kismet¶
Wireless network and device detector, sniffer and logger for Wi-Fi, Bluetooth and SDR sources
- Version recorded: 2025.09.R1
- Categories:
bluetooth,capture-analysis,wifi - Upstream: https://www.kismetwireless.net/
- Not a recommended default — installed only when asked for.
What it does¶
Listens to wireless traffic through one or more capture sources -- a Wi-Fi card in monitor mode, the laptop's Bluetooth adapter, an Ubertooth, Zigbee and BLE sniffer dongles, an RTL-SDR decoding ISM sensors or aircraft -- and builds a live list of every network and device it hears, with channels, signal strength, manufacturers, and GPS positions when gpsd is running. Everything is logged to a .kismet database that kismetdb_to_pcap, kismetdb_to_kml and the other kismet-logtools convert afterwards. It is operated from a web browser pointed at the machine it runs on.
Why you would want it¶
It is the long-standing open tool for wireless survey and wardriving, and the one that puts Wi-Fi, Bluetooth and a dozen sniffer dongles in one view instead of one program each. On your own network it answers what is actually on the air: rogue access points, a neighbour's channel crowding yours, every Bluetooth tracker in the room. It is the alternative to juggling airodump-ng, a Bluetooth scanner and Wireshark side by side; Wireshark stays the tool for reading individual frames, and Kismet writes pcapng it can open.
Before it will work¶
A capture source Kismet has a helper for. For Wi-Fi, an adapter whose driver supports monitor mode: Kismet switches it itself when you add it as a source, and many built-in laptop cards cannot. For Bluetooth, the machine's own adapter works through BlueZ. You must be in the kismet group (added by this install; log out and back in first), or run Kismet with sudo, which upstream advises against. Start it with kismet in a terminal, open http://localhost:2501, set the login, and add sources under Data Sources -- or name one on the command line, kismet -c wlan1. The CatSniffer V3 is not a source in any packaged Kismet yet; see the known problems.
How it installs¶
- apt:
kismet kismetis a metapackage in every packaging measured: kismet-core, kismet-logtools and the capture helpers (Wi-Fi, Linux Bluetooth, Ubertooth One, nRF51822, nRF52840, nRF MouseJack, TI CC2531 and CC2540, NXP KW41Z, RZ KillerBee, Freaklabs Zigbee, rtl_433, rtladsb, AntSDR DroneID, Radiacode, Radview, Hak5 WiFi Coconut). On Kali and Parrot it comes from the archive; on Debian 13, Ubuntu 24.04 and Mint 22.3 from the Kismet repository for that release (listed under its apt_repos), after its gate; on Ubuntu 26.04 nothing offers it yet and it is deferred by name.
What it changes on your machine¶
- apt_pin — On Debian 13, Ubuntu 24.04 and Linux Mint 22.3 only: adds Kismet's release repository for that release and pins its signing key. Does NOT happen on Kali or Parrot, which carry kismet in their own archives.
- Writes /etc/apt/sources.list.d/kismet-trixie.sources (Debian 13) or kismet-noble.sources (Ubuntu 24.04, Mint 22.3), and the signing key in binary form to /etc/apt/keyrings/kismet-trixie.gpg or kismet-noble.gpg, with Signed-By naming that keyring, so the key is trusted for this repository only and not archive-wide.
- undo: sudo rm /etc/apt/sources.list.d/kismet-trixie.sources /etc/apt/keyrings/kismet-trixie.gpg && sudo apt update (kismet-noble in place of kismet-trixie on Ubuntu 24.04 and Mint 22.3);
hammunition uninstall kismetremoves both files itself - group_membership — Adds the operator to the
kismetgroup, so Kismet's capture helpers run for them without running Kismet as root - With install-setuid answered true (the debconf lines this manifest preseeds), every packaging measured creates a
kismetsystem group and makes each capture helper (/usr/bin/kismet_cap_*) owned root:kismet and runnable by that group only: setuid root on Kali and Parrot, and on Kismet's own packages cap_net_raw and cap_net_admin through setcap, falling back to setuid when setcap is unavailable. Neither packaging adds anyone to the group on a noninteractive install, which is why the engine does. Membership is the ability to put radios into capture modes and capture what they hear, so treat it likewiresharkgroup membership. It does not apply to a session already open -- log out and back in. - undo: sudo gpasswd -d $USER kismet
Third-party apt repositories¶
Added only when the target's own archive has no candidate, and only after you affirm the key fingerprint (D-040); --yes does not answer it.
- kismet-trixie — on debian; version 13
https://www.kismetwireless.net/repos/apt/release/trixiesuitetrixie, componentmain- key: https://www.kismetwireless.net/repos/kismet-release.gpg.key
- fingerprint:
ADA09A0E9B80ACCCE8FE6BB65345B8BF43403B93 - kismet-noble — on ubuntu, linuxmint; version 24.04, 22.3
https://www.kismetwireless.net/repos/apt/release/noblesuitenoble, componentmain- key: https://www.kismetwireless.net/repos/kismet-release.gpg.key
- fingerprint:
ADA09A0E9B80ACCCE8FE6BB65345B8BF43403B93
Known problems¶
Kismet's web interface listens on every interface by default, not only on this machine, and the first browser to reach it sets the login: on a shared or public network, set httpd_bind_address=127.0.0.1 in /etc/kismet/kismet_site.conf before the first run. On Kali and Parrot the kismet-core package also installs and enables kismet.service, which runs Kismet as root at boot and restarts it if it stops (read from the package's postinst, deb-systemd-helper enable and a start when systemd is running; not observed on a running system); Kismet's own packages ship the same unit without enabling it. If you only want Kismet when you start it, sudo systemctl disable --now kismet.service; do the same before hammunition uninstall kismet, which removes the kismet metapackage and leaves kismet-core -- and that service -- for apt autoremove. If kismet in a terminal reports the port in use, that service is the reason. Site settings belong in /etc/kismet/kismet_site.conf, never in kismet.conf, which package upgrades replace. A source that will not open is almost always one of three things: the card cannot do monitor mode, the capture helper for that hardware is not installed, or you were added to the kismet group in a session that is still open -- docs/rf-security/kismet.md walks through each. The CatSniffer V3's Zigbee helper (capture_catsniffer_zigbee, on Kismet's development branch since 2024-09-18) and its Sniffle BLE helper (since 2026-07-22) are in no release: not in the 2025-09-R1 tag, not in Kali's or Parrot's packages, not in Kismet's release or nightly repositories (their Contents list no kismet_cap_catsniffer or sniffle binary, 2026-09-30). Until a release carries them, the CatSniffer is used through its own tooling and Wireshark. Ubuntu 26.04 has no Kismet release repository yet, so Kismet is deferred there.
Keeping it current¶
- probe: apt policy
- strategy: apt_upgrade
Where to get help with the software itself¶
Documentation at https://www.kismetwireless.net/docs/; issues at https://github.com/kismetwireless/kismet/issues. GPL-2.0 (the repository's LICENSE: "released under the GPL2 license" unless a file says otherwise). Liveness per D-032: default branch master, head cfe427074b7f committed 2026-09-17; latest release tag kismet-2025-09-R1, committed 2025-09-04.
Source: catalog/packages/kismet.yaml