ZeroTrace AirLeak Pro
Wi-Fi Ops
The active Wi-Fi testing tools, what each does, how it's configured, and what it reports
The Wi-Fi Ops run on the Pro's dedicated Wi-Fi co-processor (the ESP32-C5). Every one is configured and controlled from the app over Bluetooth, transmits or captures on the 2.4 GHz / 5 GHz bands, and streams live status back while it runs. There is no console on the device.
Every tool on this page transmits or captures traffic. Every transmitting Op requires you to explicitly confirm authorization before it will arm. Use them only against infrastructure you own or are contracted to test, within your agreed scope, with authorization on file. See Privacy & Legal.
The Wi-Fi Ops all share the single C5 radio, so they are mutually exclusive: arming one stops any other, and while a transmitting Op runs it pauses normal survey harvesting. The app's Ops view shows what's active. Bluetooth Ops run on the separate main-processor radio, so they aren't affected by this rule.
Beacon
Broadcasts test access-point beacons and hops across channels 1, 6, and 11 so the fake networks are visible to clients on all three common 2.4 GHz channels. Use it to observe how client devices react to particular network names, to test whether a monitoring system notices unexpected SSIDs, and for awareness demonstrations.
Three modes:
| Mode | What it broadcasts |
|---|---|
| Custom SSIDs | A list of up to 16 network names you supply. This mode requires at least one SSID. |
| Random | A set of randomly generated SSIDs. You choose a count of 1–50 (default 20). |
| Pwnagotchi | Spoofed Pwnagotchi advertisement beacons, each carrying a fake Pwnagotchi name, face, and JSON identity information element, to bait or test tools that look for Pwnagotchi units. |
Key settings: the mode, the SSID list or random count, and a secured flag that advertises the fake networks as secured rather than open.
Reports: whether it's active, the active mode and secured flag, the beacon/SSID count, total frames sent, frames-per-second, and a stalled indicator.
Use it to: test client behaviour, exercise rogue-AP detection, run awareness demos.
Deauth
Sends deauthentication and disassociation frames to test how a network and its clients handle connection disruption, and to validate that a defense such as PMF (protected management frames) actually holds.
Key settings: a single target MAC (leave empty to broadcast to all clients of a network), or a list of up to 8 targets, each with its own bssid, channel, and optional ssid. The op rotates through reason codes (1, 4, 6, 7, 8) as it transmits. For a unicast target it sends both deauth and disassociation frames in both directions (AP-to-client and client-to-AP) for maximum effect.
Reports: frames sent and frames-per-second.
Modern networks with protected management frames (WPA3, or WPA2 with PMF) are resistant to deauthentication. Confirming that a target network holds up is often the point of the test.
Use it to: verify PMF / management-frame protection, test client reconnection behaviour, validate wireless IDS/IPS response, all against gear you control.
Deauth detector
The passive, defensive counterpart to Deauth. It listens for incoming deauthentication (0xC0) and disassociation (0xA0) frames and reports who is sending them, so you can tell whether someone is running a deauth attack in an environment you're monitoring. It transmits nothing.
Reports: a list of attackers, each with MAC address, total frame count, last RSSI, channel, whether the frames are deauth vs disassoc, whether they're broadcast-style, and an age since last seen.
Use it to: catch active deauth attacks, monitor an environment for wireless disruption.
Handshake capture
Captures the WPA 4-way handshake for a target network you're auditing and saves the frames to a standard .pcap on the microSD card (/handshakes/HS_<bssid>.pcap, libpcap link-type 105). You then run an offline password-strength audit against that capture with your own tools.
Key settings: the target bssid (required), an optional channel, and an optional ssid used as the capture filename.
Reports: an EAPOL message mask showing which of the four handshake messages (M1–M4) have been seen, the EAPOL message count, whether a PMKID was captured, a usable flag (true when it has M2 + M3, or a PMKID — either is enough for an offline audit), total frames, and the output file path.
Handshake capture writes to SD. Insert a formatted microSD card before arming, or there is nowhere to save the capture.
Use it to: audit the password strength of a network you're authorized to assess, offline, against the capture.
Captive / Evil Portal
Stands up a rogue captive-portal access point for social-engineering and awareness assessments. It runs a SoftAP, hijacks DNS so every lookup resolves to the portal (192.168.4.1), and serves the OS captive-probe endpoints that Apple, Android, and Windows check on join — so the portal page auto-pops on a connecting device just like a real "sign in to Wi-Fi" screen.
The page: by default it serves a "Sign in to Wi-Fi" login page that posts a username and password. You can replace it with your own HTML, supplied either as chunks pushed from the app or loaded from a file on the SD card. A custom file can carry TITLE="..." and AP="..." directives to set the page title and AP name inline.
Key settings: the ssid (1–32 chars); an optional spoofed BSSID (spoof_mac); an optional auto_stop_s timer that tears the portal down automatically; and a post-capture action (post_action) that decides what a client sees after submitting — mark it connected, tell it to retry, show a custom message (post_message), or redirect it.
Captures: all submitted POST fields (not just user/password) are captured to an in-memory ring of the last 32 and appended to /captures/portal.log on SD. It also tracks each client with its IP, MAC, RSSI, OS guess (fingerprinted from the user agent), and whether that client has viewed the page and submitted credentials.
Reports: whether it's armed, the SSID, connected-client count, and capture count.
A captive portal collects what people type. Only run one under explicit authorization, handle any captured data per your engagement rules and applicable privacy law, and dispose of it properly afterwards.
Use it to: run authorized phishing / awareness assessments and measure how users respond.
Drone Remote ID
Broadcasts a standards-based ASTM F3411 Open Drone ID beacon (using the ODID OUI FA:0B:BC:0D) so you can test Remote-ID receivers and counter-drone detection systems from the transmitter side. It advertises a drone that isn't there.
Key settings: an operator ID (op_id, up to 20 chars, required), a channel (1–14, default 6), and the broadcast position — latitude and longitude (in 1e7-scaled integers) and altitude in metres.
Reports: the number of Remote-ID messages published.
Use it to: exercise and validate Remote-ID receivers and counter-drone detection.
Raw capture (pcap)
Saves all swept 802.11 management frames to a standard radiotap .pcap on the microSD card (/pcap_NNN.pcap, link-type 127) with no filtering — the general-purpose "record everything in the air" capture for offline analysis in Wireshark or similar.
Reports: frames captured, frames dropped, and bytes written.
Raw capture buffers to PSRAM and writes to microSD. It requires both a microSD card and the C5's PSRAM to run.
Use it to: capture Wi-Fi traffic for offline protocol analysis.
A note on the survey harvester
The normal Wi-Fi survey that runs outside the Ops Suite is not purely passive. To improve coverage and to surface misbehaving access points, the harvester injects randomized probe requests and a KARMA wildcard probe (a broadcast probe using a sentinel SSID) to bait access points that answer any network name — it then flags those as lure / KARMA / wildcard responders in the capture. It's worth knowing that even "just surveying" puts a small amount of traffic on the air.
Ops are configured and controlled from the app — there's no console on the device. Each Op reports live status (frames sent, clients seen, handshake progress) back to the app while it runs, and the Ops view lets you see and stop whatever is active.