passive-scan + offensive daemon
The WiFi reconnaissance daemon for OpenWrt routers. Listens to the spectrum, captures WPA handshakes and runs offensive actions — all from the radio, on the air.
// what it does on-air
Runs on the radio in monitor mode. No agent, no cloud — captures and acts locally.
Discovers APs and clients on 2.4 / 5 / 6 GHz, parallel capture per radio with its own channel-hopping.
WPA/WPA2 4-way handshakes captured and exported to hashcat .22000 format, ready to crack.
Opportunistically grabs the RSN PMKID from a single AP frame during recon — no client needed — and exports it to hashcat alongside 4-way handshakes.
Deauth and disassoc against a target to force reconnection and capture the handshake.
Broadcasts a pool of SSIDs as fake APs on the air — reuses the same injection path.
Fail-closed allow / deny lists to scope recon and offense to an authorized target.
WiGLE CSV logging via gpsd to map the survey on the ground.
Presence alerts (arrived / left) per MAC and deauth-flood detection, with per-pattern rules.
Hook your own scripts to each event (presence, flood, watch) and react however you want.
// datasheet
| OpenWrt | 23 · 24 · 25 soon |
|---|---|
| Architecture | mipsel / mips (BE) / ARM / ARM64 |
| RAM | 128 MB recommended |
| Storage | ~10 MB free flash (binary + capture DB, grows) |
| Radios | 1+ monitor-mode adapter (multi-adapter on full) |
| Bands | 2.4 / 5 / 6 GHz |
| WPA export | hashcat .22000 |
| Interface | web panel + CLI |
// license
All capabilities, multi-adapter. Activation tied to your hardware.
includes
price
Secure payment with Stripe. Card and email are entered in Stripe's checkout — never here.
// faq
An OpenWrt 23 or 24 router (25 coming soon) on mipsel, mips, ARM or ARM64 — ramips/MT7621, ath79 and similar. Around 128 MB RAM and ~10 MB free flash, plus at least one WiFi adapter capable of monitor mode. For multi-band capture or dedicated injection, add a second radio (full is multi-adapter).
Activation is tied to the device hardware. You buy here, receive your license by email and the panel activates it against the server.
full is the complete edition sold on this page: multi-adapter capture plus every
subsystem — GPS / wardriving, presence monitoring and flood detection, MAC/SSID filters,
beacon-flood, event hooks and raw frame injection. lite is the single-adapter entry
edition: passive recon, WPA 4-way handshake capture with deauth, clientless PMKID
and hashcat .22000 export — the core "scan and grab a handshake" workflow,
without the full-only subsystems. Aura lite is available to Patreon supporters —
back the project on Patreon to get the lite build; this page sells full.
The tool is legal; how you use it is on you. It's meant for authorized pentesting, your own networks, labs and education. Outside of that it may be illegal — don't do it.