Open-source project
Leadrogue/Wiflux avatar
Leadrogue/Wiflux

Wiflux wraps the wireless audit toolchain in one live terminal UI

Modern wireless security auditor with live Rich UI and smart attack orchestration

323 stars14 forksPythonMIT

At a glance

What is it?
Leadrogue/Wiflux is an MIT Python auditor that drives the existing aircrack-ng, reaver, hcxdumptool and hashcat ecosystem behind a single live terminal interface, with dependency checks, crack checkpoints and GPU control. It is built for authorized testing only, and that boundary is stated at the top of its own README.
Who is it for?
Use it if you audit wireless networks you own or hold written permission to test, and you are tired of stitching aircrack-ng, reaver, hcxdumptool and hashcat together by hand. Do not use it otherwise: the README opens with a statement that it is for authorized security testing only, and deauthentication traffic disrupts every client on the channel, not just the target.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 90 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 7, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What it orchestrates, and the line it draws

Wiflux does not implement wireless attacks. It orchestrates the tools that already do: aireplay-ng and aircrack-ng for WEP, reaver and bully with pixiewps for WPS, hcxdumptool and hcxpcapngtool for PMKID, and hashcat for cracking, with several deauthentication backends available behind a single flag. What the project adds is the layer above them: a live terminal interface, a dependency check, a scoring pass over what it sees, and a resumable cracking pipeline.

The README puts a boundary warning directly under the banner, stating that the tool is for authorized security testing only and should be used on networks you own or have explicit permission to audit. That is not boilerplate here. Deauthentication is not a passive technique, it disrupts every client associated with the access point on that channel, so the blast radius of a mis-targeted run extends well beyond the network you meant to test. Treat the permission requirement as part of the tool's design rather than as fine print.

The audience is a penetration tester or an administrator surveying their own estate, working on Kali or Debian with a monitor-capable adapter.

The scan table and the dependency screen

The interface is built on Rich and presents a live table during scanning, with columns for ESSID, BSSID, band in GHz, channel, encryption, WPS state, client count and a priority score. The GHz column was added in version 1.0.5 at a user's suggestion, which tells you something about how quickly the table grew to cover tri-band reality.

Space freezes the table so you can select and copy values, and Space resumes. That sounds trivial and is not: BSSIDs and channels are the values you need to copy into other tools, and a table that repaints continuously makes that impossible.

Before the scan, a post-splash screen checks which external tools are present and whether the rockyou wordlist is available, offering to install what is missing and to unpack rockyou.txt.gz automatically. Space continues and Ctrl+C exits cleanly. For a tool that depends on roughly a dozen external binaries, a preflight check is the difference between a failed run and a mystery.

Five attack paths, and what drives each

The README documents five supported paths, each mapped to specific external tools.

WEP uses aireplay-ng and aircrack-ng with ARP replay and a configurable timeout. WPS Pixie-Dust uses reaver or bully together with pixiewps, and can run offline from scan captures when those are available. WPS PIN uses reaver or bully, but tries algorithmically derived PINs from MAC and vendor data first. PMKID uses hcxdumptool and hcxpcapngtool and needs no associated client, with a configurable passive capture fraction and band rotation. WPA handshake capture runs through multiple deauthentication backends and hands the result to hashcat, with adaptive timing, band-stalk listening and a validation step.

Two version 1.0.3 additions are worth understanding because they change how a run behaves. Multi-stage crack ladders replace a single dictionary pass, and the WPA2 and WPA3 transition mode prefers WPA2 handshake or PMKID capture with hashcat mode 22000 on mixed networks, which can be disabled if your engagement rules forbid downgrade behaviour.

Scanning covers 2.4, 5 and 6 GHz, with the high bands selectable exclusively or in combination. A hidden SSID decloak step sends a probe during scanning to reveal cloaked network names.

Cracking: wordlists, ladders, GPUs and checkpoints

The cracking side is where most of the engineering went. Candidate generation starts with an ESSID-smart wordlist built from the network name and the vendor, capped in the preview at 100,000 entries, before falling through to vendor defaults, then a full dictionary, then hashcat rules. The ordering is fastest to longest, and a key press skips a pass.

Hashcat device handling is explicit. The tool prefers a GPU when one is available, and accepts flags to force GPU or CPU only, to select devices, to choose a backend and to set a workload profile. Version 1.0.5 added this after a user reported that hashcat could not be steered to the GPU, which is a fair illustration of how much a wrapper can hide until someone complains.

Durable checkpoints are the other half. Hashcat progress survives a restart under a dedicated checkpoints directory, and re-entering a crack offers to resume. For anyone who has lost a multi-day dictionary run to a reboot, that alone justifies the wrapper.

Results live in a SQLite store, and networks already recorded as cracked are skipped by default, with a flag to show them anyway.

Installing it and the commands worth running first

Install from the release wheel is the shortest path. Version 1.0.5 is the current release, published on 2026-07-10:

bash
pip install https://github.com/Leadrogue/Wiflux/releases/download/v1.0.5/wiflux-1.0.5-py3-none-any.whl --break-system-packages

There is also a Linux installer archive on the releases page. From source:

bash
git clone https://github.com/Leadrogue/Wiflux.git
cd Wiflux
pip install -e . --break-system-packages

Python 3.10 or newer is required, and the README notes that on Kali and Debian, sudo may not include /usr/local/bin in the path, so invocations that need root may have to set it explicitly.

The first command to run is the help output, which the README describes as grouped and colourised:

bash
wiflux --help                    # Grouped, colorized CLI reference

Three utilities need no root and no radio activity, which makes them the right way to get familiar with the tool before any engagement. One lists networks already recorded as cracked, one validates a capture file you already hold, and one exports results:

bash
wiflux --cracked
wiflux --check capture.cap
wiflux --export results.json

If you are contributing rather than auditing, the project keeps 116 automated tests that need no live radio, so continuous integration does not require hardware:

bash
cd Wiflux
pip install -e ".[dev]" --break-system-packages
python -m pytest tests/test_wiflux.py -q

Install documentation covers adapter setup and wordlists, and there is a separate tutorial document for the full walkthrough.

Where the automation can mislead you

Orchestration hides failures as well as complexity, and this tool automates several steps whose failure modes are silent.

Adaptive deauthentication tunes burst size and listen window from observed capture health. When that heuristic is wrong it will time out rather than tell you why, and the flag to disable it exists for a reason. PMKID passive ratio is likewise a tuning parameter rather than a guarantee, accepted in a range between 0.2 and 0.75. Band-stalk listening after a deauth assumes stations roam to a sibling band, which depends on the client, not on the tool.

Hardware assumptions bite too. Six GHz scanning requires a Wi-Fi 6E adapter, and the README says so. The external tool dependency is large, and a missing binary is a class of failure the preflight screen is designed to catch rather than eliminate.

Version 1.0.5 carried a long list of reliability fixes covering WPA3 password mode 22000, PMKID and EAPOL typing, multi-channel selection, 5 and 6 GHz hopping and band exclusivity, which is a fair indication that these paths were breaking in earlier releases. The project has published no release since 2026-07-10, and the last push was on 2026-07-10.

Against running the toolchain by hand

The alternative is the one every wireless tester starts with: aircrack-ng, reaver, hcxdumptool and hashcat invoked individually, with captures moved between them by hand and progress tracked in a text file. That route gives you exact knowledge of what each tool was asked to do, which matters when you have to write up findings and defend them. It also gives you nothing else: no priority scoring, no checkpoint resume, no dependency preflight, no single view of what has already been cracked.

Wiflux trades transparency for throughput. You gain a consistent pipeline and a resumable crack, and you lose the ability to say with certainty which specific command produced a given capture unless you go looking. For an internal audit that is an acceptable trade. For an engagement where the report will be scrutinised, plan to record what the tool did rather than relying on its output alone.

The licence is MIT, so reading the source to establish exactly what a given mode invokes is permitted and, on a regulated engagement, advisable.

Maintenance and the operational boundary

The project is MIT licensed, requires Python 3.10 or newer, and is currently at version 1.0.5. Releases 1.0.3 and 1.0.4 both landed on 2026-07-07 and 1.0.5 on 2026-07-10, a burst of activity followed by quiet. The repository is not archived.

Upkeep is mostly external. This is a wrapper, so a change to aircrack-ng, reaver, hcxdumptool or hashcat output formats can break parsing without the project changing a line, and the release history shows a steady stream of fixes for exactly that class of problem. Budget for tracking upstream, not just this repository.

Operationally, the boundary is worth restating because it is the part that outlives any feature list. Deauthentication affects every client on the channel. WPS and WEP paths exist because legacy equipment is still deployed, and finding either on a network you are responsible for is a result worth acting on. Running any of it against a network you do not own, or lack written authorisation for, is unlawful in most jurisdictions and is not what this tool is for.

Editorial conclusion

Use it if you audit wireless networks you own or hold written permission to test, and you are tired of stitching aircrack-ng, reaver, hcxdumptool and hashcat together by hand. Do not use it otherwise: the README opens with a statement that it is for authorized security testing only, and deauthentication traffic disrupts every client on the channel, not just the target. Before you rely on it, verify three things: that your adapter and platform match its Kali and Debian orientation, that the external binaries it drives are installed and on the path, and that you have read the current release notes, since version 1.0.5 carried a batch of reliability fixes covering WPA3 mode 22000, PMKID and EAPOL typing, and multi-channel scanning.

Frequently asked questions

Is Wiflux legal to run against any wireless network?

No. The README states it is for authorized security testing only and should be used on networks you own or have explicit permission to audit. Deauthentication also disrupts every client on the channel, not only the target, so unauthorised use affects third parties.

Which external tools does Wiflux require?

It drives existing tools rather than implementing attacks itself: aireplay-ng and aircrack-ng for WEP, reaver or bully with pixiewps for WPS, hcxdumptool and hcxpcapngtool for PMKID, and hashcat for cracking. A preflight screen checks which are present and can unpack the rockyou wordlist.

Can Wiflux resume a cracking run that was interrupted?

Yes. Version 1.0.5 added durable hashcat checkpoints stored under a crack_checkpoints directory, and re-entering a crack prompts to resume. Hashcat prefers a GPU when available and can be forced to GPU or CPU only.

Does Wiflux support 6 GHz networks?

Scanning covers 2.4, 5 and 6 GHz, with the high bands selectable exclusively or combined. The README states that 6 GHz operation requires a Wi-Fi 6E adapter.

Official sources

  1. Issues
  2. Leadrogue/Wiflux on GitHub
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/leadrogue-wiflux.svg)](https://hysenlabs.com/projects/leadrogue-wiflux)