Wireless

Wireless and SDR lab reference

The default workflow is passive reception or offline analysis of synthetic, prerecorded, or owned-device data. Any transmission requires an approved frequency, power, location, containment method, equipment list, and stop authority. Do not intentionally interfere with nearby networks or collect third-party credentials, identifiers, or content.

1. Wi-Fi passive capture

Use a dedicated adapter and an owned access point in a shielded or otherwise contained lab. Monitor mode and channel selection vary by driver:

sudo airmon-ng start wlan0
sudo airodump-ng --channel <owned-ap-channel> --bssid <owned-ap-bssid> --write owned-lab wlan0mon

Generate an ordinary reconnect from an owned test client through its user interface. Do not transmit deauthentication or injection frames. Stop capture after the expected frames arrive and record the BSSID, channel, time window, adapter, driver, and containment method.

Offline verification may use a deliberately weak lab passphrase and an approved test dictionary:

hcxpcapngtool -o owned-lab.22000 owned-lab-01.cap
hashcat -m 22000 owned-lab.22000 approved-lab-dictionary.txt

A successful lab recovery proves the test passphrase was weak; it does not justify testing unrelated networks.

2. Wireless control validation

Validate controls with benign observations:

Control Safe validation
Rogue access point detection create a labeled lab SSID inside containment and confirm the sensor alert
Protected management frames inspect the owned AP configuration and capture association metadata; do not force disconnects
Client certificate policy connect an owned client with an intentionally untrusted lab certificate and expect rejection
Segmentation connect an owned client and test one explicitly approved destination and one expected deny

Tools that automate deauthentication, evil-twin credential capture, WPS attacks, or frame injection are outside this baseline. Review them only as threat references unless a separate, contained test plan authorizes the exact action.

3. Kismet passive inventory

Configure Kismet with the dedicated receive interface and limit collection to the lab window:

kismet

Export only the evidence needed for the finding. Treat MAC addresses, SSIDs, device names, and location metadata as sensitive data.

4. Bluetooth Low Energy observation

Use an owned peripheral or a simulator. Inventory advertisements and GATT metadata without taking over an active connection. Connection hijacking and replay are outside this baseline.

Record the test device identity, firmware, advertised services, capture interface, and timestamps. Remove or encrypt captures according to the engagement retention rule.

5. SDR receive-only workflow

Verify the SDR and capture an approved frequency without transmitting:

hackrf_info
hackrf_transfer -r owned-lab.iq -f <approved-frequency-hz> -s <approved-sample-rate> -n <bounded-sample-count>

For RTL-SDR, use rtl_test for device verification and an approved receive application for analysis. Document gain, sample rate, center frequency, antenna, duration, and location so results can be reproduced.

6. Cellular and GNSS datasets

Analyze prerecorded or synthetic IQ and packet traces. Live cellular identifiers and subscriber traffic are sensitive; do not collect them from public networks. Cellular base-station impersonation, subscriber interception, over-the-air replay, and GNSS transmission are outside this reference.

GNSS signal generators may produce a file for offline simulation:

synthetic scenario -> IQ file -> software receiver or shielded conducted test

Do not connect a generated waveform to an antenna. Hardware validation requires conducted cabling or a certified RF enclosure, attenuation, frequency and power calculations, and local regulatory review.

7. Managed remote access

Remote-access overlays such as Tailscale are administration components rather than wireless assessment tools. Use the organization's identity, device-approval, ACL, logging, and offboarding standards; do not describe them as covert access.

8. Cleanup and evidence

  1. Stop capture applications and return adapters to managed mode.
  2. Confirm no test SSID, listener, or transmitter remains active.
  3. Hash evidence files and store them in the approved engagement directory.
  4. Remove temporary lab accounts and configuration.
  5. Record sensor alerts, packet timestamps, and the operator who verified cleanup.