CTS 125: 802.11 Frame Captures on Windows




Clear To Send: Wireless Network Engineering show

Summary: We take a look at what resources are available to capture frames on Windows OS.<br> 802.11 Frame Captures on Windows<br> Back in episode 121, we spoke highly of Macbook Pros being perfect tools for wireless frame captures. But not everyone has a Macbook Pro. Even I still have a Windows laptop and need to do frame captures on that every once and a while.<br> In this episode, we outline some of the resources we use for capturing frames on Windows OS. Both free and paid versions depending on how you’re trying to capture frames and how quickly you’re trying to accomplish the task.<br> Budgets will vary widely with each resource so check for the most updated pricing online.<br> Acrylic Wi-Fi Professional<br> You can try out Acrylic Wi-Fi with a trial version free for 4 days. As of June 2018, a license is $39.95 one time fee (or $19.95 for 1 year). It has a built in 802.11 packet capture tool without requiring additional hardware. But it only captures beacon frames if your Wi-Fi NIC does not support monitor mode.<br> <a href="http://www.cleartosend.net/wp-content/uploads/2018/06/acrylic-04-Packet-Capture-view.png"></a><br> The NDIS driver must be installed so your built in Wi-Fi NIC can be used in monitor mode.  If you want, you can use an external adapter to perform the capture. Acrylic recommends the following:<br> <br> * D-Link DWA-182 Revision A1<br> * Netgear A6200<br> * Asus USB-AC53<br> * List of <a href="https://www.acrylicwifi.com/en/wlan-wifi-wireless-network-software-tools/wifi-analyzer-acrylic-professional#fusion-tab-requirements" target="_blank" rel="nofollow noopener">compatible Wi-Fi NICs</a><br> <br> By default, it will be channel hopping. So don’t forget to set the channel on which you want to scan. We strongly recommend using a Riverbed AirPcap card if you are going to do anything professional.<br> Some of the packet capture features include:<br> <br> * Display the Packet Tree view including the details of the Radio Tap Header<br> * Displays the Hex and Binary view of the packet<br> * You can export the frames into a pcap file and analyze them with another tool (Wireshark)<br> * Integration with Wireshark<br> * 802.11ac not there with AirPcap Nx<br> <br> Other Features:<br> <br> * Wi-Fi Scanner<br> * Show Retry Rate when set to monitor mode<br> * Displays the SSID detected (including the hidden SSID)<br> * Displays some beacon details<br> * Script editor built-in<br> * Reports<br> * Inventory<br> <br> Links:<br> <br> * <a href="https://www.acrylicwifi.com/en/wlan-wifi-wireless-network-software-tools/wifi-analyzer-acrylic-professional/" target="_blank" rel="nofollow noopener">https://www.acrylicwifi.com/en/wlan-wifi-wireless-network-software-tools/wifi-analyzer-acrylic-professional/</a><br> * <a href="https://www.youtube.com/watch?v=buMJ9NDCsGA" target="_blank" rel="nofollow noopener">https://www.youtube.com/watch?v=buMJ9NDCsGA</a><br> * <a href="https://www.acrylicwifi.com/en/blog/how-to-capture-wifi-traffic-using-wireshark-on-windows/" target="_blank" rel="nofollow noopener">https://www.acrylicwifi.com/en/blog/how-to-capture-wifi-traffic-using-wireshark-on-windows/</a><br> <br> Microsoft Network Monitor<br> This tool is free to use with your operating system. You can download the application from <a href="https://www.microsoft.com/en-us/download/details.aspx?id=4865" target="_blank" rel="nofollow noopener">Microsoft</a> and check out a full <a href="https://www.cellstream.com/intranet/reference-reading/tipsandtricks/332-capturing-wi-fi-wlan-packets-on-windows-for-free.html" target="_blank" rel="nofollow noopener">tutorial</a>.<br> You can find a <a href="https://www.youtube.com/watch?v=yRcd8LaNlNE&amp;feature=youtu.be" target="_blank" rel="nofollow noopener">Video Tutorial</a> easily on YouTube.<br> <a href="http://www.cleartosend.net/wp-content/uploads/2018/06/windows-network-monitor-01-Monitor-mode-and-channel-se..."></a>