bettercap
A framework for scanning, monitoring, and executing man-in-the-middle attacks on WiFi, Bluetooth Low Energy, HID, CAN-bus, and IP networks
It takes care to curate a safe software space. Help us do more.
&
| + | WiFi Reconnaissance & Attacks | Scans WiFi networks and runs deauthentication and clientless PMKID attacks, plus automatic WPA/WPA2/WPA3 handshake capture. |
|---|---|---|
| + | BLE Scanning | Discovers Bluetooth Low Energy devices and enumerates, reads, and writes their characteristics. |
| + | HID Hijacking | Scans 2.4GHz wireless HID devices and injects over-the-air keystroke frames with DuckyScript support for MouseJacking-style attacks. |
| + | CAN-bus Support | Reads, injects, and fuzzes CAN-bus frames, with support for custom DBC files and a built-in OBD2 PID parser. |
| + | Network Spoofers | Runs ARP, DNS, NDP, and DHCPv6 spoofing modules to position man-in-the-middle attacks on IPv4 and IPv6 networks. |
| + | Multi-Level Proxies | Intercepts traffic at the packet, TCP, and HTTP/HTTPS layers, with each proxy scriptable through JavaScript plugins. |
| + | Credential Sniffer | Captures and parses credentials from intercepted traffic and can also be run as a network protocol fuzzer. |
| + | Port Scanner | Runs a SYN-based port scan across discovered hosts to identify open services. |
| + | REST API | Exposes session control over HTTP with asynchronous event notifications over a websocket for orchestrating attacks from external tools. |
...6 more features/limitations. Contact us to get a complete list of features and system requirements.
System Requirements
| # | Minimum |
|---|---|
| 1 |
|
| 2 |
|
Ratings
Not available, but we appreciate help! You can help us improve this page by contacting us.
Repository
License
Categories
Notes
The 1.x line (up to 1.6.2) was a Ruby implementation offering only basic MITM, sniffing, and proxying; it is deprecated and unsupported. All active development is on the 2.x Go rewrite, which added WiFi, BLE, HID, CAN-bus, IPv6, a REST API, and a web UI. bettercap is intended for authorized security testing and research on networks and devices you own or have permission to test.
OpenSSF Scorecard: 4.8/10