-
Notifications
You must be signed in to change notification settings - Fork 1
where exploits happen
Summary: A defender's map of the Wi-Fi attack surface. It walks the same join sequence a client experiences (how-wifi-works §3) and, at each step, names the attack classes that target it, what they look like to a passive listener, and the sloth detector that catches them. The framing is deliberate: attacks live at protocol seams, and sloth's job is to see the seam being worked.
Sources: docs/views/alerts.md, src/alerts.c,
docs/wiki/{fragattacks,btm-abuse,action-frames,enterprise-rogue,captive-portal,evil-twin-reproducer}.md,
research corpus under research/.
Last updated: 2026-09-30.
Wi-Fi's weak points are structural, not incidental:
- Management frames are unauthenticated by default. Without PMF (802.11w), a client cannot tell a real Deauth from a forged one.
- The passphrase handshake is passively capturable. WPA2's 4-way handshake and PMKID verify an offline guess.
- Clients advertise what they trust. Probe Requests name remembered networks, and a client will connect to any AP claiming that name.
Every attack below exploits one of those three. sloth cannot stop them — it is passive — but it can see all three being used.
| Attack | On-the-air signature | sloth detector |
|---|---|---|
| Evil twin — clone an AP's SSID, lure clients | duplicate SSID, mismatched BSSID/cipher/OUI |
EVIL_TWIN (+confidence), Twins [x], evil-twin-reproducer
|
| KARMA / MANA — answer every probed SSID | one radio responding as many SSIDs |
KARMA_AP, KARMA [y]
|
| Beacon flood — spray fake SSIDs | high rate of distinct SSIDs from one source | BEACON_FLOOD |
| SSID confusion (CVE-2023-52424) | client joins a network under the wrong name | SSID_CONFUSION |
| Open onboarding AP left exposed | open AP with a setup-shaped SSID | OPEN_SETUP_AP |
| Rogue reconnaissance of your net | client probing an SSID you designated as yours |
MY_NET_RECON (needs --my-ssid) |
| Attack | On-the-air signature | sloth detector |
|---|---|---|
| Deauth / disassoc flood — force disconnects | burst of deauth/disassoc frames at a target |
DEAUTH_FLOOD, Deauth [a]
|
| Auth / assoc flood — exhaust an AP | burst of auth or assoc requests |
AUTH_FLOOD, ASSOC_FLOOD
|
| Management fuzzing — malformed mgmt frames | spec-violating frame fields | MGMT_FUZZ |
| BTM steering abuse (802.11v) — move a client with no deauth | BSS Transition Request w/ Disassoc-Imminent toward a chosen BSSID |
BTM_ABUSE, btm-abuse, action-frames
|
| SA-Query storm / spoofed disassoc under PMF | SA-Query flood as the symptom of a forged disassoc |
SA_QUERY_FLOOD, MFP_UNPROTECTED, action-frames
|
| CSA abuse — forge a channel-switch to move clients | Channel Switch Announcement from a non-AP | CSA_ABUSE |
| RRM survey abuse (802.11k) — probe topology | crafted radio-measurement requests | RRM_SURVEY_ABUSE |
| Attack | On-the-air signature | sloth detector |
|---|---|---|
| Handshake / PMKID capture — offline passphrase guessing | captured 4-way handshake or PMKID | EAPOL [e] captures it (your own net testing), wifi-sigint
|
| WPA downgrade — force WPA1/weaker cipher | a network advertising both, or a rollback |
WPA_DOWNGRADE, WEAK_TLS (TLS analogue) |
| SAE / Dragonblood (WPA3) — downgrade or split PSK/SAE | mixed SAE/PSK advertisement, transition-mode abuse |
SAE_PSK_SPLIT, SAE_PSK_REGRESSION
|
| FragAttacks (Vanhoef 2021) — 12 CVEs in fragmentation/aggregation | plaintext/broadcast frags, mixed-key reassembly, A-MSDU abuse | seven FRAG_* rules, FragAttacks [c], fragattacks
|
| Block-Ack manipulation | forged Block-Ack to drop frames | BLOCKACK_ATTACK |
| RTS flood | RTS control-frame flood | RTS_FLOOD |
| Attack | Signature | sloth detector |
|---|---|---|
| Rogue RADIUS / EAP (WPA-Enterprise) | rogue 802.1X authenticator, identity leak |
ROGUE_RADIUS, Rogue RADIUS [z], enterprise-rogue
|
| PEAP with no server-cert check (CVE-2023-52160) — your own fleet | client accepting an unverified server |
PEAP_NO_SERVER_CERT, enterprise-rogue
|
| Captive-portal interception | rogue portal answering the OS connectivity probe |
CAPTIVE_PORTAL, captive-portal
|
| Rogue IPv6 RA (mitm6) | crafted Router Advertisement |
ROGUE_RA, ipv6-ndp
|
| ARP / DHCP spoofing | one IP → two MACs; unexpected DHCP OFFER |
ARP_SPOOF, ROGUE_DHCP
|
| Cleartext credentials | username in the clear (HTTP/FTP/POP3/IMAP/SMTP) | CLEARTEXT_CRED |
Upper-layer service attacks (SMB1, Kerberos spray, LDAP recon, SSH/RDP/ SNMP/MQTT brute force, C2 beaconing, DGA, DNS/ICMP tunnels) ride the same capture and have their own snoop pages — see attack-map.
- Passive detection sees behaviour on the air, not intent. A deauth flood and a flaky driver both produce deauth frames; sloth reports the frames and lets the operator judge. Confidence is separated from severity for exactly this reason (alerts).
- One channel at a time (monitor-mode) — an attack on a channel you are not dwelling on is unseen.
- Some detectors ship empty by design — the tool-fingerprint table (tool-fingerprints) and the threat-intel IOC list (threat-intel) — because a dishonest signature is worse than none.
- how-wifi-works — the join sequence this map follows.
- monitor-mode — why sloth can see these frames at all.
- wifi-sigint-techniques — the analyst techniques, defender-side.
- attack-map — the full protocol→view index.
- alerts — every rule, trigger, and cited basis.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance