Capturing handshakes
Record Wi-Fi authentication data for analysis
On this page
Capture Wi-Fi authentication handshakes from nearby networks for analysis. You need GhostESP with an SD card mounted to save captures, and a device that will connect to the target network so it can authenticate and create a handshake.
Legal note: Only capture traffic from networks you own or have permission to test. See Legal and ethical rules.
ClientAP
association after a forced reconnectA short deauth makes the client rejoin
EAPOL 1 - ANonceKey Info: pairwise, ACK requested
EAPOL 2 - SNonce + MICClient nonce and MIC
EAPOL 3 - GTK + MICInstall flag set; encrypted GTK delivered
EAPOL 4 - ACKHandshake complete
GhostESP forces a reconnect, then records all four frames so the passphrase can be tested offline (or the PMKID from message 1).
Capturing a handshake
On-device UI
- Open Menu → Wi-Fi → Scanning and find your target network.
- Select it with Select AP to lock onto that channel.
- Open Menu → Wi-Fi → Capture → Capture Eapol. The device will start listening for authentication activity.
- Wait for a device to connect or reconnect to the network.
You should see
Handshake found!when the capture succeeds. - Back out to stop capturing.
- The capture is saved to the SD card under
/mnt/ghostesp/pcaps/. - To convert it for offline cracking, choose Menu → Wi-Fi → Capture → Export Handshakes (hc22000).
CLI
- Run
list -ato see nearby networks. - Run
select -a <number>to lock onto your target network. - Run
capture -eapolto start listening. - Wait for a device to authenticate to the network.
You should see
Handshake found!when successful. - Run
capture -stopto finish capturing. The file location will be shown in the log. - Run
capture -export <pcap-file>to write an hc22000 file for offline cracking.
Copying the capture
- Copy the
.pcapfile from the device to your computer for further analysis. - For Flipper Zero saved files, copy the file from
/ext/apps_data/ghost_esp/pcaps/on the Flipper’s SD card.
Troubleshooting
- No handshake found: Make sure a device is actually connecting to the network. Try toggling Wi-Fi off and on on a connected device to trigger a new authentication.
- Capture file missing: Verify the SD card is mounted and has free space. Check that you stopped the capture.
