Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pi-pwnbox-rogueap — Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb: | Kitploit
Tools/GitHubGitHub/koutto/pi-pwnbox-rogueap
Wi-Fi AuditingInformation GatheringWireless SecurityPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubkoutto/pi-pwnbox-rogueap

pi-pwnbox-rogueap

Homemade Pwnbox 🚀 / Rogue AP 📡 based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap 💡

View Repository
2.1k221803 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pi-PwnBox 🚀 -RogueAP 📡

Homemade (headless) PwnBox / RogueAP based on Raspberry Pi & Alfa WiFi USB Adapters.

WiFi Hacking Cheatsheets & Mind Map 💡

Designed to be used for:

  • On-site Red Team engagements,
  • WiFi Security assessments,
  • WiFi Attacks practice.

Pi-PwnBox-RogueAP

Table of Contents

  • Pi-PwnBox-RogueAP
  • Equipment used
  • WiFi USB Adapters Overview
  • Requirements & Compatibility
  • Installation
  • PwnBox Network Configuration
    • Wireless Dedicated Administration Network
    • LAN Network (Wireless or Wired)
  • PwnBox Remote Access
  • Usage
  • WiFi Hacking Cheatsheets & Mind Map
  • Troubleshooting
  • Possible Upgrade

Equipment used

  • Raspberry Pi 3 Model B+, Pi 4 or Pi 5
  • Micro SD Memory Card 64 GB (class 10 or better, UHS-I recommended)
  • Raspberry Pi Case (with passive/active cooling for Pi 4/5)
  • Alfa WiFi USB Adapter AWUS036NEH
  • Alfa WiFi USB Adapter AWUS036ACH
  • BrosTrend WiFi USB Adapter AC1L AC1200 (can be replaced by any adapter supporting AP mode)
  • USB cable Male to Female
  • Rii Mini Wireless Keyboard (optional)
  • Powerbank (minimum 2.5A for Pi 3, 3A+ for Pi 4/5)

WiFi USB Adapters Overview

DeviceChipsetUsage802.112.4 Ghz5 GhzKali out-of-boxMon. ModeInjec-tionAP
Built-in Raspberry Pi 3 B+ WiFi chipBroadcom 43430Connection to Internet (auto-start at boot if WiFi key added in config)802.11 b/g/n/acYYYN*N*Y
BrosTrend AC1L AC1200Realtek RTL8812AUAcces Point for Remote Access (auto-start at boot)802.11 a/b/g/n/acYYNYNY
Alfa AWUS036NEHRalink RT2870/3070WiFi Attacks802.11 b/g/nYNYYYY
Alfa AWUS036ACHRealtek RTL8812AUWiFi Attacks802.11 a/b/g/n/acYYYYYY

* would require nexmon patch to enable monitor mode and injection support on built-in Broadcom chip (but we do not need it for its usage here).

Requirements & Compatibility

  • OS: Kali Linux ARM for Raspberry Pi (64-bit recommended for Pi 4/5).
  • Internet: During installation the PwnBox must have access to the Internet.
  • Root: Install script must be run as root.
  • Note for Pi 4/5: The 64-bit Kali ARM image is highly recommended. All tools work on arm64, but some older precompiled binaries may require box64 or manual compilation.

Installation

  1. Download Kali Linux ARM Image for Raspberry Pi: https://www.kali.org/get-kali/#kali-arm

  2. Flash Kali Linux ARM Image for Raspberry Pi onto Micro SD Card (use Raspberry Pi Imager or dd).

  3. Boot Raspberry Pi, log in (default kali/kali) and make sure it has Internet connection.

  4. Download install scripts/configurations on the PwnBox:

    git clone https://github.com/koutto/pi-pwnbox-rogueap.git
    
  5. Important: Edit install script configuration at the top of scripts/install-system.sh file:

    • Choose Guacamole passwords (GUACAMOLE_PASSWORD, GUACAMOLE_MYSQL_PASSWORD).
    • Set WiFi interfaces persistent names based on their MAC addresses: wlxaabbccddeeff for a device with MAC address aa:bb:cc:dd:ee:ff.
    • Set MAC addresses of eth0 & wlan0 (built-in interfaces).
    • Set WiFi connection settings (WIFI_SSID, WIFI_PASSPHRASE).
  6. Run install script (will pause at the end of each step in order to allow for manual inspection of command outputs)

