Getting Started With Wireless Auditing
Aircrack User Guide covers the aircrack-ng suite, which is a collection of tools for auditing WiFi networks. The main utilities are airomon, airodump, aireplay, and aircrack itself. You install the suite from your distribution's package manager or compile from source. On Kali, it's pre-installed. On Debian-based systems that aren't Kali, you run apt install aircrack-ng and that's it. The first thing most people get wrong is assuming their WiFi adapter will work out of the box. It doesn't. You need an adapter that supports monitor mode and packet injection. The Alfa AWUS036NHA based on the Atheros AR9271 chipset is the most reliable entry-level option. The TP-Link TL-WN722N v1 works too, but don't buy v2 or v3 — those use different chipsets that aircrack-ng doesn't support well. This matters more than anything else in this entire guide.
Aircrack User Guide
Before you run any commands, put your interface into monitor mode. Replace wlan0 with whatever your interface is called — check with ip link. You bring down the interface, set monitor mode, then bring up a new mon interface: airmon-ng start wlan0 This creates mon0. Sometimes it creates wlan0mon instead. It depends on your kernel version and driver. If airmon-ng gives you errors about interfering processes, run airmon-ng check kill first. That stops NetworkManager and other services that will grab your interface and prevent monitor mode from working properly.
Scan for target networks with airodump: airodump-ng mon0 You'll see a list of BSSIDs, channels, encryption types, and connected clients. Note the channel and BSSID of your target. If you're auditing your own network, great. If you're not the owner, stop reading now because this is illegal in most jurisdictions without written authorization.
Get the Full Details

Capture the handshake with a targeted dump. Instead of scanning everything, lock onto one network: airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture mon0 This writes to capture-01.cap. You need a four-way handshake. If clients are already connected to the target, you can wait for a reassociation, which usually happens within minutes. If not, you force one with aireplay:
aireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF mon0 The -0 flag sends deauthentication frames. Five is the count — it'll send five burst packets and stop. One burst is usually enough to kick off a reconnect. Watch the airodump window. When you see WPA handshake detected, you have what you need. Press Ctrl+C to stop capturing. Crack the handshake with aircrack:
aircrack-ng -w rockyou.txt capture-01.cap Your wordlist needs to actually contain the password. Rockyou.txt is roughly 14 million entries and downloads from the usual open-source lists. If your password is something obscure like Tr0ub4dor&3, it won't be in there and you'll wait forever for a negative result. That's the reality of dictionary attacks. There's a faster path on networks running WPA2-PSK with modern features enabled. Some access points leak a PMKID — a precomputed key material identifier — in a single management frame. You don't need to deauth anyone. You capture one frame and crack the PMKID directly. Run this:

airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w pmkid mon0 Wait about 30 seconds, then stop. Extract the PMKID with aircrack's built-in parser: aircrack-ng -J pmkid_capture pmkid-01.cap
Then hashcat it if you have a GPU. The resulting hashcat-compatible output goes straight into hashcat mode 22000. This is significantly faster than the traditional handshake method on supported hardware and avoids the deauth step entirely, which some people find cleaner from an operational security standpoint. Here's something people miss. The handshake capture step often fails not because the technique is flawed, but because the adapter drops packets. Cheap Realtek-based adapters will show high drop rates in airodump's output. Watch that number. If drops are above 5 percent during your capture window, switch adapters or move closer to the target. I spent three hours once trying to crack a handshake that never completed properly, only to realize my adapter was dropping every third beacon frame. Swapped to the Alfa and captured it in 40 seconds. Another edge case: WPA3 networks. Aircrack-ng cannot crack WPA3-SAE directly. The handshake format is different and the attack surface is fundamentally different. You'd need to downgrade the network to WPA2 first, which requires a different attack vector entirely, and even then it's not guaranteed. If you're hitting a WPA3 network, tell the client that upfront instead of running aircrack and wondering why nothing happens.
Memory issues also come up. If your wordlist is larger than available RAM during certain cracking operations, aircrack can stall or crash. Keep the wordlist under 8GB or use hashcat with a GPU instead. Hashcat parallelizes across GPU cores and completes SHA1-based WPA handshakes roughly 10x to 50x faster than a CPU running aircrack, depending on your hardware. A GTX 1070 will crack a typical WPA handshake in minutes that would take an hour on a dual-core processor. Legal note: this toolkit is dual-use. It's sold as a penetration testing utility. Using it on networks you don't own or have explicit written permission to test violates the Computer Fraud and Abuse Act in the United States and equivalent laws elsewhere. The tool doesn't care who you target. The law does.
