget-friendly$20-35
MT7612UPanda PAU0D, Alfa AWUS036ACMDual-band, Good compatibility$35-50
RTL8188EUVarious budget adaptersBasic, 2.4GHz only, Entry-level$10-20

🏆 Top Recommendations

  1. Alfa AWUS036ACH (RTL8812AU)

    • Best overall choice for penetration testing
    • Excellent driver support in Kali Linux
    • High transmit power (up to 30dBm)
    • Dual-band support
  2. TP-Link TL-WN722N v1 (Atheros AR9271)

    • Best budget option
    • Rock-solid stability
    • Native Linux support
    • ⚠️ Make sure to get version 1, not v2 or v3
  3. Alfa AWUS036ACM (MT7612U)

    • Good balance of price and performance
    • Excellent compatibility
    • Medium power output

❌ Adapters to Avoid

  • Built-in laptop wireless cards (usually don't support AP mode)
  • RTL8188FTV chipset (poor AP mode support)
  • Broadcom chipsets (limited Linux support)
  • Any adapter labeled "v2" or "v3" of previously working models (often use different, incompatible chipsets)

Verifying AP Mode Support

Before purchasing, verify the adapter supports AP mode:

# Check if your current adapter supports AP mode
iw list | grep -A 10 "Supported interface modes"

# Look for this in the output:
# * AP
# * monitor

Additional Hardware

  • Ethernet Connection: Required for internet passthrough (can be physical or USB-Ethernet adapter)
  • Sufficient USB Power: Some high-power adapters may require a powered USB hub
  • Computer: Any laptop or desktop running Linux (recommended: Kali Linux)

💻 Software Requirements

Operating System

  • Recommended: Kali Linux (2020.1 or later)
  • Also Supported:
    • Debian 10+
    • Ubuntu 18.04+
    • Fedora 30+
    • Arch Linux
    • ParrotOS
    • BlackArch

Required Packages

These will be automatically installed by install_dependencies.sh:

  • hostapd - Creates the access point
  • dnsmasq - Provides DHCP and DNS services
  • iptables - Configures NAT and firewall rules
  • iproute2 - Network interface configuration
  • wireless-tools - Wireless management utilities
  • net-tools - Network diagnostic tools
  • iw - Wireless configuration utility
  • tcpdump - Packet capture utility

Privileges

  • Root/sudo access is required for all operations

📦 Installation

Quick Start

# Clone the repository
git clone https://github.com/yourusername/evil-twin-ap.git
cd evil-twin-ap

# Install dependencies
sudo ./install_dependencies.sh

# Detect your wireless interfaces
sudo ./detect_interface.sh

# Configure your settings (update interface if needed)
nano hostapd.conf  # Change SSID, channel, interface
nano dnsmasq.conf  # Adjust DHCP settings, interface

# Start the evil twin
sudo ./start_evil_twin.sh

Detailed Installation

Step 1: Clone Repository

git clone https://github.com/yourusername/evil-twin-ap.git
cd evil-twin-ap

Step 2: Install Dependencies

The installation script automatically detects your Linux distribution and installs required packages:

sudo ./install_dependencies.sh

What it does:

  • Detects your Linux distribution
  • Updates package lists
  • Installs all required tools
  • Verifies kernel modules are loaded
  • Checks wireless adapter compatibility
  • Creates documentation

Step 3: Detect Wireless Interfaces

CRITICAL STEP: Before configuring, detect which wireless interface supports AP mode:

sudo ./detect_interface.sh

This script will analyze all wireless interfaces and recommend the best one to use.

Example output:

==========================================
   Wireless Interface Detection
==========================================

[INFO] Scanning for wireless interfaces...

[✓] Found 2 wireless interface(s)
Download Tool