Skip to content

hcxdumptool

Wi-Fi frame capture aimed at producing hash files for offline analysis

What it does

Captures 802.11 frames directly from a monitor-mode interface, targeting the material needed to reconstruct PMKIDs and handshakes rather than recording everything.

Why you would want it

It captures what is actually needed for offline analysis instead of a full packet dump, which makes both the capture and the file that comes out of it far smaller. Paired with hcxtools it is the modern path where aircrack- ng's own capture is the traditional one.

Before it will work

A monitor-mode capable adapter, and hcxtools to convert what it produces.

How it installs

  • apt: hcxdumptool

Known problems

It transmits by default in some modes -- it will actively solicit responses rather than only listening -- which is a materially different act from passive capture and is worth knowing before pointing it at anything. Version 6.x and 7.x take different command-line options, and Debian 13 and Parrot ship 6.3.5 while Kali ships 7.1.2 (apt-cache policy, 2026-08-28; Ubuntu 26.04 ships a third pair, 7.0.0 dumptool with 7.1.0 tools), so instructions from one will not run on the other.

Keeping it current

  • probe: apt policy
  • strategy: apt_upgrade

Source: catalog/packages/hcxdumptool.yaml