Title: Capturing handshakes Description: Record Wi-Fi authentication data for analysis URL: /latest/wifi/handshakes/ Version: latest Section: Wi-Fi Search index: /search-index.json # Capturing handshakes > Record Wi-Fi authentication data for analysis ## On this page - [Capturing a handshake](#capturing-a-handshake) - [On-device UI](#on-device-ui) - [CLI](#cli) - [Copying the capture](#copying-the-capture) - [Troubleshooting](#troubleshooting) --- Capture Wi-Fi authentication handshakes from nearby networks for analysis. You need GhostESP with an SD card mounted to save captures, and a device that will connect to the target network so it can authenticate and create a handshake. Legal note: Only capture traffic from networks you own or have permission to test. See [Legal and ethical rules](/latest/wifi/basics/#legal-and-ethical-rules). The four EAPOL frames ClientAP association after a forced reconnectA short deauth makes the client rejoin EAPOL 1 - ANonceKey Info: pairwise, ACK requested EAPOL 2 - SNonce + MICClient nonce and MIC EAPOL 3 - GTK + MICInstall flag set; encrypted GTK delivered EAPOL 4 - ACKHandshake complete GhostESP forces a reconnect, then records all four frames so the passphrase can be tested offline (or the PMKID from message 1). ## Capturing a handshake ### On-device UI - Open Menu → Wi-Fi → Scanning and find your target network. - Select it with Select AP to lock onto that channel. - Open Menu → Wi-Fi → Capture → Capture Eapol. The device will start listening for authentication activity. - Wait for a device to connect or reconnect to the network. You should see Handshake found! when the capture succeeds. - Back out to stop capturing. - The capture is saved to the SD card under /mnt/ghostesp/pcaps/. - To convert it for offline cracking, choose Menu → Wi-Fi → Capture → Export Handshakes (hc22000). ### CLI - Run list -a to see nearby networks. - Run select -a <number> to lock onto your target network. - Run capture -eapol to start listening. - Wait for a device to authenticate to the network. You should see Handshake found! when successful. - Run capture -stop to finish capturing. The file location will be shown in the log. - Run capture -export <pcap-file> to write an hc22000 file for offline cracking. ## Copying the capture - Copy the .pcap file from the device to your computer for further analysis. - For Flipper Zero saved files, copy the file from /ext/apps_data/ghost_esp/pcaps/ on the Flipper’s SD card. ## Troubleshooting - No handshake found: Make sure a device is actually connecting to the network. Try toggling Wi-Fi off and on on a connected device to trigger a new authentication. - Capture file missing: Verify the SD card is mounted and has free space. Check that you stopped the capture.