bettercap logo bettercap logo background glow

bettercap

A framework for scanning, monitoring, and executing man-in-the-middle attacks on WiFi, Bluetooth Low Energy, HID, CAN-bus, and IP networks

It takes care to curate a safe software space. Help us do more.

&

+
WiFi Reconnaissance & Attacks
Scans WiFi networks and runs deauthentication and clientless PMKID attacks, plus automatic WPA/WPA2/WPA3 handshake capture.
+
BLE Scanning
Discovers Bluetooth Low Energy devices and enumerates, reads, and writes their characteristics.
+
HID Hijacking
Scans 2.4GHz wireless HID devices and injects over-the-air keystroke frames with DuckyScript support for MouseJacking-style attacks.
+
CAN-bus Support
Reads, injects, and fuzzes CAN-bus frames, with support for custom DBC files and a built-in OBD2 PID parser.
+
Network Spoofers
Runs ARP, DNS, NDP, and DHCPv6 spoofing modules to position man-in-the-middle attacks on IPv4 and IPv6 networks.
+
Multi-Level Proxies
Intercepts traffic at the packet, TCP, and HTTP/HTTPS layers, with each proxy scriptable through JavaScript plugins.
+
Credential Sniffer
Captures and parses credentials from intercepted traffic and can also be run as a network protocol fuzzer.
+
Port Scanner
Runs a SYN-based port scan across discovered hosts to identify open services.
+
REST API
Exposes session control over HTTP with asynchronous event notifications over a websocket for orchestrating attacks from external tools.
...6 more features/limitations. Contact us to get a complete list of features and system requirements.

Platform

Desktop
Mobile-Tablet
Gadget

Social

System Requirements

#Minimum
1
  • Windows (64-bit amd64 prebuilt binary)
  • Linux (64-bit amd64 prebuilt binary; other architectures via source build)
  • macOS (arm64 prebuilt binary; Intel via source build)
2
  • pkg-config
  • libpcap
  • libusb-1.0-0 (required by the HID module)
  • libnetfilter-queue (on Linux only, required by the packet.proxy module)

Ratings

Not available, but we appreciate help! You can help us improve this page by contacting us.

Developer

Written in

Go

Initial Release

2015-07-19

Repository

License

Categories


Notes

The 1.x line (up to 1.6.2) was a Ruby implementation offering only basic MITM, sniffing, and proxying; it is deprecated and unsupported. All active development is on the 2.x Go rewrite, which added WiFi, BLE, HID, CAN-bus, IPv6, a REST API, and a web UI. bettercap is intended for authorized security testing and research on networks and devices you own or have permission to test.

OpenSSF Scorecard: 4.8/10