    cd pi-pwnbox-rogueap/scripts
    ./install-system.sh
    
  7. Reboot & check correct configuration of network interfaces:

    ip a
    iwconfig
    
    • Built-in wired and wireless interfaces should be named eth0 and wlan0 respectively.
    • WiFi USB Adapters should use persistent naming (modern naming convention wlx*).
    • AP (PWNBOX_ADMIN) should be started on appropriate wlx* interface.
  8. Configure VNC-over-HTTP on Guacamole:

    1. Connect to Guacamole at http://<ip_pwnbox>:8080/guacamole/
    2. Go to guacadmin (top right) > Settings > Connections
    3. Click on New Connection
    4. Fill connection settings as follows:
      • Name = pwnbox-vnc
      • Location = ROOT
      • Protocol = VNC
      • Maximum number of connections = 3
      • Maximum number of connections = 3
      • Guacamole Proxy Hostname = 127.0.0.1
      • Guacamole Proxy Port = 4822
      • Network Hostname = 127.0.0.1
      • Network Port = 5901
      • Authentication Password = (password chosen at install when running install-system.sh)
      • Color depth = True color (32-bit)
  9. Change default credentials:

    • Kali system credentials (passwd kali)
    • Guacamole credentials (via http://<ip_pwnbox>:8080/guacamole/#/manage/mysql/users/guacadmin)

PwnBox Network Configuration

Wireless Dedicated Administration Network

When booting, PwnBox automatically spawns an AP on one interface to allow for easy remote access:

  • SSID = PWNBOX_ADMIN (Hidden SSID)
  • WPA2 Passphrase (PSK) = Koutto!PwnB0x!
  • IP AP = 10.0.0.1 (when connected to this network, PwnBox can be accessed at this IP)
  • Network range = 10.0.0.1/24

LAN Network (Wireless or Wired)

When booting, PwnBox automatically connects to:

  • Wired network if Ethernet port is connected.

  • WiFi network (using built-in Raspberry Pi chip) if there is available wireless network with saved connection settings (in /etc/wpa_supplicant.conf). If you want to connect to a new WiFi network (not saved into PwnBox), it is necessary to add WPA passphrase of the network before:

    1. Access the PwnBox using another way, e.g.:

      • Use wireless dedicated administration network (most convenient approach),
      • Use wired network,
      • Use monitor + (wireless) keyboard.
    2. Add WPA passphrase to PwnBox local configuration:

      wpa_passphrase <SSID> <passphrase> >> /etc/wpa_supplicant.conf
      
    3. Test connection:

      wpa_supplicant -B -i wlan0 -c /etc/wpa_supplicant.conf
      dhclient -v wlan0
      ping 8.8.8.8
      

PwnBox Remote Access

PwnBox can be controlled through:

  • SSH Service (22/tcp):

    ssh kali@<ip_pwnbox>
    
  • VNC-over-HTTP with Guacamole (8080/tcp):

    http://<ip_pwnbox>:8080/guacamole
    

PwnBox's IP depends on the network you want to access it from:

  • Via Wireless Dedicated Administration Network (i.e. connected to hidden SSID PWNBOX_ADMIN): IP is always 10.0.0.1.
  • Via LAN Network (wireless or wired): IP depends on the value allocated by DHCP server. IP can be found using netdiscover for example.

Note: Guacamole service might take a lot of resources (RAM) when running. If not used, it can be stopped using stop-guacamole.sh script.

Usage

Download Tool