daemon on-air · OpenWrt 24 · mipsel

passive-scan + offensive daemon

Aura full

The WiFi reconnaissance daemon for OpenWrt routers. Listens to the spectrum, captures WPA handshakes and runs offensive actions — all from the radio, on the air.

See capabilities

// what it does on-air

Passive recon and offense, in a single daemon

Runs on the radio in monitor mode. No agent, no cloud — captures and acts locally.

recon

Passive multi-radio scanning

Discovers APs and clients on 2.4 / 5 / 6 GHz, parallel capture per radio with its own channel-hopping.

handshakes

WPA capture to hashcat

WPA/WPA2 4-way handshakes captured and exported to hashcat .22000 format, ready to crack.

handshakes

Clientless PMKID capture

Opportunistically grabs the RSN PMKID from a single AP frame during recon — no client needed — and exports it to hashcat alongside 4-way handshakes.

offensive

Targeted deauth / disassoc

Deauth and disassoc against a target to force reconnection and capture the handshake.

offensive

Beacon-flood

Broadcasts a pool of SSIDs as fake APs on the air — reuses the same injection path.

control

MAC / SSID filters

Fail-closed allow / deny lists to scope recon and offense to an authorized target.

geo

GPS / wardriving

WiGLE CSV logging via gpsd to map the survey on the ground.

watch

Presence monitoring

Presence alerts (arrived / left) per MAC and deauth-flood detection, with per-pattern rules.

automation

Event hooks

Hook your own scripts to each event (presence, flood, watch) and react however you want.

// datasheet

Built for the hardware you already have

OpenWrt23 · 24 · 25 soon
Architecturemipsel / mips (BE) / ARM / ARM64
RAM128 MB recommended
Storage~10 MB free flash (binary + capture DB, grows)
Radios1+ monitor-mode adapter (multi-adapter on full)
Bands2.4 / 5 / 6 GHz
WPA exporthashcat .22000
Interfaceweb panel + CLI

// license

Aura full — complete edition

All capabilities, multi-adapter. Activation tied to your hardware.

includes

  • 2 active devices per license (swap hardware from the panel)
  • 1 year of updates — every release published in the window
  • Perpetual license — your last obtained version keeps working forever, even after updates lapse
  • Passive multi-radio recon (2.4 / 5 / 6 GHz)
  • WPA handshake capture + hashcat export
  • Clientless PMKID capture (passive)
  • Offense: deauth, beacon-flood
  • Presence monitoring + flood detection
  • MAC/SSID filters, GPS/wardriving, event hooks
  • Web panel + CLI + edition updates

price

Early adopter price
70.00 USD
one-time payment · 1 year of updates · perpetual license
Launch / founder price — increases after the early-adopter window.

Secure payment with Stripe. Card and email are entered in Stripe's checkout — never here.

authorized use

Aura is an assessment tool for your own networks or ones you have explicit authorization to test. WiFi capture and injection are regulated in many jurisdictions — you are responsible for using it within the law and your engagement.

// faq

Questions

What hardware do I need?

An OpenWrt 23 or 24 router (25 coming soon) on mipsel, mips, ARM or ARM64 — ramips/MT7621, ath79 and similar. Around 128 MB RAM and ~10 MB free flash, plus at least one WiFi adapter capable of monitor mode. For multi-band capture or dedicated injection, add a second radio (full is multi-adapter).

How does the license work?

Activation is tied to the device hardware. You buy here, receive your license by email and the panel activates it against the server.

Aura full vs Aura lite?

full is the complete edition sold on this page: multi-adapter capture plus every subsystem — GPS / wardriving, presence monitoring and flood detection, MAC/SSID filters, beacon-flood, event hooks and raw frame injection. lite is the single-adapter entry edition: passive recon, WPA 4-way handshake capture with deauth, clientless PMKID and hashcat .22000 export — the core "scan and grab a handshake" workflow, without the full-only subsystems. Aura lite is available to Patreon supporters — back the project on Patreon to get the lite build; this page sells full.

Is it legal to use this?

The tool is legal; how you use it is on you. It's meant for authorized pentesting, your own networks, labs and education. Outside of that it may be illegal — don't do it.