-
Notifications
You must be signed in to change notification settings - Fork 1
monitor mode
Summary: Monitor mode is the radio mode that lets a Wi-Fi interface hand every 802.11 frame it hears up to userspace — management and control frames included, from every device in range, not just the ones addressed to you. It is the single capability that turns sloth from an IP monitor into a Wi-Fi SIGINT tool. sloth reads a monitor interface; it never puts one into monitor mode itself.
Sources: src/platform/linux_wifi.c, src/capture/capture.c,
docs/views/{wifi,probe,beacons}.md, README.md "WiFi SIGINT usage",
IEEE 802.11-2020.
Last updated: 2026-09-30.
A Wi-Fi radio can hear far more than it normally reports. The driver mode decides how much reaches software:
| Mode | Hears | Reports to userspace | Can associate |
|---|---|---|---|
| Managed (normal) | its own AP | data frames addressed to this station | yes |
| Promiscuous | its own BSS | all data frames on the joined network | yes |
| Monitor | the whole channel | every frame — mgmt, control, data — from every device | no |
| AP / mesh | (transmit roles — out of scope, sloth never uses them) |
Promiscuous mode is the wired-Ethernet idea ported to Wi-Fi and it is not enough for SIGINT: it still only sees frames on the network you joined, and only data frames. Monitor mode is different in kind — the radio stops being a member of any network and becomes a listener on a channel. That is what exposes the management-frame class (how-wifi-works §2), which is where nearly all the passively-readable intelligence lives.
Because management frames are broadcast in the clear even on protected networks, a monitor interface yields all of this without any key:
-
Every AP in range — SSID (including hidden ones, revealed when a
client probes or associates), BSSID, channel, supported rates, and the
full security posture (RSN IE: ciphers, AKM suites, PMF state). Beacons
[b]. -
Every client in range — even ones not associated to anything —
from their Probe Requests, and the PNL (the SSIDs each remembers).
Probe
[7], PNL[k]. -
Who is on which AP — from Association/Reassociation frames and the
EAPOL handshake. Assoc
[w]. -
The WPA2 4-way handshake and PMKID — capturable passively, which
is what makes offline passphrase-strength testing of your own
network possible. EAPOL
[e], wifi-sigint. -
The sequence-number trail that survives MAC randomisation.
Seqnum
[j], mac-randomisation. -
Attack frames on the air — deauth/disassoc floods, forged action
frames, fragmentation attacks, evil-twin beacons, KARMA responses.
Deauth
[a], Twins[x], KARMA[y], FragAttacks[c]. - A signal reading (dBm) per frame → rough proximity.
A managed-mode NIC sees none of the above. This is why the
NO_MONITOR_MODE alert exists: if sloth sees interfaces but none in
monitor mode, it says so, because every WiFi SIGINT view will be empty.
sloth deliberately does not touch link state. You set the mode with a standard tool before starting sloth:
sudo ip link set wlan1 down
sudo iw dev wlan1 set type monitor
sudo ip link set wlan1 up
# then:
sudo ./sloth --collect-handshakes --eapol-dir /tmp/sloth-eapol \
-o /tmp/sloth.jsonlairmon-ng start wlan1 does the same and also kills interfering
processes. sloth auto-discovers the monitor interface at startup;
--monitor-only restricts the whole capture to it and fails closed if
none is found (cli-reference).
Requirements: a chipset+driver that supports monitor mode (not all do),
and CAP_NET_ADMIN / root. --hop additionally needs the driver to
accept channel retunes.
-
One channel at a time. The radio hears only its current channel;
the rest of the band is silent to it until it retunes (
--hop). A busy attacker on channel 36 is invisible while you dwell on channel 6. - No decryption. Data-frame payloads on a protected network stay encrypted. Monitor mode exposes metadata and management frames, not the plaintext inside WPA2/WPA3 data frames.
- No transmit. Monitor mode is receive-only in sloth's use. sloth never injects — see what-sloth-does "What it never does".
- Range is physics. You hear what your antenna hears; a weak signal is a weak signal.
-
"Monitor mode" is not a transmit interlock. The mode itself does
not stop a radio transmitting — that is a property of sloth's code, not
the mode. This is why sloth is explicit that
--hopand--allow-activeare the only kernel-state writes and both are opt-in.
- how-wifi-works — the frame classes monitor mode exposes.
- what-sloth-does — the tool this capability sits under.
- wifi-sigint — the SIGINT primitives built on captured frames.
- wifi-sigint-techniques — how an analyst uses the capture.
- where-exploits-happen — the attacks that ride the exposed frames.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance