Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Wireless Evil Twin

ASecurity

Stand up a rogue/evil-twin access point to harvest credentials — WPA2-Enterprise PEAP-MSCHAPv2 challenge/response and captive-portal capture. Load on an authorized wireless engagement targeting WPA-Enterprise (802.1X) or a portal-based network. Signals: PEAP/EAP/802.1X, RADIUS, "enterprise Wi-Fi", eaphammer/hostapd-wpe in play, a captive portal, corporate SSID with per-user logins.

20 stars
0 votes
0 copies
1 views
Added 9/22/2026
ai-agentsgorails

Works with

cli

Security Analysis

A100/100

Scanned 9/22/2026

$npx -y skills add NoorQureshi/SploitAgent --skill wireless-evil-twin --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Wireless Evil Twin?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Wireless Evil Twin
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-wireless-evil-twin/badge)](https://www.skillsdirectory.com/skills/noorqureshi-wireless-evil-twin)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: wireless-evil-twin
description: >
  Stand up a rogue/evil-twin access point to harvest credentials — WPA2-Enterprise PEAP-MSCHAPv2
  challenge/response and captive-portal capture. Load on an authorized wireless engagement targeting
  WPA-Enterprise (802.1X) or a portal-based network. Signals: PEAP/EAP/802.1X, RADIUS, "enterprise
  Wi-Fi", eaphammer/hostapd-wpe in play, a captive portal, corporate SSID with per-user logins.
domain: wireless
type: technique
stability: learning
modes: [pentest]
severity: high
mitre: [T1557, T1556]
cwe: [CWE-290, CWE-522]
tools: [eaphammer, hostapd-wpe, hashcat, asleap]
schema_version: 1
---

# Evil-twin / rogue AP (enterprise credential harvesting)

## When it applies
An authorized assessment of a WPA2-**Enterprise** (802.1X) network, or a captive-portal Wi-Fi, where
clients can be lured to a look-alike AP. `pentest`-only, in-scope SSIDs recorded in `scope.txt`, and
coordinated so you only capture *test/consenting* users' credentials per RoE.

## Why it works
WPA2-Enterprise authenticates users to a RADIUS server, but many clients don't properly validate the
RADIUS server's certificate. A rogue AP advertising the same SSID can complete enough of the
PEAP-MSCHAPv2 exchange to capture each user's username + MSCHAPv2 challenge/response, which cracks
offline to the domain password. Captive portals simply hand you the credentials the user types.

## Method
1. **Profile the target** (`wireless-wpa2-attacks` recon): SSID, the EAP type (PEAP/EAP-TTLS), and
   whether clients validate the server cert (they often don't).
2. **Stand up the evil twin.** `eaphammer` (or `hostapd-wpe`):
   `eaphammer --cert-wizard` then
   `eaphammer -i wlan0 --essid <SSID> --creds` — advertises the SSID and runs a rogue RADIUS that
   logs credentials.
3. **Lure clients** — same SSID (and, per RoE, a stronger signal / brief targeted deauth of the real
   AP to prompt roaming). Keep disruption minimal and in-scope.
4. **Capture & crack** the PEAP-MSCHAPv2 username + challenge/response:
   `hashcat -m 5500 netntlm.txt wordlist` (or `asleap`) → domain password.
5. **Captive-portal variant** — clone the portal page on the rogue AP to capture typed creds
   directly; disclose per the SE guardrails in `social-eng-methodology`.
6. **Pivot** — validated creds feed `network-password-spraying`, VPN/OWA access, and AD work.

## Gotchas
- **You're capturing real people's credentials** — this is human-adjacent: only in-scope SSIDs,
  coordinate with the client, minimize capture, and protect/destroy what you collect per RoE (treat
  like `social-eng` data discipline).
- **Cert validation defeats it** — clients that properly pin/validate the RADIUS cert won't leak;
  that's the positive finding (report "clients validate the server cert").
- **Deauth/luring can be disruptive and out of RoE** — confirm before forcing roaming.
- **MSCHAPv2 capture format** must match hashcat `-m 5500` exactly — use the tool's emitted format.
- **Legal line** — capturing enterprise creds without explicit authorization is illegal; stop if
  scope is unclear (`tradecraft-scope-roe`).

## Verify success
Captured PEAP-MSCHAPv2 credentials that crack to a working domain password (or portal creds that
authenticate) — for in-scope, authorized users only, with a "clients don't validate the RADIUS cert"
root cause for the report.

## References
`eaphammer` / `hostapd-wpe` docs; hashcat mode 5500; PEAP-MSCHAPv2 weaknesses. Data discipline:
`social-eng-methodology`; follow-on: `network-password-spraying`.

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →