Agent skill

Offensive Wifi Recon

by SnailSploit in SnailSploit/Claude-Red

Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery…

MITAuto-check: notesSecurity

Install Offensive Wifi Recon

skills CLI
$ npx skills add SnailSploit/Claude-Red --skill offensive-wifi-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SnailSploit/Claude-Red offensive-wifi-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/wireless/offensive-wifi-recon .claude/skills/offensive-wifi-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
offensive-wifi-recon
GitHub stars
7.4k
Token cost
~1.7k tokens
SKILL.md length
504 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery…

  • Works in 6 steps: Pick the right adapter for the target's… → Verify monitor mode + injection actually… → Set the regulatory domain (legal… → …
  • Security work in your project
  • SKILL.md covers Quick Workflow, Adapter Selection, Monitor Mode Setup and Regulatory Domain, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Offensive Wifi Recon is an agent skill from SnailSploit/Claude-Red. Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and structured airspace data capture for downstream attacks. Use at the start of any wireless engagement to build the target map before active attacks; covers 2.4 GHz, 5 GHz, and 6 GHz (Wi-Fi 6E) bands and…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/offensive-wifi-recon”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Pick the right adapter for the target's band(s) and PHY
  2. Verify monitor mode + injection actually work
  3. Set the regulatory domain (legal channels and TX power)
  4. Sweep all bands passively
  5. Drill down on each in-scope BSSID for client population and PMF status
  6. Record everything in a structured target list before any active attack

What it can do on your machine

Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Offensive Wifi Recon loads about 1.7k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 504 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:43
    sudo airmon-ng check kill
  • NoteRuns commands with sudoSKILL.md:46
    sudo airmon-ng start wlan0
  • NoteRuns commands with sudoSKILL.md:48
    sudo ip link set wlan0 down
  • NoteRuns commands with sudoSKILL.md:49
    sudo iw wlan0 set monitor control
  • NoteRuns commands with sudoSKILL.md:50
    sudo ip link set wlan0 up
  • NoteRuns commands with sudoSKILL.md:53
    sudo aireplay-ng --test wlan0mon
  • NoteRuns commands with sudoSKILL.md:65
    sudo iw reg set US
  • NoteRuns commands with sudoSKILL.md:74
    sudo airodump-ng wlan0mon --band abg
  • NoteRuns commands with sudoSKILL.md:77
    sudo airodump-ng wlan0mon --band a
  • NoteRuns commands with sudoSKILL.md:80
    sudo airodump-ng wlan0mon --band ax

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 504 words, ~1,709 tokens.

Download SKILL.mdSave it as .claude/skills/offensive-wifi-recon/SKILL.md (or your agent's skills folder).
name
offensive-wifi-recon
description
Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and structured airspace data capture for downstream attacks. Use at the start of any wireless engagement to build the target map before active attacks; covers 2.4 GHz, 5 GHz, and 6 GHz (Wi-Fi 6E) bands and adapter compatibility for each.

Wi-Fi Reconnaissance

The first phase of any wireless engagement. Build a complete picture of the airspace before you deauth, evil-twin, or capture handshakes — every later attack depends on knowing the right BSSID, channel, encryption, and client population.

Quick Workflow

  1. Pick the right adapter for the target's band(s) and PHY
  2. Verify monitor mode + injection actually work
  3. Set the regulatory domain (legal channels and TX power)
  4. Sweep all bands passively
  5. Drill down on each in-scope BSSID for client population and PMF status
  6. Record everything in a structured target list before any active attack

Adapter Selection

ChipsetStrengthsNotes
Atheros AR9271 (Alfa AWUS036NHA)Solid 2.4 GHz monitor + injection802.11n only
Realtek RTL8812AU (AWUS036ACH)Dual-band, injectionDriver: aircrack-ng/rtl8812au
MediaTek MT7612U (AWUS036ACM)Stable dual-bandIn-tree driver on modern kernels
MediaTek MT7921AUWi-Fi 6 monitor (limited)Patched drivers required
AWUS036AXML / AXMWi-Fi 6E (6 GHz)Bleeding edge — verify per release
bash
# Identify your radio
lsusb | grep -iE "(atheros|realtek|mediatek|alfa)"
iw dev
iw list | grep -A 8 "Supported interface modes"
iw list | grep -E "Frequencies:" -A 30

Monitor Mode Setup

bash
# Kill conflicting services
sudo airmon-ng check kill

# Enable monitor mode
sudo airmon-ng start wlan0
# Or manually
sudo ip link set wlan0 down
sudo iw wlan0 set monitor control
sudo ip link set wlan0 up

# Verify monitor mode + injection
sudo aireplay-ng --test wlan0mon

The injection test should report 30/30 ack rates against nearby APs. Lower scores indicate driver, antenna, or position issues.

Regulatory Domain

bash
# Check current
iw reg get

# Set explicitly (us = United States, jp = Japan extended, etc.)
sudo iw reg set US

Setting the right regdomain unlocks legitimate channels (US: 1–11 on 2.4, 36–165 on 5; JP adds 12–13 + 184+ DFS) and TX power. Operate within the regdomain you're authorized to use.

Passive Multi-Band Sweep

bash
# All bands
sudo airodump-ng wlan0mon --band abg

# 5 GHz only (helps see UNII bands)
sudo airodump-ng wlan0mon --band a

# 6 GHz (requires 6E-capable adapter and updated airodump-ng)
sudo airodump-ng wlan0mon --band ax

# Hop only specific channels
sudo airodump-ng wlan0mon -c 1,6,11,36,40,44,48

Capture to file for later analysis:

bash
sudo airodump-ng wlan0mon --band abg --write recon --output-format pcap,csv

Targeted Capture

Once you've identified an in-scope BSSID:

bash
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w target wlan0mon

Pin to the channel — channel-hopping during a focused capture loses frames.

Hidden SSIDs

Hidden APs broadcast beacons with empty ESSID. The name leaks during client probes (active scan) or association requests:

bash
# Wait for legitimate client to associate, ESSID appears in airodump output
# Or, if a client is already associated, deauth them once to force reassociation:
sudo aireplay-ng --deauth 1 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon

(Only deauth with explicit authorization — see offensive-deauth-disassoc.)

Kismet for War-Driving

bash
sudo kismet -c wlan0mon
# Open https://localhost:2501 for the dashboard

Kismet handles GPS integration, plots APs to a map, fingerprints by IE order, identifies probable IoT vendors from OUI prefixes, and tags known-vulnerable models.

For long-running captures, drop --no-ncurses and run headless under tmux.

Show full SKILL.md (208 more words)Show less

Wigle Submission

If the engagement permits:

bash
# Export Kismet's .kismet → CSV → Wigle import format
kismetdb_dump_devices --in capture.kismet --out devices.csv

(Wigle aggregates wireless network observations geographically — useful for mapping but check ROE.)

Vendor / OUI Identification

bash
# Quick OUI lookup
echo "AA:BB:CC" | wireshark-tools/manuf-lookup
# Or check the airodump CSV's BSSID prefix against /usr/share/wireshark/manuf

Vendor identification informs:

  • Likely default credentials (router brand → known defaults)
  • Known firmware bugs (CVE per chipset)
  • Whether WPS is likely vulnerable (Pixie Dust per chipset)
  • Whether KRACK / FragAttacks patches are likely applied (vendor patch cadence)

Data to Record per Target

FieldWhy
BSSIDRequired for every active attack
ESSIDMatch against PNL probes; client probe correlation
Channel + widthPin radio for capture
BandAdapter selection
EncryptionWPA2-PSK / WPA2-Enterprise / WPA3-SAE / Open / WEP
PMF (Protected Management Frames)Whether deauth works
RSSIPosition planning
Beacon interval / TIMAnomaly detection vs. evil-twin defenders
Vendor (OUI)Likely default creds, known bugs
Client list (MACs + RSSI)Targets for deauth/relay
WPS enabled?Pixie Dust candidate

Detection Considerations

A defender's WIDS sees:

  • New device entering the airspace (probe requests reveal even before association)
  • Channel hopping patterns of monitor-mode interfaces
  • Non-standard probe behavior (KARMA-style universal responses, see offensive-evil-twin)

Pure passive recon (no probes from your radio) is invisible to most WIDS deployments. Stay passive until you're committed to the active phase.

Engagement Cheatsheet

bash
# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0
sudo iw reg set US
sudo aireplay-ng --test wlan0mon          # confirm injection (skip if pure passive)

# 2. Sweep all bands, write to file
sudo airodump-ng wlan0mon --band abg --write recon --output-format pcap,csv

# 3. Kismet for sustained map (optional)
sudo kismet -c wlan0mon --no-ncurses --daemonize

# 4. Per BSSID drill-down
sudo airodump-ng -c <ch> --bssid <BSSID> -w <name> wlan0mon

# 5. Build target list with all fields above

Key References

© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/wireless/offensive-wifi-recon of SnailSploit/Claude-Red.

Open the folder on GitHubat commit 739512a

Compare with similar skills

Offensive Wifi Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Offensive Wifi Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Offensive Wifi Recon this skillSnailSploit/Claude-Red7.4k—~1.7kAutomated safety check: NotesMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from SnailSploit/Claude-Red

All 10 skills in this repo
  • Offensive Krack Fragattacks

    SnailSploit/Claude-Red

    KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.

    7.4k GitHub stars~1.1k tokensUpdated 19 days ago
    Auto-check: notes
  • Offensive Fuzzing

    SnailSploit/Claude-Red

    Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…

    7.4k GitHub stars~3k tokensUpdated 19 days ago
    Auto-check: warnings
  • Offensive Lorawan Sub Ghz

    SnailSploit/Claude-Red

    LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…

    7.4k GitHub stars~1.7k tokensUpdated 19 days ago
    Auto-check passed
  • Offensive Mobile

    SnailSploit/Claude-Red

    Mobile (Android + iOS) application penetration testing methodology.

    7.4k GitHub stars~3.5k tokensUpdated 19 days ago
    Auto-check passed
  • Offensive Wifi

    SnailSploit/Claude-Red

    Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.

    7.4k GitHub stars~2.8k tokensUpdated 19 days ago
    Auto-check: notes
  • Offensive Wps

    SnailSploit/Claude-Red

    WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…

    7.4k GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check: notes

Categories

Questions about Offensive Wifi Recon

What does Offensive Wifi Recon do?

Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery…. Offensive Wifi Recon is an agent skill from SnailSploit/Claude-Red. Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspace mapping, hidden SSID discovery, BSSID/ESSID/channel/PMF/encryption fingerprinting, client probe analysis, vendor OUI lookup, war-driving with Kismet/airodump-ng/Wigle, and structured airspace data capture for downstream attacks.

When should I use Offensive Wifi Recon?

Offensive Wifi Recon fits situations like: security work in your project.

How do I install Offensive Wifi Recon in Claude Code?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi-recon -a claude-code`. Or copy the skill folder (Skills/wireless/offensive-wifi-recon in SnailSploit/Claude-Red) into .claude/skills/offensive-wifi-recon in your project. Claude Code loads it when a task matches its description.

How do I install Offensive Wifi Recon in Codex?

Run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi-recon -a codex`. Or copy the skill folder (Skills/wireless/offensive-wifi-recon in SnailSploit/Claude-Red) into .agents/skills/offensive-wifi-recon in your project. Codex loads it when a task matches its description.

Can I use Offensive Wifi Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-wifi-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-wifi-recon, .gemini/skills/offensive-wifi-recon, .github/skills/offensive-wifi-recon and .opencode/skills/offensive-wifi-recon in your project.

What does Offensive Wifi Recon need to run?

SKILL.md names no scripts, command-line tools or credentials: Offensive Wifi Recon is instructions for the agent only.

Does Offensive Wifi Recon access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Offensive Wifi Recon safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Offensive Wifi Recon use?

Offensive Wifi Recon is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Offensive Wifi Recon use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Offensive Wifi Recon?

Skills that share tags, products or a category with Offensive Wifi Recon: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Offensive Wifi Recon?

SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,362 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.

Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.