
Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research.
A complete, modular, and reproducible evil twin access point setup for defensive security testing, penetration testing, and wireless security research.
FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY
This tool is provided for:
ILLEGAL USE IS STRICTLY PROHIBITED. Unauthorized access to computer networks is a crime in most jurisdictions. Users are solely responsible for:
By using this tool, you agree to use it only on networks you own or have explicit written permission to test.
This toolkit creates a rogue wireless access point (evil twin) that mimics a legitimate network. It captures network traffic by creating an identical SSID that clients may automatically connect to, believing it's the legitimate network.
An evil twin is a fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communications. The attack works by positioning a rogue access point near the target network, broadcasting the same SSID, and tricking devices into connecting.
Your wireless adapter MUST support AP (Access Point) mode. Not all wireless cards support this functionality.
These adapters are known to work well and support AP mode:
| Chipset | Model Examples | Features | Price Range |
|---|---|---|---|
| RTL8812AU | Alfa AWUS036ACH, TP-Link Archer T4U | Dual-band (2.4/5GHz), High power, Excellent range | $40-60 |
| RTL8814AU | Alfa AWUS1900, TP-Link Archer T9UH | Quad antenna, AC1900, Long range | $60-80 |
| Atheros AR9271 | TP-Link TL-WN722N v1, Alfa AWUS036NHA | Stable, Well-supported, Budget-friendly | $20-35 |
| MT7612U | Panda PAU0D, Alfa AWUS036ACM | Dual-band, Good compatibility | $35-50 |
| RTL8188EU | Various budget adapters | Basic, 2.4GHz only, Entry-level | $10-20 |
Alfa AWUS036ACH (RTL8812AU)
TP-Link TL-WN722N v1 (Atheros AR9271)
Alfa AWUS036ACM (MT7612U)
Before purchasing, verify the adapter supports AP mode:
# Check if your current adapter supports AP mode
iw list | grep -A 10 "Supported interface modes"
# Look for this in the output:
# * AP
# * monitor
These will be automatically installed by install_dependencies.sh:
hostapd - Creates the access pointdnsmasq - Provides DHCP and DNS servicesiptables - Configures NAT and firewall rulesiproute2 - Network interface configurationwireless-tools - Wireless management utilitiesnet-tools - Network diagnostic toolsiw - Wireless configuration utilitytcpdump - Packet capture utility# Clone the repository
git clone https://github.com/yourusername/evil-twin-ap.git
cd evil-twin-ap
# Install dependencies
sudo ./install_dependencies.sh
# Detect your wireless interfaces
sudo ./detect_interface.sh
# Configure your settings (update interface if needed)
nano hostapd.conf # Change SSID, channel, interface
nano dnsmasq.conf # Adjust DHCP settings, interface
# Start the evil twin
sudo ./start_evil_twin.sh
git clone https://github.com/yourusername/evil-twin-ap.git
cd evil-twin-ap
The installation script automatically detects your Linux distribution and installs required packages:
sudo ./install_dependencies.sh
What it does:
CRITICAL STEP: Before configuring, detect which wireless interface supports AP mode:
sudo ./detect_interface.sh
This script will analyze all wireless interfaces and recommend the best one to use.
Example output:
==========================================
Wireless Interface Detection
==========================================
[INFO] Scanning for wireless interfaces...
[✓] Found 2 wireless interface(s)